Live data from Hacker News

South Korean regulator accuses DeepSeek of sharing user data with ByteDance

bbc.com

131–140 of 146 posts

Re: South Korean regulator accuses DeepSeek of sharing user data with ByteDance

#131

Earlier quoted context omitted.

This is a rare example where I actually think Meta should be providing the evidence, and not the other way around. When you have a history of doing greasy shit, you don't get the benefit of the doubt.

What evidence would be convincing?

How about a breakdown on the exact ways WhatsApp makes them money and how the justified value of $20 bil when meta purchased it made sense?

Re: South Korean regulator accuses DeepSeek of sharing user data with ByteDance

#132
post #97

Earlier quoted context omitted.

If the argument is that there's no credible evidence, retorting with a vague question doesn't really help your case. If anything it reinforces the original claim that there's no credible evidence.

If Ruppert Murdoch bought an independent news agency, would you expect the agency to remain unbiased in their reporting?

Being "biased" isn't remotely close to outright lying. Despite all the exasperation about Fox News being "fake news" or whatever, they very rarely outright lie.

https://www.astralcodexten.com/p/the-media-very-rarely-lies

Re: South Korean regulator accuses DeepSeek of sharing user data with ByteDance

#133
post #132

Earlier quoted context omitted.

If Ruppert Murdoch bought an independent news agency, would you expect the agency to remain unbiased in their reporting?

Being "biased" isn't remotely close to outright lying. Despite all the exasperation about Fox News being "fake news" or whatever, they very rarely outright lie. https://www.astralcodexten.com/p/the-media-very-rarely-lies

This is how you're playing this argument out??

Re: South Korean regulator accuses DeepSeek of sharing user data with ByteDance

#134

Earlier quoted context omitted.

Which is in this case a pretty important distinction. Letting another company leverage user data within the bounding zone which you've defined is not the same thing as is being alleged here, which is actually sharing data. It's quite literally the difference between exposing a public API and actually handing over the contents of the database.

> Letting another company leverage user data within the bounding zone which you've defined is not the same thing as is being alleged here, which is actually sharing data. Both are real violations of users.

I didn't say they weren't, but it's an important distinction nonetheless.

Re: South Korean regulator accuses DeepSeek of sharing user data with ByteDance

#135

Major Chinese tech companies often collaborate with government entities, potentially compromising user privacy. Given China's regulatory environment, where authorities can access data held by domestic firms, users worldwide should exercise caution when engaging with platforms from such backgrounds.

Which countries don’t have a process for the same thing…specifically?

Re: South Korean regulator accuses DeepSeek of sharing user data with ByteDance

#136
post #44

I guess we know how many bots are commenting on this article based on how many of them are talking about the US, when the article is about South Korea?

Does that make you a bot for not realizing the article also talks about US researchers coming to a similar conclusion?

For a single sentence on an entire article about South Korea and a pundit comment by a company whose job it is to look at this sort of thing? If you pick the US as your thing to comment on in an article like this, maybe you're just a bot, or even hired hand, for making comments about the US without bothering to understand that you're obviously commenting out of place.

Re: South Korean regulator accuses DeepSeek of sharing user data with ByteDance

#137

Earlier quoted context omitted.

The ostensible business models of the companies at play. Stop looking at any opportunity to bark as Sinophobia.

Don't just restate it using different words! Precisely how's that different to the business models at play at Meta etc?

Supposing you were an investor in either or both, is that the question you waited three months to ask?

Re: South Korean regulator accuses DeepSeek of sharing user data with ByteDance

#138

This is my surprised face -_- If you're shocked or even the slightest bit surprised, then I can't imagine how blissful your life is to be so unaware about how much corporations are sharing data with each other. Like, I wholeheartedly expect that if I mention Beyblade toys on Facebook, then the next time I visit Amazon, they'll be suggesting Beyblades even if I've never even searched Amazon for toys, let alone Beyblad…

I recently had an experience that genuinely surprised me: I was watching a Peruvian video on YouTube, and I clicked on the creator's Instagram profile link in the description. Literally a few minutes later I received a promotional email with services and investment opportunities from an official Peruvian government email. Somehow opening an Instagram profile of a Peruvian creator got me tagged as a potential investor…

Apparently Peru's poise presents preparedness porque es preferido para la presencia de GalApagos al oeste. [sic]

Re: South Korean regulator accuses DeepSeek of sharing user data with ByteDance

#139
post #130

Earlier quoted context omitted.

Weird hill to die on, man. Like, sure credible evidence is one of the most important things in the world... but what, are you honestly saying that you're going to be surprised if WhatsApp turned out to be leaking data? We don't need the pitchforks just yet, sure, but shit, you have to remain realistic about these things.

>but what, are you honestly saying that you're going to be surprised if WhatsApp turned out to be leaking data? Your words, not mine. I never made such claims, and you're trying to move the goalposts from "Meta does this" to "I'll be surprised if Meta does this".

I'm not moving goalposts. I didn't accuse WhatsApp of leaking data, stop twisting other people's words.

I think you mean "I'll NOT be surprised if Meta does this", which is the reasonable position of any rational person to take.

I'm allowed to extrapolate expectations of future behaviour, based on past behaviour. Doing otherwise is naive, dangerously so if you're responsible for someone else's security or privacy.

Re: South Korean regulator accuses DeepSeek of sharing user data with ByteDance

#140
post #77
post #31

Some missing context is that the data is shared via the DeepSeek app's use of ByteDance analytics/configuration frameworks. So not a backroom deal where DeekSeek handed over the chat history for its user base, but rather ongoing analytics data being sent from the DeepSeek mobile app. Here's the SecurityScoreCard article that brought attention to this: https://securityscorecard.com/blog/a-deep-peek-at-deepseek/#... Be…

We analyzed the iOS app[1] and observed similar traffic as well as a number of basic security issues (hardcoded encryption keys, use of 3DES and some traffic over HTTP). [1] https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers...

Thanks for writing this article! I quite enjoyed it.

question: does the DeepSeek's app use of hardcoded encryption keys rise beyond just their attempt to obfuscate and protect their app's private API endpoints? I believe this an attempt to make abusing their mobile app's private web APIs more difficult since even with cert-pinning disabled and HTTPS MITM'd you still can't observe the real traffic and replicate their requests.

If all its doing is obfuscation though, then I don't understand why pointing out that the keys are hardcoded is meaningful. It certainly doesn't engender trust. But if the app's binary is ultimately decoding some encrypted data, it needs the key, meaning it's ultimately available to the reverse engineer. Whether it's hardcoded or not doesn't matter.

It's a bad look, but if the app used the latest tech and assigned each client its own symmetric encryption key for a session, wouldn't you still be able to access the same data? What would be meaningfully different from a security perspective if they had done this obfuscation better?

Post reply on HN