Hindustan Times (Lucknow)

‘Chinese apps may pose security risks’

- Binayak Dasgupta binayak.dasgupta@htlive.com ■

NEWDELHI:Software and hardware developed in China often pose the threat of being used for mass surveillan­ce, cybersecur­ity researcher­s have said, citing data breaches as well as laws that indicate presence of mechanisms that can be activated to collect and sift through troves of user data.

One of the strongest hints came last year when Dutch cybersecur­ity experts discovered billions of messages of users of Chinese apps WeChat and QQ, which were stored in a manner that suggested they were part of a massive dragnet that was used to censor content on these platforms.

“Every Chinese tech company has to comply with the Chinese cybersecur­ity law which allows the Chinese government to have access to the data these companies collect – this is part of the nationwide mass surveillan­ce systems that are in place in China,” said Victor Gevers, head of research at the Dutch Institute of Vulnerabil­ity Disclosure (DIVD), who discovered such databases in 2019.

WeChat and QQ are among 59 mostly Chinese applicatio­ns banned by the Indian government on Monday after complaints that these were collecting and sending data of Indian users outside of the country, a move that comes in the middle of increased hostilitie­s between the two countries over the disputed border at Ladakh.

“These data collection­s are not limited to only Chinese users but all users of a certain platform and data includes every interactio­n,” contended Gevers, adding that the leaks in 2019 showed the inner workings of these mass surveillan­ce systems for the first time.

Gevers’s concerns were echoed by Anand V, an independen­t security researcher based in Bengaluru. “Generally, developers from China are used to looking at techno-cultural approach that all data belongs to government. They believe that it is okay to collect data in such manner because it comes from such a mindset,” he said. Among the database were roughly 3.7 billion messages sent on one particular day – March 18, 2019 – on WeChat that had a common theme: they all contained some specific keywords that were likely to have been identified as triggers for censorship or action by law enforcemen­t. The words included “Jinping”, “power”, “CCP”, “Tiananmen”, and “Dalai”.

“It became very clear that they actually gather everything at some point and sift through it to see if there has to be any intercepti­on or human interactio­n. They copy all the data or take a stream of realtime data and use keywords to trigger a censor system that automatica­lly removes content from applicatio­ns or flag them for a review,” Gevers said.

Indication­s of unlawful collection of data emerged afresh last week with another prominent Chinese company, TikTok, which was found to have been logging what people were typing on their iPhones. According to Gevers, logging keystrokes – what people type – may now become one of key ways such companies intercept the data they are legally required to maintain as more apps deploy end-to-end encryption.

“What we saw with TikTok is likely to happen with other applicatio­ns,” he warned. The concerns stretch over to hardware as well, he added. “We have observed that China is investing in mass surveillan­ce using not only CCTVs but also other interfaces. The big worries are Huawei with its 5G networks,” he said. The entry of Huawei in 5G mobile communicat­ion has triggered concerns in some Western nations, predominan­tly the US, that it may allow for a backdoor for Chinese intelligen­ce to internet as well as phone data.

Gevers as well as Anand said the risk in particular was because of how free applicatio­ns work: they collect massive amounts of user data to sustain the business by offering ads. “Chinese developers often use the principles of data collection and data mining commonly used for advertisin­g and uses it to its mass surveillan­ce system,” said Gevers.

“Most of these applicatio­ns collect far more data than required and that has been a very long-going concern. It is a giant dragnet of data,” added Anand.

Newspapers in English

Newspapers from India