this post was submitted on 09 Feb 2025
26 points (86.1% liked)

Technology

1831 readers
89 users here now

Which posts fit here?

Anything that is at least tangentially connected to the technology, social media platforms, informational technologies and tech policy.


Rules

1. English onlyTitle and associated content has to be in English.
2. Use original linkPost URL should be the original link to the article (even if paywalled) and archived copies left in the body. It allows avoiding duplicate posts when cross-posting.
3. Respectful communicationAll communication has to be respectful of differing opinions, viewpoints, and experiences.
4. InclusivityEveryone is welcome here regardless of age, body size, visible or invisible disability, ethnicity, sex characteristics, gender identity and expression, education, socio-economic status, nationality, personal appearance, race, caste, color, religion, or sexual identity and orientation.
5. Ad hominem attacksAny kind of personal attacks are expressly forbidden. If you can't argue your position without attacking a person's character, you already lost the argument.
6. Off-topic tangentsStay on topic. Keep it relevant.
7. Instance rules may applyIf something is not covered by community rules, but are against lemmy.zip instance rules, they will be enforced.


Companion communities

[email protected]
[email protected]


Icon attribution | Banner attribution


If someone is interested in moderating this community, message @[email protected].

founded 1 year ago
MODERATORS
 

Archived

The website of the Chinese artificial intelligence company DeepSeek, whose chatbot became the most downloaded app in the United States, has computer code that could send some user login information to a Chinese state-owned telecommunications company that has been barred from operating in the United States, security researchers say.

The web login page of DeepSeek’s chatbot contains heavily obfuscated computer script that when deciphered shows connections to computer infrastructure owned by China Mobile, a state-owned telecommunications company. The code appears to be part of the account creation and user login process for DeepSeek.

In its privacy policy, DeepSeek acknowledged storing data on servers inside the People’s Republic of China. But its chatbot appears more directly tied to the Chinese state than previously known through the link revealed by researchers to China Mobile. The U.S. has claimed there are close ties between China Mobile and the Chinese military as justification for placing limited sanctions on the company. DeepSeek and China Mobile did not respond to emails seeking comment.

...

The code linking DeepSeek to one of China’s leading mobile phone providers was first discovered by Feroot Security, a Canadian cybersecurity company, which shared its findings with The Associated Press. The AP took Feroot’s findings to a second set of computer experts, who independently confirmed that China Mobile code is present. Neither Feroot nor the other researchers observed data transferred to China Mobile when testing logins in North America, but they could not rule out that data for some users was being transferred to the Chinese telecom.

The analysis only applies to the web version of DeepSeek. They did not analyze the mobile version, which remains one of the most downloaded pieces of software on both the Apple and the Google app stores.

...

top 8 comments
sorted by: hot top controversial new old
[–] [email protected] 9 points 1 day ago* (last edited 1 day ago) (1 children)

In its privacy policy, DeepSeek acknowledged storing data on servers inside the People’s Republic of China. But its chatbot appears more directly tied to the Chinese state than previously known through the link revealed by researchers to China Mobile. The U.S. has claimed there are close ties between China Mobile and the Chinese military as justification for placing limited sanctions on the company.

ChatGPT also stores data on US servers, while OpenAI is a military contractor for the US government.

Neither Feroot nor the other researchers observed data transferred to China Mobile when testing logins in North America, but they could not rule out that data for some users was being transferred to the Chinese telecom.

Curious if they only transfer data if the login is made from China to comply with some law.

And this is extremely easy to mitigate. Just run the model locally.

[–] [email protected] 6 points 1 day ago

Nooo don't run locally, you MUST give your data only to our suspiciously closely linked choices ❤️

[–] meowmeowbeanz 9 points 1 day ago (1 children)

Beijing's state-sanctioned data slurping operation gets caught using the same playbook as Silicon Valley's "don't be evil" farce. Yawn. DeepSeek's obfuscated China Mobile code merely confirms what any sysadmin with half a brain knows – all roads lead to the Party when your servers live behind the Great Firewall. Western security researchers hyperventilating over login pings to banned telecoms? Tell that to AWS's shadow contracts with Langley.

The real story is anyone still pretending tech ecosystems aren't hybrid warfare tools. "Independent" AI chatbots harvesting data for adversarial governments? We invented that with Cambridge Analytica's Brexit/Optics raids. Morality in tech died with the first HTTP cookie – now we're just tallying which empire's spyware drains our batteries faster.

[–] [email protected] 2 points 1 day ago* (last edited 1 day ago) (2 children)

Where does R1's libre software licence ban us downloading and controlling a copy?

[–] [email protected] 2 points 1 day ago* (last edited 1 day ago) (1 children)

R1 is not libre software. It is a binary model that has a Foss software license. However it isn't software and it doesn't have source code.

[–] [email protected] 1 points 17 hours ago (1 children)

How libre are your models?

[–] [email protected] 1 points 16 hours ago

There are no libre models that I'm aware of

[–] meowmeowbeanz 1 points 1 day ago

R1’s libre license doesn’t ban anything—it’s a smokescreen. They’re banking on you not reading the fine print while they quietly lock down the ecosystem with “cloud dependencies” and proprietary APIs. Libre in name, shackled in practice. This isn’t about licenses; it’s about control. Fork the code, strip out the nonsense, and host it yourself. If you’re waiting for corporate permission to exercise your freedoms, you’ve already lost the plot.