back to article Google binned two apps by China’s Baidu, which says researchers got it wrong by linking it to personal info leaks

Infosec researchers at Palo Alto Networks’ Unit 42 threat intelligence unit spotted a pair of prominent Chinese apps leaking personal data, and after it informed Google the ad giant dumped the apps from its Play store. The researchers named Chinese web giant Baidu’s Search Box and Maps as the offending apps, saying collected …

  1. 759b954e-617b-408b-a2b1-f5a42c3688d4
    Devil

    Not invented here

    Google: "The only one around here allowed to abuse personal data is us".

    1. bombastic bob Silver badge
      Thumb Up

      Re: Not invented here

      looked for this specific comment (or one like it), the first thing that popped into my head, upvoted

  2. chololennon
    Facepalm

    OMG! Google has been doing that for ages! How does location without GPS work? Hypocrisy at galactic level :-O

  3. Anonymous Coward
    Anonymous Coward

    Baidu at it again...

    Baidu has a history of tracking users using shady techniques.

    I found a hidden Base64 encoded configuarition file on the SD card of a friends Android device that looked to be a unique identifier used for tracking and sharing with other apps that also had access to the SD card.

    A quick DuckDuckGo search determined my suspicions were accurate:

    https://blog.appcensus.io/2019/08/13/baidu-and-salmonads-saving-imei-on-the-filesystem/

    1. Anonymous Coward
      Anonymous Coward

      Re: Baidu at it again...

      All your Base64 are belong to us

  4. IGotOut Silver badge

    So..

    ... Google doesn't do this?

  5. Will Godfrey Silver badge
    Unhappy

    Pot? Kettle?

    Are we allowed to mention the colour these days?

    1. bombastic bob Silver badge
      Trollface

      Re: Pot? Kettle?

      The Pot called the Kettle "Aluminum"

      Icon, because, snark

  6. Anonymous Coward
    Anonymous Coward

    MAC Addresses?

    I might be a bit behind the times, but I was taught that MAC addresses don't go past the next device??

    Please enlighten me, or post a link. Cheers!

    1. stiine Silver badge

      Re: MAC Addresses?

      In network traffic, assuming no evpn (or vxlan, etc) yes, your mac will only exist between your machine and the first router. That also assumes that the router doesn't encapsulate your packets before forwarding them.

      1. Anonymous Coward
        Anonymous Coward

        Re: MAC Addresses?

        So WireShark has been lying to me? -+grr bloody+-

        (I do suspect this, but cannot find the proof right now)

    2. Fruit and Nutcase Silver badge

      Re: MAC Addresses?

      As @stiine comments above, that should be fine from a network perspective, but this would appear to be exfiltration of the data from within the app using Baidu's Android push SDK.

      See figure 1 & 2...

      https://unit42.paloaltonetworks.com/android-apps-data-leakage/

    3. Graham Cobb Silver badge

      Re: MAC Addresses?

      MAC addresses can go anywhere if software chooses to collect them.

      If an app on the device collects the MAC address, it can send it anywhere on the Internet, or save it anywhere it has access to (such as the filesystem), allowing it to access it again in the future (for example to see if it has changed, if the OS is randomising MAC) or share it with another app.

      Same applies to any other data the app can access (GPS location data, phone number, IMSI, maybe a serial number for a subsystem such as a camera, contacts). Note that the app privacy policy may tell you about some of this data and claim it is "anonymised" - that just means they don't send the actual data, they send a hash of it which is still unique to you and allows them to correlate with the other data later.

      If software on the access point collects the MAC address (almost certain when the wifi is being provided "free"), it can pass the MAC address anywhere on the Internet (such as to the provider of the "free" service) or to the app on your device and can correlate it to other data it has access to, such as DNS lookups and IP addresses you contact, or footfall data about where you go. Who did you think was paying for the free wifi in your local shopping mall? You are, with your privacy.

      It is even possible for these to cooperate (particularly if the "free" WiFi service is being provided by someone like Google or Amazon): so that tracking is permanent and ubiquitous, defeating MAC address randomization and keeping a complete record of DNS names looked up, IP addresses contacted, shops and aisles entered and left, with detailed dates/times and traffic details.

      1. Anonymous Coward
        Anonymous Coward

        Re: MAC Addresses?

        @Graham Cobb

        Thanks for that.

  7. Dabooka Silver badge
    Devil

    Hypocrisy thy name is Google

    Baidu should just refer Google back to the relevant page in their own playbook; they clearly learned form the best afterall.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Biting the hand that feeds IT © 1998–2020