Baidu web browsers leaked sensitive information, researchers say

Baidu has fixed some of the issues, but others remain

Two web browsers developed by Chinese search giant Baidu have been insecurely transmitting sensitive data across the Internet, putting users' privacy at risk, according to a new study.

Baidu responded by releasing software fixes, but researchers say not all the issues have been resolved.

The study was published Tuesday by Citizen Lab, a research group that's part of the University of Toronto. 

It focused on the Windows and Android versions of Baidu's browser, which are free products. It also found that sensitive data was leaked by thousands of apps that use a Baidu SDK (software development kit).

With the browsers, Citizen Lab found that a user's search terms, GPS coordinates, the addresses of websites visited and device's MAC (Media Access Control) address were sent to Baidu's servers without using SSL/TLS encryption.

"The transmission of personal data without properly implemented encryption can expose a user's data to surveillance," the report noted.

Other sensitive information, such as IMEI (International Mobile Station Equipment Identity) numbers, nearby Wi-Fi networks and their MAC addresses, and hard-drive serial numbers were transmitted with weak encryption that could be broken.

Neither web browser used digital code signatures for updates, meaning attackers could try to slip in their own code instead.

The government of China strictly controls Internet use, and Baidu can be required to hand over user data to intelligence agencies and law enforcement. The data collection raises questions about whether it could be used against those who oppose government policies.

"While Internet companies often collect personal user data for the normal and efficient provision of services, it is unclear why Baidu Browser collects and transmits such an extensive range of sensitive user data points," the report said.

Citizen Lab also found that thousands of mobile apps that use Baidu's mobile analytics SDK transmit the same sensitive information back to the company.

"Any app that uses this SDK for statistics and event tracking sends messages to Baidu’s servers," the report said.

Baidu officials could not be immediately reached for comment, but Citizen Lab published a document with questions it posed and answers from the company.

Baidu doesn't answer a question about what user data is it required to retain under Chinese law. It also says it was unable to comment on why requests using its browsers to visit websites outside of China went through a proxy server.

But Baidu said it has improved security based on the researchers' findings. For example, it said data transmitted by the Android browser would be fully encrypted by the end of this month, and for the Windows browser by early May.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?