Popular Chinese QQ Browser Caught Sending User Data to Its Servers

  • 29 March 2016
  • 1 reply
  • 138 views

Userlevel 7
Badge +54

Browser also fails to encrypt exfiltrated data, exposing user PII, and also features an insecure update process

 
Mar 29, 2016 11:00 GMT  ·  By Catalin Cimpanu A report from the Citizen Lab at the University of Toronto reveals that the popular QQ Browser is collecting sensitive user information and sending it in an insecure manner to its servers.
 
QQ Browser is yet another of those heavily customized Chromium clones that are distributed by companies that have no reason to distribute browsers. In this case, it's Chinese Internet giant Tencent, who provides its QQ Browser for the Windows, Mac, Android and iOS platforms.
 
According to the research group at Citizen Lab, the Android and Windows versions of this browser are collecting a trove of data from its users and have design flaws that expose this information to prying eyes while in transit.
 
Full Article

1 reply

Userlevel 7
Well, what browser doesn't send data back to base...it seems that one has to make a virtue about not being a data tale tell these days...but then again I suspect that people are becoming so inured re. this that the are really not bother until the evidence is shoved under their noses...then they holler.
 
It would be useful if browsers clearly indicated what data they routime send back to base and then what is down with that, rather then the public having to discover what they do via the press. 

Reply