DeepSeek – another wakeup call for device and data security

DeepSeek – another wakeup call for device and data security

DeepSeek – another wakeup call for device and data security

By Philip Ingram MBE

According to De Weld (DW), “Tech stocks plunged on Monday after claims of advances by Chinese artificial intelligence (AI) startup DeepSeek cast doubts on United States firms’ ability to cash in on the billions they have already invested on AI.

Shares in chipmaker Nvidia, Microsoft and Meta all plunged in early trading, with the tech-heavy Nasdaq also taking a serious tumble.

The fall is tied to DeepSeek’s release last week of its latest large language AI model, which claims to match the performance of leading US rivals such as OpenAI despite spending far less money and using far fewer Nvidia chips.”

DeepSeek has developed a large language model that can make grater use of normal chips thereby undermining some of the business models behind the wider business relationships between the likes of NVIDA, ChatGPT, Apple, Microsoft and more.  However, we must ask why?

The opening question I have is quite simple, “Is DeepSeek a dual use technology?”.  So, what do I mean by ‘dual use’? It is quite simple, produce a capability that delivers something people want to use in order for it to ‘go viral’ and be installed on as many devices as possible. That is the primary use, what the general public want to see. The secondary use is, set the conditions to access and exfiltrate the data held and processed on as many devices as possible; this is what the public don’t want to acknowledge.

This isn’t the first time a viral app has had the data it can access on hosting devices questioned.

The UKs Information Commissioners Office talks of Pokemon Go, “Originally designed as a 2014 April Fools’ Day joke by Google, The Pokémon Company and Nintendo, the augmented reality mobile app launched as a free-to-play game in July 2016. The game uses GPS location data to find, capture, train and battle virtual Pokémon, which appear as if in the user’s physical location. By the end of 2016, it was one of the most used and downloaded apps of the year with over 500 million downloads worldwide.

Despite this popularity, questions were raised on how the app uses personal information. At its launch, the game relied on having access to your location and to track where you were in the world. It also used access to your camera, so you could catch any Pokémon you came across. This highlighted some privacy concerns – how the app collected this data, what it did with it, and how long it kept it for.

Following public debate about the sheer amount of personal information collected, the Pokémon Go creators made changes, so the app collected “only the basic profile data that Pokémon Go needs”.”

That sheer amount of data is government quango speak for almost everything on the device whether the game needed it or not.

What people didn’t realise is that Section 702 of the US Foreign Intelligence Surveillance Act (FISA), a critical intelligence collection authority that enables the Intelligence Community (IC) to collect, analyse, and appropriately share foreign intelligence information about national security threats. Section 702 authorizes targeted intelligence collection of specific types of foreign intelligence information—such as information concerning international terrorism or the acquisition of weapons of mass destruction—identified by the Attorney General and the Director of National Intelligence (DNI).

Section 702 only permits the targeting of non-United States persons who are reasonably believed to be located outside the United States.  Pokémon Go had a specific clause in its data protection statement saying that all data collected by the app was transferred to and processed on servers in the US.

The Pokémon Company and Nintendo were held to account in the pross and the court of public opinion and changed what data the app – the game- accessed on people devices.

Tom Tugendhat MP for Tonbridge and former Security Minister said in a very recent interview on GB News, said TikTok “can read everything you are doing on your phone, and is a form of propaganda.” He goes on to say “perhaps, just perhaps the code that is written in Shenzhen is under the influence of some others.” Here he is clearly referring to Article Seven of China’s National Intelligence Law, that states that all Chinese organisations and citizens should “support, assist and co-operate” with Chinese intelligence efforts.  TikTok’s parent company Bite Dance is a Chinese owned company with close links to the Chinese State.

Bite Dance insists it operates no differently to other social media companies and says it would never comply with an order to transfer data.  However, it has been caught out using TikTok’s data to track US journalists investigating the company and others. If Bite Dance wasn’t complying with Chinese national intelligence requests, then Liang Rubo, its CEO would be in prison. He isn’t so either he hasn’t been asked (not likely) or he is complying and denying, knowing the outside world can’t or won’t hold him to account properly. This is the nub of the argument behind the security rational for banning TikTok in the US. However, President Trump sees a business opportunity that he clearly sees as more important than national security issues.

Liang Wenfeng, CEO of Hangzhou DeepSeek Artificial Intelligence Co., Ltd established in 2023 is subject to the same Article seven of China’s National Intelligence Law and a large language model AI tool operating on a device is a massive data gathering opportunity that the Chinese State simply won’t miss.

If the Israeli Cyber Company NSO can develop a tool (Pegasus) that allows total control of a mobile device even when switched off through the receipt of a message, a zero click attack, what could be embedded in the code of some of these potentially dual use, viral apps?

Why does China want all of this data? Simply to know more about societies outside China than they know about themselves, building up profiles on every individual. This is an impossible thought with current computing power but with quantum computing, something China is leading the worlds in developing, all of a sudden what you can do with huge volumes of data is frightening. What is needs is as much data as it can collect over as long a period of time as possible. That data collection is what is happening today, using viral apps. Tom Tugendhat explanation of propaganda expanded is manipulating how people think through targeted content. That is the ultimate goal, and it isn’t science fiction it is very much science fact.

Within that data targeted analysis can help identify and exploit individuals in current positions of influence, so government ministers, senior military and security personnel, academics, those involved in research, company CEOs and COOs and chief technologists and many more.

Should we be wary of DeepSeek – quite simply Yes!  The use of thse apps makes us all as individuals and as a society hugely more vulnerable.