AI News AI资讯 7h ago Updated 2h ago 更新于 2小时前 46

Apps targeted at US troops contain Chinese and Russian code 针对美军人员的APP包含中国和俄罗斯代码

A study of over 220 military-marketed apps revealed that more than one in eight contained software development kits (SDKs) from nations considered adversarial by the Pentagon, including China and Russia. Approximately 64% of the examined apps included third-party code capable of tracking user behavior and location, with 40% collecting or sharing more data than disclosed in their store listings. Specific instances included Huawei’s HMS Core in twelve apps, raising concerns about remote code updat 一项针对超过 220 款面向军方推广的应用程序的研究显示,其中超过八分之一的应用程序包含来自被五角大楼视为敌对国家的软件开发工具包(SDK),包括中国和俄罗斯。 在被审查的应用程序中,约 64% 包含了能够追踪用户行为和位置的第三方代码,其中 40% 收集或共享的数据量超过了其在应用商店列表中披露的数量。 具体案例包括在十二款应用程序中发现了华为的 HMS Core,这引发了人们对远程代码更新可能将休眠软件转变为监控工具的担忧。 受访的军方相关人员对外国代码表示高度不安,但缺乏透明度机制,因为主要的应用商店并未披露嵌入式 SDK 的原产国。 参与者认为,手机内的外国代码警告以及对数据经纪商实施

65
Hot 热度
70
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • A study of over 220 military-marketed apps revealed that more than one in eight contained software development kits (SDKs) from nations considered adversarial by the Pentagon, including China and Russia.
  • Approximately 64% of the examined apps included third-party code capable of tracking user behavior and location, with 40% collecting or sharing more data than disclosed in their store listings.
  • Specific instances included Huawei’s HMS Core in twelve apps, raising concerns about remote code updates that could transform dormant software into surveillance tools.
  • Surveyed military-affiliated individuals expressed high discomfort with foreign code but lacked transparency mechanisms, as major app stores do not disclose the country of origin for embedded SDKs.
  • Participants identified in-phone warnings for foreign code and stricter federal regulations on data brokers as the most effective mitigation strategies.

Why It Matters

This issue highlights a critical vulnerability in national security where commercial data brokerage practices inadvertently expose military personnel to espionage risks. For AI and cybersecurity practitioners, it underscores the necessity of supply chain transparency in software dependencies and the limitations of current privacy labels in detecting geopolitical risks embedded in third-party code.

Technical Details

  • Scope: Analysis of 220+ apps marketed to US military personnel, sourced from Google Play and military subreddits, covering utility, banking, and social categories.
  • SDK Prevalence: 64% of apps contained third-party SDKs; 76 distinct SDKs were traced to countries including China, Russia, Israel, India, and Germany.
  • Adversarial Code: Roughly 7% of apps contained code from nations designated as cyber adversaries by the Pentagon; 12 apps specifically included Huawei’s HMS Core, which maps locations and stores media.
  • Data Discrepancy: 40% of apps collected or shared data exceeding their public privacy disclosures, indicating a gap between stated and actual data practices.
  • Transparency Gap: Neither Google Play Store Data Safety sections nor Apple App Store Privacy Labels provide information regarding the geographic origin of the software components within apps.

Industry Insight

  • Supply Chain Security: Developers and platform providers must implement stricter auditing for third-party SDK origins, particularly for applications targeting sensitive demographics, to prevent inadvertent inclusion of adversarial code.
  • Regulatory Pressure: The lack of transparency in app store privacy labels suggests a need for new regulatory standards requiring disclosure of SDK vendor nationality and data routing paths.
  • User Awareness Tools: There is a clear market demand for automated detection tools that alert users to the presence of foreign or unknown third-party code, which could serve as a primary defense mechanism against data harvesting.

摘要

一项针对超过 220 款面向军方推广的应用程序的研究显示,其中超过八分之一的应用程序包含来自被五角大楼视为敌对国家的软件开发工具包(SDK),包括中国和俄罗斯。
在被审查的应用程序中,约 64% 包含了能够追踪用户行为和位置的第三方代码,其中 40% 收集或共享的数据量超过了其在应用商店列表中披露的数量。
具体案例包括在十二款应用程序中发现了华为的 HMS Core,这引发了人们对远程代码更新可能将休眠软件转变为监控工具的担忧。
受访的军方相关人员对外国代码表示高度不安,但缺乏透明度机制,因为主要的应用商店并未披露嵌入式 SDK 的原产国。
参与者认为,手机内的外国代码警告以及对数据经纪商实施更严格的联邦法规是最有效的缓解策略。

深度分析

太长不看(TL;DR)

  • 一项针对超过 220 款面向军方推广的应用程序的研究显示,其中超过八分之一的应用程序包含来自被五角大楼视为敌对国家的软件开发工具包(SDK),包括中国和俄罗斯。
  • 在被审查的应用程序中,约 64% 包含了能够追踪用户行为和位置的第三方代码,其中 40% 收集或共享的数据量超过了其在应用商店列表中披露的数量。
  • 具体案例包括在十二款应用程序中发现了华为的 HMS Core,这引发了人们对远程代码更新可能将休眠软件转变为监控工具的担忧。
  • 受访的军方相关人员对外国代码表示高度不安,但缺乏透明度机制,因为主要的应用商店并未披露嵌入式 SDK 的原产国。
  • 参与者认为,手机内的外国代码警告以及对数据经纪商实施更严格的联邦法规是最有效的缓解策略。

为什么这很重要

这一问题凸显了国家安全中的一个关键漏洞,即商业数据经纪做法无意中使军事人员面临间谍活动的风险。对于人工智能和网络安全从业者而言,这强调了软件依赖项中供应链透明度的必要性,以及当前隐私标签在检测第三方代码中嵌入的地缘政治风险方面的局限性。

技术细节

  • 范围:对 220 多款面向美国军方人员推广的应用程序进行分析,来源包括 Google Play 和军事相关的 Reddit 论坛,涵盖实用工具、银行和社会类应用。
  • **SD

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究 Policy 政策