YYaaa News

220+ apps marketed to U.S. troops ship Chinese and Russian code | Huawei SDK found embedded

TL;DR

Researchers at Purdue and elsewhere found nearly two-thirds of 220+ apps marketed to U.S. military personnel embed third-party code from China, Russia and others — including Huawei's SDK, flagged as a national security threat. Remote-updatable code is the core risk. 76-83% of 103 surveyed military-affiliated respondents reported extreme discomfort.

Researchers at Purdue and other institutions found that of 220+ apps marketed to U.S. military personnel — covering base reviews, uniform guides, banking, dating — nearly two-thirds embed third-party code from China, Russia and others, including Huawei's software development kit (SDK), already flagged by the U.S. government as a national security threat.

The technical risk sits in remote updatability. Researchers note no data was observed flowing to Huawei servers, but this class of SDK can be remotely updated by the developer at any time, meaning dormant code can be activated on demand. Of 103 surveyed military-affiliated respondents, 76% to 83% reported extreme discomfort at apps containing Chinese, Russian, Iranian or North Korean code.

Not the first time. The Department of Defense has previously reported adversaries using commercial location data to monitor U.S. troops in the Middle East. App-store takedown governance can't keep up with third-party SDK update cadence — the code that actually runs on a soldier's phone sits a full supply chain away from Washington's Entity List.

via WIRED
220 款美軍常用 App 近三分之二含中俄代碼|華為 SDK 潛伏其中