Is anyone actually surprised by this?

  • JOMusic@lemmy.ml
    link
    fedilink
    English
    arrow-up
    53
    arrow-down
    1
    ·
    6 days ago

    This article is what US propaganda looks like folks. Mashable should be ashamed.

    Literally all AI companies do this to run their services. Except you can actually download Deepseek and run it completely securely on your own devices. You know who doesn’t allow that security? OpenAI and the other US companies currently being screwed.

  • Jhex@lemmy.world
    link
    fedilink
    arrow-up
    28
    ·
    5 days ago

    as opposed to OpenAI which also stores keystrokes and then sells them to anyone who’d pay?

  • Zip2@feddit.uk
    link
    fedilink
    arrow-up
    66
    arrow-down
    1
    ·
    6 days ago

    Did the American technology giants think they had the monopoly on capturing human input too?

  • ArchRecord@lemm.ee
    link
    fedilink
    English
    arrow-up
    44
    arrow-down
    2
    ·
    6 days ago

    the company states that it may share user information to "comply with applicable law, legal process, or government requests.

    Literally every company’s privacy policy here in the US basically just says that too.

    Not only does DeepSeek collect “text or audio input, prompt, uploaded files, feedback, chat history, or other content that [the user] provide[s] to our model and Services,” but it also collects information from your device, including “device model, operating system, keystroke patterns or rhythms, IP address, and system language.”

    Breaking news, company with chatbot you send messages to uses and stores the messages you send, and also does what practically every other app does for demographic statistics gathering and optimizations.

    Companies with AI models like Google, Meta, and OpenAI collect similar troves of information, but their privacy policies do not mention collecting keystrokes. There’s also the added issue that DeepSeek sends your user data straight to Chinese servers.

    They didn’t use the word keystrokes, therefore they don’t collect them? Of course they collect keystrokes, how else would you type anything into these apps?

    In DeepSeek’s privacy policy, there’s no mention of the security of its servers. There’s nothing about whether data is encrypted, either stored or in transmission, and zero information about safeguards to prevent unauthorized access.

    This is the only thing that seems disturbing to me, compared to what we’d like to expect based on the context of what DeepSeek is. Of course, this was proven recently in practice to be terrible policy, so I assume they might shore up their defenses a bit.

    All the articles that talk about this as if it’s some big revelation just boil down to “company does exactly what every other big tech company does in America, except in China”

  • Treczoks@lemmy.world
    link
    fedilink
    arrow-up
    71
    ·
    6 days ago

    “We store the information we collect in secure servers located in the People’s Republic of China”

    Now you Americans know how we Europeans feel when Google, Amazon and Facebook store our information on American servers. Hint: The protective wall between Chinese servers and their government are about as good as the one between American servers and their government - at least for non-US citizens. The last thin veil of privacy for Eurpeans has been ripped to shreds by Trump last week.

    • Ferk@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      5 days ago

      The last thin veil of privacy for Eurpeans has been ripped to shreds by Trump last week.

      What did he do? I know Trump does not like the GDPR, but did he sign something affecting it last week?

      • Treczoks@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        5 days ago

        He killed the EU-US Data Privacy Framework. Theoretically, no company is allowed to transfer data of European citizens to US-based servers anymore. Sadly, Ursula von der Leyen is lacking the balls to act on this.

        • Ferk@lemmy.ml
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          5 days ago

          Thanks, I did not know. I think you are referring to this: https://www.freevacy.com/news/noyb/trumps-actions-to-dismantle-pclob-threatens-eu-us-data-transfers/6088

          To be completely honest… as an European I would be happy if they actually did make it so that no EU-US data transfer were allowed… we need to stop depending on all these US-based services… but like you said, they probably don’t have the balls to pull the plug. Which makes me wonder if that board was actually really any protection at all for privacy or it had always been an empty shell used as an excuse on both sides just to keep up appearances and maintain the plug on.

          I honestly think this could be a win for us. Worst case scenario, nothing really changes but some masks fall off and at least some people would stop acting under false pretense (which could open the doors for change). So I’m actually glad he did that.

  • geneva_convenience@lemmy.ml
    link
    fedilink
    arrow-up
    25
    arrow-down
    2
    ·
    5 days ago

    They should store the data in US servers like OpenAI does. Apparently then Mashable won’t write an article about it.

    The criticism thrown at DeepSeek in the past days is just as applicable to American AI models. But when that was brought up it in the past it was “making things political”.

    At least I can run DeepSeek locally.

  • grey_maniac@lemmy.ca
    link
    fedilink
    arrow-up
    60
    arrow-down
    2
    ·
    6 days ago

    I’m confused. Isn’t “collecting keystroke data” just an alarmist way to describe text entry?

    • Ferk@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      3 days ago

      This is the full paragraph:

      We collect certain device and network connection information when you access the Service. This information includes your device model, operating system, keystroke patterns or rhythms, IP address, and system language. We also collect service-related, diagnostic, and performance information, including crash reports and performance logs. We automatically assign you a device ID and user ID. Where you log-in from multiple devices, we use information such as your device ID and user ID to identify your activity across devices to give you a seamless log-in experience and for security purposes.

      It looks to me that they are using it to identify the user uniquely, maybe also related to captcha to prevent bots (it’s common practice to capture mouse and keyboard while resolving captchas to see if the movement is human-like).

    • noisefree@lemmy.world
      link
      fedilink
      arrow-up
      14
      arrow-down
      1
      ·
      6 days ago

      Maybe. They could also be doing things like paying attention to input cadence and typos/pre-send typo corrections to use as part of a fingerprint associated with the identifying information a user gives them when creating an account so that they can then attempt to detect the user elsewhere on the web whether they are using an identifying account or not.

    • uis@lemm.ee
      link
      fedilink
      arrow-up
      7
      arrow-down
      4
      ·
      6 days ago

      Not exactly. Timing between key presses can be used to identify people.

        • uis@lemm.ee
          link
          fedilink
          arrow-up
          1
          ·
          3 days ago

          The goal is not to identify keyboard model. The goal is to identify person. And people tend to have something called habbits.

          • kekmacska@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            3 days ago

            the chance of this is almost zero. if you are a dangerous cybercriminal, they will track your device down by a networking solution, wait until you leave it unattended and install a hardware-based spy device and capture evidence. No fbi agent will fuck around with keyboard sounds or movie bs like that

            • uis@lemm.ee
              link
              fedilink
              arrow-up
              1
              ·
              3 days ago

              with keyboard sounds

              Ok, I see you are intentionally going in circles.

      • grey_maniac@lemmy.ca
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        5 days ago

        I am literally so paranoid I regularly vary my keysteoke rhythms and explore polyrhytmic techniques to create variations. Not even joking.

    • tux@lemmy.world
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      6 days ago

      Not usually. Keystroke info is different than text input, like if you didn’t click onto any field and typed it would only be captured if keystroke are all being grabbed. It’s especially scary if you keep the app running in the bg and then type something and it still captures it. Not saying they’re doing that, but the privacy policy says they might.

      The rhythm part is annoying, it’s commonly used to ID people even through things like ad blocks and dns blocks. Could also (in theory) be used to capture what people are typing just by hearing how they type.

  • circuitfarmer@lemmy.sdf.org
    link
    fedilink
    arrow-up
    144
    arrow-down
    3
    ·
    7 days ago

    This “China’s AI is taking your data and that’s bad” is shockingly similar to “TikTok is taking your data and that’s bad”. Lots of US counterparts do the same thing, but I don’t see (as much) media coverage about that.

    Don Draper: “no no no, everyone else’s cigarettes are dangerous. Lucky Strikes are… toasted.”

    • chicken@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      36
      arrow-down
      3
      ·
      7 days ago

      The way I think of it is, I don’t live in China, so regardless of my objections to their values or human rights abuses, why would CCP or an affiliated company care about me or ruin my life on the basis of or by abusing my data? A big part of why I care about privacy is I don’t want to be filtering my every thought through consideration of whether the powers that be would approve, and US companies are way more relevant to that.

    • shawn1122@lemm.ee
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      7 days ago

      These the excuses you start to make when you’re losing. Not looking great for the US…

    • smb@lemmy.ml
      link
      fedilink
      arrow-up
      5
      ·
      6 days ago

      I think its called a data lake, so they don’t “store” it, its rather floating around there 🤪

      • howrar@lemmy.ca
        link
        fedilink
        arrow-up
        9
        ·
        6 days ago

        These lakes are formed when the cloud is saturated and gives us data precipitation.

        • smb@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          6 days ago

          thanks for the great picture 👍

          so here is the current cloud clima forecast:

          The saturated clouds will rain into the data lakes that are already overspilling here and there into the ransomstreams already taking all soil in their way with them. During the day there will be security clouds preventing from visible rain only while during the night those same security clouds rain themselves all collected data to their homelake while their homelake security already is corrupted and spills over regulary.

          As soon as the fort-cisc-pal-ocstricken-redm-ondams breach it’ll gonna have floods with multi-exabyte waveheights and the ripples of the release will be felt over to far east china and the currents will circulate around the world multiple times causing damage and devastation in their wake around the world and eventually even reach connected orbit.

          The floods will have the potential to also wash away and /or drown or choke all the big tech dinosaurs. Only small foss mammals and deep sea amphibics will survive this historic event.

          … you kinda asked for it 😉 same as “they” kinda asked for it too. 🤔

  • ozoned@lemmy.world
    link
    fedilink
    arrow-up
    56
    ·
    6 days ago

    Chinese company does what American companies have done for 25+ years now!

    Is it time for REAL data privacy laws or are we just gonna keep playing whack-a-mole with Chinese tech companies that get us nowhere?

    • Someonelol@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 days ago

      Our data’s just too valuable for these parasites. Data privacy laws may eventually pass to compel software companies to store everything in US servers only.

      • ozoned@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        6 days ago

        Excellent Point. If that’s the case though, then wouldn’t other countries follow suit which still limits big tech’s reach and makes them less profitable and less powerful? Idk. Guess we’ll see how it plays out. Either way, I’m staying as far from those ecosystems as possible to at least try to mitigate some of what they do. I’ll never be totally successful, genie is put of the bottle, but we can at least attempt.

  • conditional_soup@lemm.ee
    link
    fedilink
    arrow-up
    37
    arrow-down
    3
    ·
    6 days ago

    Yeah, uh… If you think that American companies aren’t doing this same thing and handing your data over to the government without a warrant among other bad uses, I have some bad news for you. This is pretty much par for the course, and I’m pretty sure that we’re witnessing a well financed negative media blitz happening to try and keep OpenAI from getting all of its spaghetti spilled. Watch for the government to try and ban deepseek for “national security” reasons soon.

    • Duamerthrax@lemmy.world
      link
      fedilink
      arrow-up
      3
      arrow-down
      4
      ·
      6 days ago

      Not gonna happen. Someone in China gave to Trump’s inauguration fund, so nothing’s getting banned.