Chinese RedNote App Exposes Sensitive User Data

แชร์
ฝัง
  • เผยแพร่เมื่อ 23 ม.ค. 2025

ความคิดเห็น • 616

  • @bmacd11b
    @bmacd11b 4 วันที่ผ่านมา +160

    Do you see similar traffic using TikTok, Matt?

    • @mattbrwn
      @mattbrwn  4 วันที่ผ่านมา +214

      Great question. I'm guessing no. They have a world class bug bounty program that would catch this stuff.
      Might be a good follow up video 😁

    • @gary5626
      @gary5626 4 วันที่ผ่านมา +22

      Thanks for the video, TikTok follow up is a great idea!

    • @smithsmithington
      @smithsmithington 4 วันที่ผ่านมา

      @@mattbrwn Not to mention TikTok has had eyes on it for a while, if they were sending any data back to the CCP, it would likely be through much more untraceable and encrypted onion routed proxy stuff.

    • @urs915
      @urs915 4 วันที่ผ่านมา +7

      ​@@mattbrwnas a tt veteran id looove to see a wireshark charting of tt :)

    • @rahallde
      @rahallde 4 วันที่ผ่านมา

      The sad thing is that many TikTokers have no problem transferring their data to the inhumane Chinese government while they distrust their own western liberal democratic governments.

  • @pgknox
    @pgknox 2 วันที่ผ่านมา +44

    There’s not a US social media site that wouldn’t sell their mom’s data for a quick buck. I’m all for privacy and security but have no tolerance for hypocrisy.

    • @jnr2349
      @jnr2349 วันที่ผ่านมา

      Pretty much. The working class of all countries are esentially prisoners to the people who run their infrastructure (capitalists).
      And some even defend their own overlords. Isnt that the definition of nationalism?

    • @שלוםוברכה-ז8כ
      @שלוםוברכה-ז8כ 2 ชั่วโมงที่ผ่านมา

      Mark Zukerberg's mom looks ok to me

  • @matthewperlman3356
    @matthewperlman3356 3 วันที่ผ่านมา +93

    I would really like to see this same analysis for Facebook. I would be curious to compare the two.

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา +6

      Lol good one. Pretty sure most people are okay with giving up their data

    • @johnniecinco6698
      @johnniecinco6698 2 วันที่ผ่านมา +14

      Won't happen because nobody will bribe him to do that.
      Oh, sorry... I mean "sponsor" him.😂

    • @realitymyquest
      @realitymyquest วันที่ผ่านมา

      Yes. I think everyone has forgotten the Facebook-Cambridge Analytica data scandal. Everyone has also forgotten Edward Joseph Snowden (former NSA intelligence contractor and whistleblower) has been in hiding in Russia as he leaked the US and global surveillance programs on all private citizens. Everyone must note that even the Telcos have massive data breaches. Everyone is constantly stealing our data.

    • @UCiWrMgES50tlUhV3l6NqjNA
      @UCiWrMgES50tlUhV3l6NqjNA วันที่ผ่านมา

      god bless the CCP for opposing the new world order! if we didn't have them, what the fuck could we ever do about it...

    • @rogerfaint499
      @rogerfaint499 วันที่ผ่านมา +1

      He's forbidden to do that . . .

  • @cool-0501
    @cool-0501 3 วันที่ผ่านมา +59

    Haha, finally, the video of the Chinese software threat theory has finally appeared. As we Chinese would like to think, the "Chinese threat is always the best reason for the US" propagated by the European and American media.

    • @FF-kc7fc
      @FF-kc7fc 2 วันที่ผ่านมา +3

      Wumao

    • @SportsIncorporated
      @SportsIncorporated 2 วันที่ผ่านมา

      The Israelis pushed exploding hardware to Hezbollah. We get hardware from China. I'm buying hardware from China for others to use. You just never know. I'll beat my brains out trying to make the software secure. But I'll never really know that the hardware can't override the software, turn off the system,...

    • @cool-0501
      @cool-0501 2 วันที่ผ่านมา +6

      @@FF-kc7fc 随你怎么说了,哈哈,不在意。你这个反击都很合理的出现。哈哈

    • @lsj58585711195858
      @lsj58585711195858 2 วันที่ผ่านมา

      @@FF-kc7fc 1450

    • @PaulMR007
      @PaulMR007 2 วันที่ผ่านมา

      Yes!

  • @semkol
    @semkol 3 วันที่ผ่านมา +48

    Yeah no shit. Meanwhile the most invasive app on android is? Facebook messenger, literally sniffing all your wifi connected things

    • @OkItsJustSean
      @OkItsJustSean 2 วันที่ผ่านมา

      Difference is, your data is used to influence ads not politics and narratives.

    • @user-et7pl7sw6v
      @user-et7pl7sw6v 2 วันที่ผ่านมา +16

      @@OkItsJustSean Ironic seeing as how much social media influences politics and narratives and even further so by learning your behavior to understand what content you accept and reject to probably enhance its capability in feeding you narratives you would be likely to buy into based on your behavior.

    • @FyerBear
      @FyerBear 2 วันที่ผ่านมา +7

      ​@OkItsJustSean ?????? What about ads about politics and narratives? Lmao. I appreciate your positive thinking but it's woefully naive to think American policies does not influence the ads and content we're served

    • @OkItsJustSean
      @OkItsJustSean 2 วันที่ผ่านมา

      @ Did you actually comprehend what I said? Data companies aren't using your data to influence politics. Data doesn't influence politics. It influences ads. It tells the person with your data what you like seeing. It doesn't influence politics itself. Whereas its been well warned for about a decade now that China and Russia are using your data to figure out how to sneak misinfo into the media you consume. Diff is, the US government doesn't use your data, FB does to sell to other private interests and ads. China sure does and thats a dictatorship. But I'm sure you don't care.

    • @OkItsJustSean
      @OkItsJustSean 2 วันที่ผ่านมา

      @ I think you too have reading comprehension issues. US companies aren't using your data to influence your politics. They using it to keep you hooked and to sell ads. China and Russia use your data to spread for political purposes. Difference is, in America your data goes to Private companies for profit, in China your data goes to dictators for political purposes. But the avg brainrotted ticktok user doesn't know this because you only can comprehend memes.

  • @ChasBlobster
    @ChasBlobster 4 วันที่ผ่านมา +52

    President Xi, please enjoy my clear text cat video. Better story on this app is the us/Chinese interactions on it. Normal people from “enemy” countries speaking directly worries some people.

    • @mikestewart4752
      @mikestewart4752 2 วันที่ผ่านมา +2

      @@ChasBlobster
      1 single American: “I make $50/hr, plus benefits.”
      All of China: 😱😱😱

    • @joshuain2771
      @joshuain2771 2 วันที่ผ่านมา +2

      @@mikestewart4752Dude, I remember arguing with you under a china uncensored video 😂

    • @mikestewart4752
      @mikestewart4752 2 วันที่ผ่านมา +2

      @@joshuain2771 Do you think of me when you fall asleep too? 🌈
      Edit: Kidding of course.

    • @LifeInJambles
      @LifeInJambles 2 วันที่ผ่านมา

      ​@mikestewart4752
      It's been a whole lot of Americans going, "no, really. Those are real numbers." and Chinese people going "I think you're lying. I was always told everyone in America has a big house and a new car, throws away their food when they just want something else, and chooses not to save money because they like to consume" and Americans going "my whole paycheck goes to survival. How am I supposed to save money?"
      Apparently they thought we have free healthcare, and have also been pretty horrified by the cost of ambulances and the practice of charging people who've just had kids to hold their newborn skin to skin.
      Most of them are willing to believe us, but are still shocked by hearing what life is like over here. Some of them are convinced we're outright lying for some unknown reason, though.

    • @rogerfaint499
      @rogerfaint499 วันที่ผ่านมา

      @@mikestewart4752 1 single Chinese: "I make $5000/hr, + benefits"
      All Americans: We gonna die.

  • @Thejakegee
    @Thejakegee 4 วันที่ผ่านมา +118

    I think that’s the point. The people said fu*k it and exposed it on purpose.

    • @2v2
      @2v2 4 วันที่ผ่านมา

      People might think this is an outlandish statement but recently Microsofts own security research team has brought up the same questions surrounding TP-Link Products. Suggesting they may be purposefully exposing their devices in such a way that would aid in chinas cyber offensive operations on edge and IOT devices.

    • @GameHEADtime
      @GameHEADtime 3 วันที่ผ่านมา +1

      yeap i put it on windows my android iphone etc

    • @TurfSurf
      @TurfSurf 2 วันที่ผ่านมา

      💯

    • @OkItsJustSean
      @OkItsJustSean 2 วันที่ผ่านมา +1

      I dont think the avg tiktok user knows anything about about this or where their data goes.

    • @panda_coffeeanimation1992
      @panda_coffeeanimation1992 2 วันที่ผ่านมา

      ​@@OkItsJustSean Most know and very much do not care

  • @dandelion1627
    @dandelion1627 3 วันที่ผ่านมา +47

    It would make more sense if you can actually compare it side by side with meta apps, Facebook, TikTok, Instagram, Google apps, etc.

    • @TwoTreesStudio
      @TwoTreesStudio 3 วันที่ผ่านมา +5

      An employee at any of those companies would be laughed out of the room for even suggesting loading resources from the CDN over raw http.

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา

      @@TwoTreesStudio Oh no my cat pictures are being sent over HTTP ! Ive been hcked

    • @ChasBlobster
      @ChasBlobster วันที่ผ่านมา +2

      @ do you think that's the only way privacy is threatened is with a specific "oops, anyone who can sniff can see it" issue? I mean, even if you're not on any Meta properties if any of your friends ever posts about you, they keep a shadow profile around. Normal stuff, right? Nothing to worry about because it's an "American" company right?

    • @ultravioletiris6241
      @ultravioletiris6241 วันที่ผ่านมา

      @ Of course! Everyone knows that sensitive data can only be accessed by foreign powers through their personally-administered applications hosted on their soil. Other social media companies definitely dont collect dossiers on their users and sell them to data brokers. How ridiculous. If they were doing that everyone would be concerned about national security… right…?

    • @TwoTreesStudio
      @TwoTreesStudio วันที่ผ่านมา +1

      @@ChasBlobster no, I don't think that

  • @MarcoMugnatto
    @MarcoMugnatto 3 วันที่ผ่านมา +53

    As a non-American, who comes from a country whose military dictatorship was admittedly funded by the U.S., and who has a memory and hasn't forgotten the revelations about the NSA, look... I'm soooo worried...

    • @KopieYum
      @KopieYum 3 วันที่ผ่านมา

      The US has been known to backdoor the communications of other countries they are promising to help. They've offered to do it for the Olympics to "help detect and prevent an attack". But we all know they never leave. They won't stop just because the Olympics are over. They're in now.

    • @solarpanel8195
      @solarpanel8195 3 วันที่ผ่านมา +2

      Why? The unity and love going on right now Has to be The Coolest thing I have ever seen in my 30+ years of life. It's insanely beautiful.... Its like pushing everyone to be super positive!! ..Imagine if everyone starts saying no more war. No more division..February 1st is when mass boycotts start! Don't support any mainstream bs! Only support locals, neighbors, Amish, ecovillages, homestead, independent farms etc! Only buy as much fuel as you NEED! Do this until the people in power stop being dicks and give us more affordable items/hemp fuels(only known sustainable fuel source , Henry Ford built and ran his 1st cars on it!) It's time for a change!!! The people in power don't need 10 houses and 13 cars! While most can't even afford ONE! Enough is enough!

    • @solarpanel8195
      @solarpanel8195 3 วันที่ผ่านมา

      Also, why would u be more worried about an ap and it's data, over our own gov who quite literally has been exposed killing MILLIONS... not to mention all the humans who "killed themselves " after trying to change things here...I think we better worry bout that sht 1st, no?😂

    • @user-bh9vf2zu1r
      @user-bh9vf2zu1r 3 วันที่ผ่านมา

      What does disclosing a security vulnerability have to do with Americans? Security Bugs in software/hardware affects every nationality. To make this issue about Americans is ridiculous and out of pocket.

    • @feetpolice7135
      @feetpolice7135 วันที่ผ่านมา +1

      i think the other two commenters are confused.... lmaao....

  • @insidei76
    @insidei76 4 วันที่ผ่านมา +48

    You should take a look at how Messenger (Meta) behaves. What it logs, what "telemetry data" sends home and what it does. You'd be surprized.
    Device info (id, mac,ip, apps name / use, contacts, etc etc), connection info (networks name, map of the network, info on devices in the network id/name/ip/mac), etc etc.
    Have fun.

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา

      Nah FB cant be used as a boogeyman to push recruitment and funding for wars . Not as useful to make videos about. Btw this channel glows hard, i highly doubt he’s even allowed to talk about FB

  • @SuhandiWijaya
    @SuhandiWijaya 2 วันที่ผ่านมา +21

    It makes a lot of sense that first-world country of China is spying on third-world country of Murica 🤣🤣🤣

  • @nahlene1973
    @nahlene1973 วันที่ผ่านมา +4

    For most people, your personal data is less valuable than you think😢
    The true value is when u and millions of others together gives a meaningful statistical trend to the system, but then your data is not personal anymore.

  • @HIGSTERJ247
    @HIGSTERJ247 4 วันที่ผ่านมา +67

    have you tried this approach with Meta and X?

    • @huhwhatwho7895
      @huhwhatwho7895 4 วันที่ผ่านมา +15

      He’s not skilled enough to take on targets like that 😂 that’s why he sticks to random IoT devices 😂

    • @mikestewart4752
      @mikestewart4752 4 วันที่ผ่านมา +27

      @@huhwhatwho7895Says the guy with no content of his own. 🤦‍♂️

    • @deletevil
      @deletevil 4 วันที่ผ่านมา

      @@huhwhatwho7895 I just checked Facebook and X, these apps don't send any user data un-encrypted.

    • @MichaelOfRohan
      @MichaelOfRohan 3 วันที่ผ่านมา +1

      Jesus christ all 3 of you need to just put your phones down for a while you have nothing to fight for your lives are boring and it shows

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา +2

      @@mikestewart4752 I don’t think it requires being a content creator to call one out for selective coverage. That’s kind of like saying only journalists can criticize journalists

  • @JoelBergmark
    @JoelBergmark 3 วันที่ผ่านมา +17

    5:39 Actually the CN name only means it's registered in China, where it is might not be there. I work for Chinese tech giant all our up addresses is CN but actually in our global cloud

  • @gotmilk91
    @gotmilk91 2 ชั่วโมงที่ผ่านมา +1

    Reality-comedian Josh Johnson perfectly explained why TikTok users flooded to XHS, and security vulnerabilities was not the point at all, which is a given on any app; it's U.S. goverment's I own censorship and shadow-ban on certain topics.

  • @Scarecrowswdsmn
    @Scarecrowswdsmn 4 วันที่ผ่านมา +11

    Thanks so much for doing this. I’d love to see what you’re able to get from TikTok, Facebook, Instagram, TH-cam, Twitter/X and so on. It’s important that more laypeople (like me) understand how this traffic works and what of their (my) information is readily accessible. Would love to see a video with simple to advanced advice on protecting your information too.

  • @Gummibri
    @Gummibri 4 วันที่ผ่านมา +43

    Matt,
    As a long time mobile home hacker (not the cool kind, the kind that carrier unlocks phones, flashes custom roms and socially engineers workers to activate non-company phones on their service which should be locked to another carrier...) In my years of experience, I can tell you that running a test like this is already compromised because you used a 3rd party website to download the app and didn't compare the md5 to a copy downloaded from the playstore. We don't know if this APK has been modified or not at this point.

    • @talkingcure
      @talkingcure 4 วันที่ผ่านมา

      how do you know he didn’t checksums?

    • @BOOSTEDDUDE
      @BOOSTEDDUDE 3 วันที่ผ่านมา +5

      Valid point. The website does say "Trusted App" with a green shield though.

    • @jamiej2216
      @jamiej2216 3 วันที่ผ่านมา +5

      youve got a simple understanding of what youre talking about
      not comparings the hashes doesnt just throw this out the window.
      if it were an official paper it could cast doubt. but someone else will do the same tests on the app store version and likely find the same activity.
      the likelyhood of the app version he used having been tampered with significantly is low.
      low enough to overlook on a casual inveatigation like this.

    • @Gummibri
      @Gummibri 3 วันที่ผ่านมา

      ​@@talkingcureI'm a sub and this dude is smarter than I am but it can't be legally admissible evidence in court for example.

    • @I_Am_Your_Problem
      @I_Am_Your_Problem 3 วันที่ผ่านมา

      @@Gummibri Setting the bar lower does not make for a more robust defense.

  • @Timberius
    @Timberius 3 วันที่ผ่านมา +5

    If trying to sound alarm bells for the neophytes, demonstrating that a jpeg destined to be posted publicly anyways, won't hit the mark.
    I was going to link this in a forum but that may be counter-productive because many of those neophytes will just end the video right there.

  • @williambrasky3891
    @williambrasky3891 18 ชั่วโมงที่ผ่านมา +1

    That is the whole reason ppl are using RedNote. I’m afraid you’ve missed the point. (In fact, I’d argue, basic security flaws and all, as an American, it’s safer to use a data hoarding Chinese social media app than a data hoarding American social media app. Considering the rapidly escalating authoritarianism of the US government and the blurring lines between Silicon Valley & the government, I’d argue, as an American Citizen, putting my data in the hands of any American social media company could pose a very real threat to my physical safety. It can happen here. It is happening here. The treat landscape has changed. Now, does that mean the security flaws you demonstrated aren’t serious? Not at all. It’s just, for the time being, everything is on fire. My main priority is making sure I don’t get burned. That means the main reason not to use such a poorly secured app is the man in the middle who is coming from inside the house (which is also on fire and surrounded by hoards of angry fascists).

  • @fonephreak02
    @fonephreak02 4 วันที่ผ่านมา +21

    I'm curious about metas apps, as well as temu and shien

    • @brokencrayon3476
      @brokencrayon3476 4 วันที่ผ่านมา

      Seriously I think US companies are just as bad

  • @bigbigdog
    @bigbigdog 20 ชั่วโมงที่ผ่านมา +2

    Wait!!! Hold up!!! You mean to tell me a Chinese app, built for Chinese people, to use in China, so they can communate with other Chinese people, send data to China??? WHAT?????

  • @jshowao
    @jshowao 20 ชั่วโมงที่ผ่านมา +1

    Literally every social media app exposes user data.

  • @MUCAV_COM
    @MUCAV_COM 4 วันที่ผ่านมา +40

    Android app reads clipboard every open

    • @JessicaFEREM
      @JessicaFEREM 4 วันที่ผ่านมา +15

      tiktok did this too lmao

  • @yechielw
    @yechielw 4 วันที่ผ่านมา +26

    Instead of using all that iptables complication, you can simply setup a custom DNS server using something like dnschef with a wildcard record pointing you workstation's external IP. then configure the phones DNS to use your roge DNS server and have the certmitm listen on port 443

  • @chrisrosenkreuz23
    @chrisrosenkreuz23 4 วันที่ผ่านมา +21

    downloading that app while avoiding a google account... chef's kiss.

    • @I_Am_Your_Problem
      @I_Am_Your_Problem 3 วันที่ผ่านมา

      @chrisrosenkreuz23 You losers and your catch phrases. The world is always going to be beyond your grasp.

    • @PandemoniumMeltDown
      @PandemoniumMeltDown 3 วันที่ผ่านมา +1

      CCP United Front psyop apps are widely and liberally distributed, they want people to have them, no matter what. People with the app are the prize! Like randomly finding a USB stick in the parking lot of the business where you work.

    • @chrisrosenkreuz23
      @chrisrosenkreuz23 3 วันที่ผ่านมา

      ​@@PandemoniumMeltDown perfectly eloquent.

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา

      @@PandemoniumMeltDown I dont think the two scenarios are that relatable.

    • @PandemoniumMeltDown
      @PandemoniumMeltDown 2 วันที่ผ่านมา

      @ Psyop is an engineered attack on minds, hacking the sense of reality and replace it with lies and deception, in order to distract while executing a plan requiring your enemy to be distracted (in this case, using foreigners against their own society, institutions, government).
      A UBS stick in a parking lot is the same, social engineering to disturb a process, bypass a security where you need to either go in and do, or use a useful idiot that will do what you need. Both warfare, both aimed at using what's not yours to gain an advantage you have no right to have.
      You can outline pedantic differences, yet have to realize they are both hybrid warfare aimed at a unique goal: CCP, and other transnational criminal organizations, want to bring the "West" down and replace it with their system of "governance".
      All humans, most, are curious, like a free lunch and have issues; making them easy targets of social engineering. Uneducated humans are a great order of magnitude more vulnerable to such engineering.
      Outraged entitlement, exceptionalism and pride are the fuel of the desire to break rules in a most self-immolating fashion, our enemies understand this and are exploiting it, it's their main "investment", one should realize this by now.
      We have to educate people, it's really that simple; ostrich policies and treating people like children is also self-immolating: one can't do much, legions can do anything.

  • @dabay200
    @dabay200 2 วันที่ผ่านมา +2

    sending traffic to Chinese servers is not surprising since it is a Chinese app that was developed for the domestic market. Just like Google & Facebook would send data to US servers from other geographical locations. The laxed security doesn't surprise me either the developers wouldn't add in this functionality unless they deemed it necessary, data privacy is not a big thing in China.

    • @jshowao
      @jshowao 20 ชั่วโมงที่ผ่านมา +1

      It's not a big thing in the US either, not having data privacy is what makes these apps profitable. It's why so many companies complained about the EU implementing GDPR.

    • @handaxia1251
      @handaxia1251 8 ชั่วโมงที่ผ่านมา

      lol, 🤣 it is obvious if you understand how internet app works. I do not understand why the host made video like this. This video just randomly appear on my feed

  • @YeeeeeHaw1
    @YeeeeeHaw1 4 วันที่ผ่านมา +25

    What have you proved?

    • @kennethmicojoepanganibanvl5161
      @kennethmicojoepanganibanvl5161 วันที่ผ่านมา +2

      Watch the video again.

    • @JasonLaneZardoz
      @JasonLaneZardoz วันที่ผ่านมา

      That at best CCP controlled China often has a terrible standard of software engineering, engineers like myself have know this for a very long time. It's why many western countries backed off from Chinese supplied infrastructure and cancelled 5G projects.
      Those badly witten apps can be taken advantage of by not only the CCP but anyone.

  • @makkam7575
    @makkam7575 4 วันที่ผ่านมา +6

    Just a small note amazing video btw.
    A ton of open source tools are available to reverse engineer android apps just something to look for maybe in the future and tools like frida for example can help to bypass the ssl pinning if present. But usually in the apps I develop, I put everything behind an api gateway so I really don't understand why they have so many different domains (it makes it harder for them because they need to ssl pin the certs for all the domains because the os's system ca certs can be changed easily on a rooted device)

  • @DamishiCloudwalker
    @DamishiCloudwalker วันที่ผ่านมา +1

    I think that was the point, that we really don’t care if the Chinese track is like meta, X, Google, and Microsoft. We just want the content

  • @dunckhan2g
    @dunckhan2g 2 วันที่ผ่านมา +1

    I don't think anyone on it care about that. It's a big fk you to the government.

  • @davidmcken
    @davidmcken 2 วันที่ผ่านมา +1

    And the casualty of encrypting everything, caching...
    If multiple people even on the same LAN are watching the same stream your upstream gets hit multiple times. Its also completely incompatible with multicast. So only the largest providers that can eat the bandwidth costs can survive. Same applies to any sort of video / audio conferencing.

  • @TriVoxel
    @TriVoxel 3 วันที่ผ่านมา +2

    Hey, TBF, maybe the developers don't know any better? If you can, please report this to the developers so they can fix it! Maybe they would pay you as they have been rapidly improving the experience for westerners, no doubt they are investing heavily in improving the app...! I think the app is a net positive and I am more worried about our ISPs monitoring our connections lol

  • @aquatrax123
    @aquatrax123 4 วันที่ผ่านมา +9

    Is the certificate certminm uses installed on the phone? Are you testing to see if the app uses certificate pinning, or if it does not, checking to see if the certificate is trusted by the phones CA store?

    • @mattbrwn
      @mattbrwn  4 วันที่ผ่านมา +14

      Great question!
      No the certmitm cert is not trusted by the phone and so we are not testing for lack of cert pinning.
      We're testing if the app checks the validity of the server certificate at all based on what's in the phone's trust store

    • @sierra991
      @sierra991 4 วันที่ผ่านมา

      I tried to do this on my own but was unable to get past it. it just got stuck at the splash screen

    • @aquatrax123
      @aquatrax123 4 วันที่ผ่านมา +1

      @ What is realy interesting is why the programming language would ignore certificate trust. I dev apps with C# and you have to go out of your way to ignore certificate trust using the WebClient. I don't do any dev for Android so I don't know how it works but I would imagine it would be similar. Perhaps this approach checks a box for the CN gov accessing the data if they are doing MITM on the incoming traffic.

    • @qwertyboguss
      @qwertyboguss 4 วันที่ผ่านมา

      ​@@aquatrax123good point, was wondering the same thing.
      On a side note, came here to comment that indeed you will be able to do q lot more mitm attacks if you add the certmitm certificate to the trusted certificates on the phone. Useful when not testing for attack vectors but want to inspect the traffic.

    • @helmchen1239
      @helmchen1239 4 วันที่ผ่านมา

      ​@@aquatrax123 sometimes your dealing with older and/or poorly maintained APIs that may or may not have a valid certificate at the moment or there are other things that do not fit together for whatever reason. Accepting self-signed certificates would be another reason - though i dont know why anyone would use those for production servers tbh.

  • @buixote
    @buixote 3 วันที่ผ่านมา +3

    NSA is a bigger threat

  • @888YangJi
    @888YangJi วันที่ผ่านมา +1

    nobody is being forced to use Red note. I think that is the most important part.

  • @kiloton5764
    @kiloton5764 4 วันที่ผ่านมา +34

    your pronunciation of little red book is spot on.

    • @mattbrwn
      @mattbrwn  4 วันที่ผ่านมา +24

      thanks :) I did take a couple semesters of mandarin.

    • @bobanmilisavljevic420
      @bobanmilisavljevic420 4 วันที่ผ่านมา

      Saying little red book isn't hard 🤪

    • @SuperSreggin
      @SuperSreggin 4 วันที่ผ่านมา

      yep, not sure about any of the Manderin... but the english part was spot on!

  • @BicycleFunk
    @BicycleFunk 4 วันที่ผ่านมา +4

    Is there any social media that isn't a major, or even minor privacy concern?

    • @FyerBear
      @FyerBear 2 วันที่ผ่านมา +3

      Not really lol. Bluesky or mastodon is what I see security people using, but I think by design you're kind of giving up your information just to have a normal experience

  • @Hugo-zg5kr
    @Hugo-zg5kr 4 วันที่ผ่านมา +103

    People behave like addicts searching for their fix. They become more mindless every day

    • @mattbrwn
      @mattbrwn  4 วันที่ผ่านมา +62

      Yeah watching ppl on Reddit act like they are in withdrawal is kinda sad and funny at the same time

    • @markarca6360
      @markarca6360 4 วันที่ผ่านมา +3

      It is a digital opium, right?

    • @josephsagotti8786
      @josephsagotti8786 4 วันที่ผ่านมา +3

      This isn't the reason why people moved to XHS and you know it.

    • @brokencrayon3476
      @brokencrayon3476 4 วันที่ผ่านมา +4

      @@mattbrwnyou do realize the US and the companies in it are just as bad if not worse than Chinese ones in terms of data harvesting right?

    • @Micron88
      @Micron88 4 วันที่ผ่านมา

      ​@@brokencrayon3476I don't think he said that, did he?

  • @markcentral
    @markcentral 4 วันที่ผ่านมา +71

    The “bro” interface 🤣

    • @dj_chateau
      @dj_chateau 3 วันที่ผ่านมา +2

      This is just the standard interface naming in Linux for a bridge interface starting with 0. It's not showing "bro", it's showing "br0".

    • @jamesbrady9105
      @jamesbrady9105 3 วันที่ผ่านมา

      @@dj_chateau haha

  • @boines
    @boines 4 วันที่ผ่านมา +3

    just like during my days as an Network Analyst doing wireshark tracers etc for apps like fb ig twitter amazon as well as Eu apps and always noticed dns http etc went to outside countries but never understood why. We believed bc of cdn, backups in case country internet ya, loading more dns for load Balnce, etc, etc. Even us apps sometimes route through outside.

  • @scottyz
    @scottyz 4 วันที่ผ่านมา +4

    Your videos are fantastic. Easy to follow and you put everythign in context.

  • @nasenbaer4627
    @nasenbaer4627 4 วันที่ผ่านมา +3

    16:47 Interesting, but what keeps you from adding the cert of a CA that you control to the Android phone? Wouldn't this then allow for a MITM attack on *all* of the TLS traffic?

    • @jackchen314159
      @jackchen314159 2 วันที่ผ่านมา

      big difference. you can manipulate your own device to make it trust any certs you want, that's not the issue. the issue is if client doesn't check certs or doesn't check it "properly" (there are cases even top tier firewall does that), a third party can do MITM attack without access to your device, you won't even know it. For example, a public wifi router.

  • @SportsIncorporated
    @SportsIncorporated 2 วันที่ผ่านมา +1

    Thanks!

    • @mattbrwn
      @mattbrwn  2 วันที่ผ่านมา

      Thanks for the support !!!

  • @skyslycer
    @skyslycer 4 วันที่ผ่านมา +4

    So which sensitive user data is being sent?

    • @mattbrwn
      @mattbrwn  4 วันที่ผ่านมา +9

      Auth tokens and content for starters.

    • @JasonLaneZardoz
      @JasonLaneZardoz 3 วันที่ผ่านมา

      @@mattbrwn 🤯

    • @matpk
      @matpk 2 วันที่ผ่านมา +1

      ​@@mattbrwn when will you travel to Taiwan?

    • @为民程
      @为民程 2 วันที่ผ่านมา

      @@mattbrwn I dont know what you talking about, every app using OAuth2 framework will send auth token for verify, without token, how server verify your account???

    • @Dude-hs7zm
      @Dude-hs7zm 22 ชั่วโมงที่ผ่านมา

      @@mattbrwn but is it only Rednote’s auth tokens?

  • @_____1826
    @_____1826 วันที่ผ่านมา +1

    Do the same thing with facebook, x, or instagram

  • @cameronsmith8986
    @cameronsmith8986 4 วันที่ผ่านมา +207

    Rednote is literally named after Mao's little red book. You deserve to have your data read if you download that

    • @pvim
      @pvim 4 วันที่ผ่านมา +62

      every social media app does that, it boils down to whether you want your data to be stolen by the west or china. But this particular one also has vulnerabilities aside from stealing your data.

    • @gary5626
      @gary5626 4 วันที่ผ่านมา +22

      ​@@pvim Well said without bias. Does anybody know Facebook is the worst of all?

    • @Slushee
      @Slushee 4 วันที่ผ่านมา +21

      From what I've seen, users are aware and they don't care, they say stuff like "take my data" and such

    • @fonephreak02
      @fonephreak02 4 วันที่ผ่านมา +15

      Right? FB messenger is wild as to what it pulls

    • @xpeng121
      @xpeng121 4 วันที่ผ่านมา +17

      That is actually not true

  • @AZ-hj8ym
    @AZ-hj8ym 2 วันที่ผ่านมา +11

    Tiktok needs WiFi to connect to the internet, senetor

    • @bigbigdog
      @bigbigdog 20 ชั่วโมงที่ผ่านมา +3

      I am a Singaporean, senetor

    • @sohon6609
      @sohon6609 18 ชั่วโมงที่ผ่านมา +1

      Did you ever work for the ccp or owning a Chinese passport?😂😂😂😂

  • @robertclark8351
    @robertclark8351 4 วันที่ผ่านมา +2

    Partially garbled audio for anyone else? So is the implication they're not doing cert-pinning Matt, or does it go beyond that?

    • @mattbrwn
      @mattbrwn  3 วันที่ผ่านมา +2

      Tell me you didn't watch the whole video, without telling me...

  • @charlesdoesmore5488
    @charlesdoesmore5488 3 วันที่ผ่านมา +1

    Yet, they don’t even want to touch a Instagram Reel.

  • @no-kd7vf
    @no-kd7vf 3 วันที่ผ่านมา +8

    is this really a surprise for you guys?

    • @mikestewart4752
      @mikestewart4752 3 วันที่ผ่านมา +1

      Right??? 🤦‍♂️

    • @jshowao
      @jshowao 20 ชั่วโมงที่ผ่านมา +1

      It's a surprise to dumb people.

  • @dakotaferris4842
    @dakotaferris4842 4 วันที่ผ่านมา +1

    I tried setting up your mitmrouter and my phone (or any device) could connect to the wifi network but had no internet

  • @bmacd11b
    @bmacd11b 4 วันที่ผ่านมา +1

    Also, if they had a US-based AWS or Azure bucket where they initially push/pull the data, and then dump it to off-site data centers, would we be any wiser?

    • @pvim
      @pvim 4 วันที่ผ่านมา +1

      @@bmacd11b for the user no, but it would definitely satisfy the government as they want access to the servers. For what purpose remains to be a debated thing, security or the ability to control the narrative.

    • @da_cat
      @da_cat 4 วันที่ผ่านมา

      Yes, they would definitely give their citizens data to NSA , 2 digit iq ?

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา

      The Equation Group

  • @kamilhorvat8290
    @kamilhorvat8290 4 วันที่ผ่านมา +13

    Every app with ads exposes sensitive data !

    • @khuntasaurus88
      @khuntasaurus88 วันที่ผ่านมา

      XHS has no ads except very few users (usually girls) promoting their products (sponsored makeup or outfits)

  • @ducky1681
    @ducky1681 4 วันที่ผ่านมา +4

    Well that didn't take too long! I wish people cared more about this stuff..

  • @Robin_8Bit
    @Robin_8Bit 3 วันที่ผ่านมา +1

    They didn't even ban Tiktok in my country, but I'm interested in red note
    I love the chinese

    • @mikestewart4752
      @mikestewart4752 3 วันที่ผ่านมา +1

      Xi Jinping, “Power Must be Caged by the System”, Qiushi, January 22, 2013:
      “We should continue to catch “tigers” as well as “flies” when dealing with cases of leading officials in violation of Party discipline and state laws as well as misconduct and corruption problems that directly affect the people’s interests. All are equal before the law and Party discipline; whoever is involved in a corruption case must be thoroughly and impartially investigated.”
      The results, after 12 years of Xi’s anti-corruption campaign?
      “Corruption is RAMPANT in China!”
      -Victor Gao, Al Jazeera, August 2024 in front of a live international audience.
      The land of arbitrary law enforcement™️.

  • @gaspumprepairservice7009
    @gaspumprepairservice7009 4 วันที่ผ่านมา +2

    Thank you , sir. Out of curiosity .. does TikTok have similar vulnerabilities? I don’t (and won’t) use either, but folks don’t seem to comprehend the risks. ✌️

    • @mattbrwn
      @mattbrwn  4 วันที่ผ่านมา +7

      Tiktok has a world class bug bounty program. They have made significant security investments where this RedNote app clearly hasn't

    • @rob8823
      @rob8823 4 วันที่ผ่านมา

      Are you thinking China doesn't have all the data from TicTok? I think the ban will have the effect of making China cool to the younger generation. Data collection for machine learning will continue to be vacuumed up.

  • @ouyardbird5172
    @ouyardbird5172 4 วันที่ผ่านมา +1

    I would think these clear text protocols would make it easy for China's auditors to gather evidence or info on their Citizens.

  • @Chicken_Massacre
    @Chicken_Massacre 3 วันที่ผ่านมา +1

    So am i wrong for thinking that the apps in Play Store are secure?

    • @FyerBear
      @FyerBear 2 วันที่ผ่านมา

      You're giving up information to any app you download. They do some cursory vetting but there's still plenty of malicious stuff on the app store. Temu, for example, has been found to send texts on your behalf to your contacts without your knowledge. It also collects more data than any shopping app should, which doesn't sound very secure to me

  • @devon12346
    @devon12346 4 วันที่ผ่านมา +6

    Can someone explain the issue I really don't see one

    • @morphingsomething5203
      @morphingsomething5203 3 วันที่ผ่านมา +1

      Do you know what "mitm" is? That's the main problem. :)

    • @devon12346
      @devon12346 3 วันที่ผ่านมา

      @@morphingsomething5203 its a chinese video sharing app not a banking app who cares if someone mitm my videos

    • @melonsauce1474
      @melonsauce1474 2 วันที่ผ่านมา

      Don't US apps do that?​@@morphingsomething5203

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา

      @@morphingsomething5203 So this would go away if they started appropriately utilizing HTTPS and TLS certs?

    • @FyerBear
      @FyerBear 2 วันที่ผ่านมา

      Your data can be intercepted and read with very little effort

  • @pauljames9596
    @pauljames9596 4 วันที่ผ่านมา +4

    Could you do vid on the unplugged phone that's out? By Erik Prince? Curious if it actually does what he advertises it's supposed to do. That would be great if ya could. New subscriber here!

  • @chengyongchen4130
    @chengyongchen4130 3 วันที่ผ่านมา +1

    what is the problem data going to china? rednote was designed for chinese only, rednote didn't invite american users.

  • @OperationDx1
    @OperationDx1 4 วันที่ผ่านมา +4

    Well they probably should not have banned Tiktok. These kids don't care at all about privacy concerns.

  • @aquilafasciata5781
    @aquilafasciata5781 3 วันที่ผ่านมา +2

    Unfortunately, I believe your primary audience already knows this and the people who need to learn aren’t watching 😢

    • @mikestewart4752
      @mikestewart4752 3 วันที่ผ่านมา

      I shared it on Reddit to spread the word.

  • @LuminousWatcher
    @LuminousWatcher 4 วันที่ผ่านมา +1

    Would PCAPDroid be useful here as an alternative to your script?

  • @PrakharNigam-zr5lk
    @PrakharNigam-zr5lk 4 วันที่ผ่านมา +1

    What if I host my reverse proxy in Singapore and route the traffic to china?

  • @RoamingRamble
    @RoamingRamble 2 วันที่ผ่านมา

    the first Image was rednotes logo

  • @MikeTrieu
    @MikeTrieu 4 วันที่ผ่านมา +1

    They didn't do certificate pinning? How embarrassing!

  • @florentinocrt
    @florentinocrt 4 วันที่ผ่านมา +9

    You should totally compare tiktok in the same way. I’m willing to bet it’s not as bad as congress makes it seem.

    • @mattbrwn
      @mattbrwn  4 วันที่ผ่านมา +5

      I would bet the same.

    • @Turnkey_BM
      @Turnkey_BM 4 วันที่ผ่านมา

      If it was so bad they would have shut it down long ago. They wouldn't have let it be "saved" by the incoming authoritarian regime.

  • @YeloPartyHat
    @YeloPartyHat 4 วันที่ผ่านมา +2

    You really know your stuff. I learned some good wireshark and man in the middle knowledge!

  • @PeteThePancake-bh5ks
    @PeteThePancake-bh5ks 4 วันที่ผ่านมา +1

    How about a look at Eufy security cameras etc. Do they use servers in China? and what might that mean for the people who use their products in the US?

  • @whoisjewel0666
    @whoisjewel0666 4 วันที่ผ่านมา +3

    Bro tbh idc id overnight ship a urine sample if they asked

  • @silverstone7778
    @silverstone7778 4 วันที่ผ่านมา +1

    Well, for one you should always block OUTBOUND DNS and only have your Local DNS (DNSmasq, Pihole, ...) resolve to a Couple DNS Servers of your Choice (Cloudflare, Google Public DNS, ...)

  • @kishore87jetty
    @kishore87jetty 4 วันที่ผ่านมา +3

    Hi Matt ,, I would request you to do a tear down on Xiaomi Mobiles as well. Most of the market from India is being taken by these guyes, I myself own a Xiaomi device and wanted to see is there anything that we should be worried about this device and I will send your video as proof of concept to be cautious to buy these devices

  • @talkingcure
    @talkingcure 4 วันที่ผ่านมา +1

    this is amazing content. Thank you Matt, this is what youtube is about and i wish i could show my less-than tech savvy family members this.. but they don’t seem to care about their privacy

  • @TheViktorofgilead
    @TheViktorofgilead 2 วันที่ผ่านมา

    What device did you test with? Was it up to date?

  • @amindamok
    @amindamok 4 วันที่ผ่านมา +12

    What a surprise. An app on your phone exposes sensitive user data.

    • @deletevil
      @deletevil 4 วันที่ผ่านมา +2

      You clearly didn't understand the significance of the un-encrypted transmission here. Phones via this app are sending data in clear text (un-encrypted). All MIM (all men in the middle) can know whatever the app is sending from millions of devices before the data even reaches the chinese servers. This type of unencrypted data from phones for data-brokers/stealers is like unlimited fish for cats.

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา

      @deletevil I thought the bad part was the chinese servers not random US data brokers?

  • @VladThyKing
    @VladThyKing 2 ชั่วโมงที่ผ่านมา

    i have people around me that they say i dont care about my data i just want tiktok and this is why i wanted it to be removed cause its a tumor

  • @dadw7og116
    @dadw7og116 4 วันที่ผ่านมา +4

    "Little Red Book"? Seriously? As in Chairman Mao Tse-tung's "Little Red Book"? Classic 😂

    • @naj7574
      @naj7574 3 วันที่ผ่านมา +4

      my understanding is that it's actually a different word. That Mao's little red book in Chinese is Hongbaoshu, while the "rednote" app is Xiaohongshu. They end up translating the same to English "little red book", now being called "Rednote", but the origins are different. I've seen it explained that the name Xiaohonshu/Rednote, connects to a story in China about a red rope (?) connecting people.

    • @hawrify2148
      @hawrify2148 2 วันที่ผ่านมา

      mistranslation into english

  • @JohnScalla
    @JohnScalla วันที่ผ่านมา

    Oh please, Meta and Google have been doing worse for years. Apple just started and TikTok has ramped up since it came ‘back’. It’s funny to think we actually have control of our data.

  • @Lethaltail
    @Lethaltail 4 วันที่ผ่านมา +7

    I do believe the funniest part was the privacy policy and also terms (which I had agreed to ofc) were only in Chinese. We (all of these users) all just blew through that stuff, already knowing full well that the org is gonna just collect all that they can. It's state-affiliated, of course they're going to.

    • @Lethaltail
      @Lethaltail 4 วันที่ผ่านมา

      On the topic of HTTP, when you do copy a video link from the XHS app, it does come in the form of a http link, no s to be seen. It also gets sandwiched between a ton of "come check this out" text that I have no idea what it says, followed by the video ID, and there's some Emoji sprinkled in for good measure.

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา

      It isnt only outwardly state affiliated apps that collect data , the big ones all do it. Notice how this channel wont ever have an interest in comparing the social media app with some US-based ones and their telemetry

  • @ClumsyCars
    @ClumsyCars 4 วันที่ผ่านมา +1

    maybe you can do a video confirming or dispelling the tiktok meta server switch

  • @ericon.7015
    @ericon.7015 4 วันที่ผ่านมา +3

    Matt what is your confidence in this app you downloaded outside the official app store? Apkpure😮?
    When I do test I prefer download in the official app in the AVD phone

  • @ChasBlobster
    @ChasBlobster 4 วันที่ผ่านมา +3

    Now do a bunch of us social apps

    • @ChasBlobster
      @ChasBlobster 4 วันที่ผ่านมา +1

      (hint: the bad guys, depending on your trust of the 3 letter agencies, perhaps they are the good guys… well they don’t need to sniff anything, they are partners w/Meta and the like - for your own protection of course)

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา +1

      Not gonna happen. This channel glows way too hard to expose inconvenient truths like that

    • @ChasBlobster
      @ChasBlobster วันที่ผ่านมา

      @ "hacker" culture has really evolved since the 90's. there used to be an inherent distrust of our government (as there should be!) but now it's just a bunch of dudes trying to be internet cops and folks who don't believe anything unless it comes from the US state dep't.

  • @Robbie-mw5uu
    @Robbie-mw5uu วันที่ผ่านมา

    could you do something like this for the Temu app?

  • @MXstar189
    @MXstar189 3 วันที่ผ่านมา +1

    hey you do anything with ESP32's? I am developing firmware for a homebrew product. I would like to slow down someone from copying the product.... apparently can encrypt but watching (longtime listener first time caller) your videos I know a lot of stuff can be done so just wondering if you knew or have done anything with those Micros......as always thanks for all the great content

    • @snikrepak
      @snikrepak 3 วันที่ผ่านมา

      never heard of google?

  • @chuckt6381
    @chuckt6381 2 วันที่ผ่านมา

    Dude, jpeg you have extract is just the Rednote logo. No need to encrypt that

  • @gary5626
    @gary5626 4 วันที่ผ่านมา +10

    Honestly, I'm not surprised they developed such a technically lousy app. This should be a small development team. They didnt even bother about the international market and only cater for china market. I suspect they dont have that budget to go big.

    • @petergerdes1094
      @petergerdes1094 4 วันที่ผ่านมา +5

      Yah but c'mon, I know lone developers doing hobby projects who do security better than this.

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา

      @@petergerdes1094 I also know of big corporations who have basically this level of security or worse. The size of a team or budget doesn’t necessarily translate into security improvements

  • @claesmalmberg4806
    @claesmalmberg4806 วันที่ผ่านมา

    We already know all apps in this world collect data, some lost them, some sold them, anything new?

  • @bmacd11b
    @bmacd11b 4 วันที่ผ่านมา +2

    Awesome job and impeccable timing!

  • @theskelet4r
    @theskelet4r 3 วันที่ผ่านมา +1

    Love It,! Thanks for quick and very relevant video Matt

  • @shawna0653
    @shawna0653 3 วันที่ผ่านมา +1

    Yeah, and how much data was harvested by Facebook? I don't care, still using Red Note.

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา

      I dont think Matt cares much about domestic data collection, which is actually more of a present and clear danger to most individuals than collection by a foreign power

  • @BootleggedBatman
    @BootleggedBatman 3 วันที่ผ่านมา +1

    Installing Chinese software in 2025 is wild

    • @ultravioletiris6241
      @ultravioletiris6241 2 วันที่ผ่านมา +1

      Tbh most social medias are just as bad if you really care about data.

  • @Kimberleeannreynolds
    @Kimberleeannreynolds 4 วันที่ผ่านมา +2

    Excellent video mate!! Thanks.

  • @yntenseinfo
    @yntenseinfo 4 วันที่ผ่านมา +1

    I knew it, I suspected since the beginning

  • @fotografm
    @fotografm 3 วันที่ผ่านมา

    Excellent stuff ! I learn a lot from you 🙂

  • @boycycle
    @boycycle 4 วันที่ผ่านมา +4

    Hey Matt, I really appreciate your videos ! I always learn something new either about hardware, network or software when I tune in. Interesting to see what data you can collect with a "basic" tool like wireshark. Looking forward to more videos like this - cheers ! :)

  • @summerflowers1842
    @summerflowers1842 วันที่ผ่านมา

    is it dangerous to have the app or is it as much of a risk as meta apps or tiktok?

  • @notafbihoneypot8487
    @notafbihoneypot8487 3 วันที่ผ่านมา +1

    GrapheneOS user?

  • @ChakaHamilton
    @ChakaHamilton 3 วันที่ผ่านมา +3

    I don't see how this is any different than what Facebook Instagram and Google have been doing since their Inception. 🤷🏾‍♂️

  • @sidharthcs2110
    @sidharthcs2110 วันที่ผ่านมา +1

    Did the feds pay you for this?