The article discusses the discovery of malware in Pinduoduo, a Chinese e-commerce company, that allows it to access users' personal data without their consent. The malware was found by cybersecurity experts who noticed unusual behavior in the app's requests for permissions.
**Key Findings:**
1. **Malware Discovery:** Cybersecurity experts discovered a piece of malware in Pinduoduo's app that allowed it to access users' personal data, including locations, contacts, and social media accounts.
2. **Exploits:** The malware exploited internet-related security vulnerabilities to carry out attacks on users' devices.
3. **Data Collection:** The malware collected large amounts of user data, including location information, contacts, calendars, notifications, and photo albums.
4. **Regulatory Failure:** The Chinese Ministry of Industry and Information Technology did not detect the malware or take any action against Pinduoduo.
**Consequences:**
1. **User Safety:** Users' personal data was compromised, putting them at risk of identity theft and other security threats.
2. **Regulatory Oversight:** The regulatory failure raised questions about the effectiveness of China's cybersecurity regulations and the ability of regulators to detect and respond to threats like this one.
**Response from Pinduoduo:**
1. **Update Removal:** Pinduoduo removed the exploits from its app after the discovery.
2. **Team Disbandment:** The company disbanded a team of engineers and product managers who had developed the malware, and most of them were transferred to other departments.
**Expert Reactions:**
1. **Tech Policy Expert:** Kendra Schaefer, a tech policy expert at Trivium China, said that the failure of regulators to detect the malware was "embarrassing for the regulator."
2. **Cybersecurity Expert:** A cybersecurity expert with 1.8 million followers on Weibo criticized regulators for their inability to understand coding and programming, making it difficult for them to detect and respond to threats like this one.
**Conclusion:**
The discovery of malware in Pinduoduo highlights the need for stronger regulatory oversight and more effective cybersecurity measures in China. The incident also raises questions about the effectiveness of China's data protection laws and the ability of regulators to enforce them.
**Key Findings:**
1. **Malware Discovery:** Cybersecurity experts discovered a piece of malware in Pinduoduo's app that allowed it to access users' personal data, including locations, contacts, and social media accounts.
2. **Exploits:** The malware exploited internet-related security vulnerabilities to carry out attacks on users' devices.
3. **Data Collection:** The malware collected large amounts of user data, including location information, contacts, calendars, notifications, and photo albums.
4. **Regulatory Failure:** The Chinese Ministry of Industry and Information Technology did not detect the malware or take any action against Pinduoduo.
**Consequences:**
1. **User Safety:** Users' personal data was compromised, putting them at risk of identity theft and other security threats.
2. **Regulatory Oversight:** The regulatory failure raised questions about the effectiveness of China's cybersecurity regulations and the ability of regulators to detect and respond to threats like this one.
**Response from Pinduoduo:**
1. **Update Removal:** Pinduoduo removed the exploits from its app after the discovery.
2. **Team Disbandment:** The company disbanded a team of engineers and product managers who had developed the malware, and most of them were transferred to other departments.
**Expert Reactions:**
1. **Tech Policy Expert:** Kendra Schaefer, a tech policy expert at Trivium China, said that the failure of regulators to detect the malware was "embarrassing for the regulator."
2. **Cybersecurity Expert:** A cybersecurity expert with 1.8 million followers on Weibo criticized regulators for their inability to understand coding and programming, making it difficult for them to detect and respond to threats like this one.
**Conclusion:**
The discovery of malware in Pinduoduo highlights the need for stronger regulatory oversight and more effective cybersecurity measures in China. The incident also raises questions about the effectiveness of China's data protection laws and the ability of regulators to enforce them.