📢 New work out today from our Tech team & China research team: @joinClubhouse app recently became popular in 🇨🇳. We looked at its data security practices & found a potential risk to mainland Chinese users.

🔗 cyber.fsi.stanford.edu/io/news/clubho…

Here are our key findings 👋🧵⤵️

(1/8)
(1) .@AgoraIO, a Shanghai-based startup, provides the backend platform to Clubhouse. This has been widely suspected.

(2/8)
(2) .@joinClubhouse user IDs (not their username — more like a unique serial number) are transmitted in plaintext over the internet, making them trivial to intercept. Chatroom IDs (again, more like serial number) also transmitted in plaintext.

(3/8)
Any observer of internet traffic could easily match IDs on shared chatrooms to see who is talking to whom. For mainland Chinese users, this is troubling

(4/8)
(3) Users’ raw audio is likely but not certainly available to @agoraIO. AgoraIO says it does not store client audio, but PRC Cybersecurity Law could compel the firm to cooperate on handing over user data
@jeromeacohen @fryan

(5/8)
(4) .@joinClubhouse terms state that it temporarily records user audio on its own servers. Unclear where servers are, or how long is “temporary.” If servers are in the US, Chinese govt is unlikely to receive legal access to them
@Riana_Crypto

(6/8)
(5) We also explore how the Chinese govt could crack down on mainland Chinese Clubhouse users, even in subtle ways. We also discuss why China banned the app now
@jenjpan @mollyeroberts

(7/8)
Thank you to our team @elegant_wallaby @jackhcable @noUpside @alexstamos @debutts & @Riana_Crypto for their analysis on this post.

(8/8)

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Stanford Internet Observatory

Stanford Internet Observatory Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @stanfordio

13 Feb
📢 我们Tech team 和 China and Tech research teams今天新发表的研究成果: 我们研究了@joinClubhouse app’s 数据安全措施和中国大陆用户的潜在风险.
 
🔗 cyber.fsi.stanford.edu/io/news/clubho…
 
以下是我们的发现👋🧵⤵️

(1/8)
1. AgoraIO, 一家位于上海的初创企业,一般被猜测为Clubhouse提供了后端平台

(2/8) Image
2. @joinClubhouse用户ID(而不是用户名,更像是唯一的序列号)是通过Internet以纯文本格式传输的,因此很容易被拦截。聊天室ID(再次不是房间名称,更像是序列号)也以明文形式传输。 

(3/8) Image
Read 8 tweets
28 Jan
1/ 📢 Out Today: A new report on the contours of Parler. Our team examines growth dynamics (non) moderation policies, and platform growth in 🇧🇷 and 🇸🇦 .

🔗 and 🧵⤵️

cyber.fsi.stanford.edu/io/news/sio-pa…
2/ Our analysis pulled data from three snapshots of Parler’s roughly 29 months online. We looked at metrics from the API to map join dates and linguistic patterns on the site.
3/ Parler has roughly 800 moderators, but their moderation practices were purely reactive and did little to filter out spam or fraud accounts.
Read 9 tweets
8 Oct 20
🚨Today SIO released assessments of 7 #TakedownThursday info ops removals. On @Facebook 1 network attributed to US consultancy Rally Forge & 1 attributed to the Islamic Movement in 🇳🇬. From @TwitterSafety 5 separate networks attributed to 🇮🇷🇸🇦🇨🇺🇹🇭🇷🇺 🧵⤵️
cyber.fsi.stanford.edu/io/news/twitte…
2\ The Rally Forge network was an astroturfing operation involving fake accounts (some w/AI-gen faces) that left thousands of comments on FB, Twitter, & Instagram. Clients included Turning Point Action and Inclusive Conservation Group, a pro-hunting org cyber.fsi.stanford.edu/io/news/oct-20…
3\ The 🇳🇬 network is linked to the Islamic Movement in Nigeria. With fake accounts, it advocated for the release from prison of IMN leader Sheikh Ibrahim El-Zakzaky. cyber.fsi.stanford.edu/io/news/islami…
Read 8 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!