MODA Warns of Cybersecurity Risks in Chinese-Made Apps

Taipei: Taiwan's Ministry of Digital Affairs (MODA) on Wednesday said the public should be alert to cybersecurity risks posed by four Chinese-made mobile apps, including Amap, which currently tops both the Android and iOS download charts for navigation apps in Taiwan. The other three apps covered in the review were video platforms bilibili and iQIYI, and messaging app BIMOBIMO, according to MODA's Administration for Cyber Security (ACS), which announced the findings at a news conference in Taipei.

According to Focus Taiwan, ACS Director-General Tsai Fu-Longe stated that the key concern with Chinese-made apps is their potential to transmit data to China, posing "a greater risk to national security." This is a significant concern that MODA aims to highlight to the public. Further elaborating on these risks, ACS senior official Lee Yu-wei explained that under China's Cybersecurity Law and National Intelligence Law, companies behind the four apps might be obligated to hand over user data, including that of Taiwanese users, to Chinese authorities.

The ACS conducted tests on the four apps using 15 indicators across four categories: reading data from other apps, collecting and sharing user data, accessing users' device information, and reading users' activity. Among the apps tested, Amap exhibited the highest number of risk behaviors, with 11 detected on Android devices and eight on iOS devices. Risk factors common to both operating systems included continuously reading users' location, accessing contacts, and obtaining audiovisual data and microphone permissions.

Tsai further explained that ACS compared Google Maps and Amap, revealing that the Chinese developer of Amap requested more privacy-related permissions. Notably, the Android version of Amap was found to transmit data even when closed. He advised users to remain vigilant about risks posed by all apps, not just those made in China, by scrutinizing requested permissions for their reasonableness and using cybersecurity tools as necessary.