Machine Translators May Leak Confidential Information
ID: fbb22e97-0305-5420-84cc-90866b73b7a6
STIX ID: report--fbb22e97-0305-5420-84cc-90866b73b7a6
Feed Name: Zscaler Security Research Blog
The report analyzes the Youdao desktop translation tool and demonstrates that it transmits user-highlighted text and related metadata over unencrypted HTTP GET requests, exposing potentially sensitive or confidential content to anyone able to passively sniff the network. The authors tested multiple versions, reconstructed a sample plaintext query containing confidential-looking content and application context (notepad.exe), and recommend verifying whether HTTPS can be enabled, pausing translation, and avoiding deployment of such cloud-based translation tools in confidential environments unless secure transport and privacy assurances are confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
