Do not use Baidu AV

Status
Not open for further replies.
I don't think so.. Since the in your face video's have been removed from this site,,!
 
I'd like to remind everybody that Baidu software products have been known in the past to produce Adware, pop-ups, browser hijacking, toolbar kind of behaviour. See the explanation of one such infection on our very own site: http://malwaretips.com/blogs/adware-win32-baidu-a-removal/

Of course in this case, I believe the most likely culprit would be a PUP software that has bundled itself with Marg's download of Baidu Antivirus. Although for those of you still not convinced I'd like to point out this rather scary paragraph from their EULA (license agreement which applies as soon as you use Baidu):

3.9 Users agrees that Baidu may collect the follow personal information:

1. User's system information: list of installed software, msconfig list, service list. Operating system version, browser version, mac address of the network card, hard drive serial number, memory, system structure ( 32 /64 ).

2. Behavior information of the Software itself: installing, uninstalling, daily activity, upgrade requests, etc.

3. User behavior data: including the features used and button clicked by the User.

4. PE files ** (exe, dll, sys file ) from user's computer, PE file path will be uploaded.

For example, if a new file gtapi.dll is created on a User's computer, our anti-virus products will upload this file and the file path (C:\Users\renzhijie\AppData\LocalLow\Sun\Java\jre1.6.0_20\gtapi.dll) to our server for identification.

5. ** The Portable Executable (PE) format is a file format for executables, object code, DLLs, FON Font files, [1] [2] and others used in 32-bit and 64-bit versions of Windows operating systems. Please refer to the address below for further details: http://en.wikipedia.org/wiki/Portable_Executable. As to URLs visited by the User, to verify the safety of such visited URL, for example, a user visited with a browser http://www.google.com, our anti-virus products will upload this URL to our server for identification.

Interestingly enough, this paragraph appears in the terms on the website, but not in the EULA agreement shown in the software o_O:

Now you see it: http://antivirus.baidu.com/en/license_agree.php
Now you don't: http://antivirus.baidu.com/en/eula.html

Note this line from the Baidu EULA (lower link):

3.7.2 User agrees that this Software will make reasonable efforts to protect the privacy and integrity of user's computer resources and computer communications. However, user acknowledges and agrees that Baidu provides no guarantee in this regard.

I personally think this clause is in very poor taste Baidu, and very suspicious. Especially when you consider the information collected, as I quoted above. It's also illegal in most parts of the world for a company to fail to guarantee the security of user data. I have reported this to Baidu and encouraged them to respond here. Let's see if they reply and what they have to say for themselves.

Be careful what you download ;)
 
Last edited:
for qihoo:
" Device information. We may collect device-specific information, including your operating system version, system language, and IMEI number.
  • Log information. When you use our Services and Software, we may automatically collect and store certain information on our servers related to your use of our website or Services and Software to help us improve the quality of our products and service. This may include:
  • The manner in which you use our website or Services and Software, including how frequently you install, use or uninstall our Software and its features.
  • IP address.
  • Information collected relating to installed programs scanned by Software features. The information uploaded onto our 360 cloud security center ("360 Cloud Security Center") servers for virus scanning include: file paths and MD5 checksums of the executable files, installed software names, package names, software signature certificates, and software URLs in conjunction with our filtering feature, which we apply to suspicious URLs when you use 360 Internet Protection (this information is processed with encryption).
  • URL information. URLs of websites that you visit will be uploaded to 360 Cloud Security Center servers for phishing and online fraud analysis. Any Personal User Information will be removed from the URLs before they are uploaded. The information is processed with encryption before the upload.
  • Unique Serial numbers. When you use certain services, they might have a unique 360 serial number. This serial number and certain information about your installation (for example, the type of operating system on your device) may be sent to Qihoo 360 when you install or uninstall Software or when Software periodically contacts our servers, such as in a check for automatic updates.
  • Local storage. We may collect and store information (including personal information) locally on your device using mechanisms such as browser web storage (including HTML 5) and application data caches. Such information includes: user settings, file whitelist and blacklist used to accelerate file scanning.
Soooo goooood ...

Source : http://www.360safe.com/privacy.html
 
The main problem with Baidu @thepierrezou is that they state they do not guarantee the privacy of user data. Which basically gives them free license to distribute it to other companies, organisations, governments as they please without justification or accountability.
 
You always say Badiu instead of Baidu!

Hahaha... Oops http://malwaretips.com/styles/MalwareTips/xenforo/clear.pnghttp://malwaretips.com/styles/MalwareTips/xenforo/clear.png I have no idea why! I'll go through and correct them :)

It's my little Cow-isms that make me who I am ;) :P
 
  • Like
Reactions: FreddyFreeloader
Very useful informations, BUT, can anyone name an AV vendor who does not use the user's personal data?
The Chineese companies spies on us.....ok, the USA companies dont do it?
You can sue US companies, try suing a Chinese company. And, just look at the Chinese government trying to blackmail/extort Microsoft.
 
  • Like
Reactions: Cowpipe
Very useful informations, BUT, can anyone name an AV vendor who does not use the user's personal data?
The Chineese companies spies on us.....ok, the USA companies dont do it?

To be honest, it isn't specifically the information they collect that concerns me, but rather their attitude towards it. Take the Kaspersky EULA for example. They collect personal data, but they also include safeguards such as:

5.4. The Software does not process any personally identifiable data and does not combine the processed data with any personal information.
Source: http://support.kaspersky.co.uk/8752
 
  • Like
Reactions: thepierrezou
I insist....From the moment you use the internet your privacy is more or less exposed.
ALL antivirus vendors use user's data, some refer to it ''gently'' others not, but in the end...our privacy is compromised.
Personally i dont complain about it. China, USA, Europe etc....they ALL spy one way or another.
 
Status
Not open for further replies.