In simply 17 days after release, Temu surpassed Instagram, WhatsApp, Snapchat and Shein at the Apple App Retailer within the U.S., consistent with Apptopia knowledge shared with CNBC.
Stefani Reynolds | Afp | Getty Photographs
The U.S. has accused bargain buying groceries web site Temu of conceivable knowledge dangers after its Chinese language sister app was once pulled from Google’s app retailer over “malware” — however analysts say they are now not that nervous.
In comparison to Pinduoduo, which was once suspended through Google in March after variations presented outdoor Google’s Play retailer had been discovered to include malware, Temu is “now not as competitive,” one analyst mentioned.
The malware in Pinduoduo was once discovered to leverage particular vulnerabilities for Android telephones, permitting the app to avoid consumer safety permissions, get admission to non-public messages, alter settings, view knowledge from different apps and save you uninstallation.
Google known as it an “known malicious app” and advised customers to uninstall the Pinduoduo app, however the Chinese language on-line store denied the ones claims.
In line with research through Kevin Reed, leader knowledge safety officer at cybersecurity company Acronis, Pinduoduo requests for as many as 83 permissions — together with get admission to to biometrics, Bluetooth and details about Wi-Fi networks.
“A few of these permissions Pinduoduo is calling appears to be sudden for an e-commerce app,” mentioned Reed, who shared his research of each apps with CNBC.
“However Temu isn’t as competitive as Pinduoduo this is inquiring for a wide variety of privileges,” mentioned Reed.
Pinduoduo is a China-based e-commerce app that sells the whole thing from groceries to clothes. It’s the flagship manufactured from Nasdaq-listed Chinese language corporate PDD Holdings which additionally owns Temu. Temu’s headquarters are positioned in Boston.
Pinduoduo is a lot more competitive in amassing customers’ knowledge and clearly switch it again to the corporate.
Kevin Reed
leader knowledge safety officer, Acronis
“There must be little need for biometric knowledge to be saved on an e-commerce website online or app. I in my view would not need my biometric knowledge to be saved anyplace else as opposed to my instrument,” mentioned Sean Duca, vp and regional leader safety officer for Asia Pacific and Japan at cybersecurity company Palo Alto Networks.
“Biometrics have so much larger price than the rest, as a result of I will’t merely exchange my fingerprint in any respect, in contrast to passwords,” mentioned Duca.
He additionally puzzled why get admission to to Wi-Fi knowledge was once essential. Whether it is company Wi-Fi that the consumer is attached to, it’ll “turn out to be an overly profitable goal for cyber criminals the place they begin to if truth be told achieve get admission to to this knowledge,” cautioned Duca. “However why does an e-commerce supplier if truth be told want that?”
What does Temu do?
Temu, dubbed a copycat of fast-fashion label Shein, is taking the U.S. marketplace through hurricane.
Simply 17 days after its release in September, the app surpassed Instagram, WhatsApp, Snapchat and Shein at the Apple App Retailer within the U.S., consistent with Apptopia knowledge shared with CNBC. It introduced within the U.Ok. in March, simply weeks after coming into Australia and New Zealand.
The truth that Pinduoduo “has asked much more permissions than Temu app even if they appear to be a equivalent roughly packages turns out over-intrusive to me,” mentioned Reed.
“Pinduoduo is a lot more competitive in amassing customers’ knowledge,” mentioned Reed who claimed the knowledge was once “clearly [transferred] again to the corporate.”
PDD Holdings didn’t reply to CNBC’s request for remark relating to the ones permissions.
When compared, the Temu app requests for twenty-four permissions, mentioned Reed. A few of these permissions come with get admission to to Bluetooth and details about Wi-Fi networks.
I’m much less nervous in regards to the buying groceries apps than social media platforms like TikTok and Lemon8.
Lindsay Gorman
Senior fellow for rising tech, German Marshall Fund
“There were no studies of the malicious capability found in official Play, App Retailer or third-party variations of Temu. The keys used to signal the Pinduoduo malware don’t seem to be the similar keys used to signal the Temu app,” mentioned Daniel Thanos, vp and head of Arctic Wolf Labs, the risk intelligence arm of cybersecurity company Arctic Wolf.
“In accordance with our research, apparently that this malware is focused on Chinese language customers basically, as apparently to focus on units typically bought and utilized in China reminiscent of Xiaomi, Vivo, Oppo, Samsung, and so on, and their corresponding packages,” mentioned Thanos. PDD Holdings didn’t straight away reply to CNBC’s request for remark.
Knowledge dangers
In a document on Chinese language “instant style” platforms printed in April, the U.S.-China Financial and Safety Evaluate Fee accused Temu and Shein of posing conceivable knowledge dangers.
Shein and Temu “basically depend on U.S. shoppers downloading and the use of Chinese language apps to curate and ship merchandise,” mentioned the document.
“Those corporations’ business good fortune has inspired each established Chinese language e-commerce platforms and startups to duplicate its fashion, posing dangers and demanding situations to U.S. laws, rules, and rules of marketplace get admission to,” it mentioned.
Chinese language-owned apps face intense scrutiny within the U.S. over safety issues. U.S. lawmakers have cautioned that any Chinese language-owned apps might be at risk of knowledge privateness breaches or interference from the Chinese language executive.
Whilst politicians frequently accuse Chinese language firms of handing knowledge over to the Chinese language executive, there’s no proof to strengthen such claims.
“However there may be additionally a bigger play right here, which is many different apps that don’t seem to be mentioned also are amassing knowledge and feature been doing so for one of these very very long time,” mentioned Duca, noting it’s extra of a systemic downside.
Learn extra about tech and crypto from CNBC Professional
One analyst mentioned she was once much less nervous about buying groceries apps than social media platforms reminiscent of TikTok and its sister app Lemon8.
“From a countrywide safety perspective, along with developing consumer profiles with a majority of these knowledge, social media platforms additionally have the option to choose, advertise and demote content material in accordance with opaque metrics that in the end, we do not in reality have an perception into,” mentioned Lindsay Gorman, senior fellow for rising tech on the German Marshall Fund.
For buying groceries apps, the “actual kind of content material affect” could also be Chinese language firms selling their merchandise which “feels much less of a risk to democracy,” mentioned Gorman. As an alternative, social media apps may just advertise content material about political subjects that are a lot tougher to trace, she mentioned.
TikTok faces a conceivable ban within the U.S. after its CEO Shou Zi Chunk’s testimony prior to Congress, which did not quell lawmakers’ issues in regards to the app’s ties to China or the adequacy of Challenge Texas, its plan to retailer U.S. knowledge on American soil.
“ByteDance isn’t owned or managed through the Chinese language executive. It is a non-public corporate,” Chunk mentioned all the way through the listening to.
In his first public interview because the congressional listening to, Chunk mentioned on the TED2023 convention remaining week: “We’re development all of the gear to forestall any of [Chinese government interference in U.S. elections] from taking place.”
He mentioned he was once “very assured” the chance may also be lowered to as shut as 0 with the corporate being “very, very a ways alongside” with Challenge Texas.
Every other analyst, Glenn Gerstell, senior consultant at Heart for Strategic and Global Research, mentioned those apps are “in the end managed through Chinese language events and that is the reason what the American political device goes to be fascinated about.” Geopolitical tensions with China will proceed to position Chinese language apps below scrutiny.
“It can be that if we were given extra subtle, we would be able to distinguish one app from every other and create a more secure, extra restricted and regulated house. However at this time, we do not need that device in position,” mentioned Gerstell.