FINDING · DETECTION

YY version 7.1 silently exfiltrates the full text of any triggering message via HTTP GET to sere.hiido.com, including sending user ID, receiving user ID, and the triggering keyword. The surveillance endpoint authenticates using md5(⌊unix_epoch/1000⌋ + ";username=report;password=pswd@1234") with hardcoded credentials, making the surveillance traffic structurally distinguishable from normal YY traffic.

From 2015-knockel-everyEvery Rose Has Its Thorn: Censorship and Surveillance on Social Video Platforms in China · §4.1.1 · 2015 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
keyword-filtering

Extracted by claude-sonnet-4-6 — review before relying.