An investigation has uncovered that the Viidure mobile application, used in conjunction with police body cameras, transmits sensitive data to servers located in China. The app sends device identifiers and user data to cloud servers operated by Huawei International Pte. Ltd., specifically connecting to app-api.lufengzhe.com:9091 (IP address 115.175.147.124). The discovery comes as law enforcement agencies increasingly adopt advanced body camera solutions, such as Motorola’s AI-powered SVX device, which focuses on secure, domestic data handling.
Technical analysis revealed that these communications occur over TLS port 9091, an unconventional configuration that differs from standard protocols. The application also connects with Baidu mapping services, using api.map.baidu.com and loc.map.baidu.com for geolocation functionality, with both services hosted in China. The arrangement raises particular concerns given ongoing international scrutiny of Chinese technology companies and their relationships with state authorities.
The findings emerged from network analysis conducted using Wireshark packet captures in an isolated environment to monitor encrypted sessions. The transmission of video-related metadata and device identifiers through servers based in China presents potential implications for data sovereignty and access control, particularly concerning evidence used in legal proceedings. The security concerns mirror recent incidents of law enforcement data exposure, including cases where sensitive information has been compromised through third-party applications.
“As this case demonstrates, low-cost solutions may introduce unacceptable risks, jeopardizing both privacy and prosecutorial efficacy,” said cybersecurity experts involved in the investigation. “Continuous scrutiny of vendor implementations and adherence to stringent cybersecurity requirements remain essential to safeguard public trust.”
The investigation highlights considerations for law enforcement agencies in their evaluation of body camera vendors and associated software, particularly regarding data security protocols and the handling of sensitive law enforcement information by foreign entities. The findings emerge amid growing awareness of data security vulnerabilities, as evidenced by recent incidents such as unauthorized access to government databases and the exploitation of personal information through various channels.
Sources: GBHackers