Educause Security Discussion mailing list archives

DingTalk software concerns?


From: "Bole, Jim A" <jbole () ALBANY EDU>
Date: Thu, 11 Feb 2021 14:08:18 +0000

We have a faculty group planning to teach students at a Chinese university. The university, as well as a lot of folks 
in China, use DingTalk.

Our faculty wants to install it to conduct classes, much in the same manner as they use Zoom.

Anyone have any experience with this?

I do have some privacy concerns for the faculty members using the software. It’s entirely possible that their 
activities would be tracked by someone in China. And that tracking could potentially include things like our network 
ranges, etc.

But it looks like the software itself isn’t malicious. The mobile app has been vetted by Apple and Google.

I’ve reviewed their privacy page: https://page.dingtalk.com/wow/dingtalk/act/privacy-en-lite?

I’ve reviewed their security whitepaper (attached). First time I’d heard of ChaCha20 encryption.

While it does have some interesting language, it covers most of the basics.

It’s an interesting use case and I’d appreciate any feedback.

Jim Bole
Chief Information Security Officer
Information Technology Services
University at Albany



**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Attachment: DingTalk security whitepaper.pdf
Description: DingTalk security whitepaper.pdf


Current thread: