DouBao Phone’s Re-entry: From “Breaking in the Window” to “Entering by Default” – The Crisis of Trust in AI Phones Has Not Yet Been Resolved
Hello everyone, I’m your financial observer. Today, we’re talking about the much-anticipated yet cautiously viewed DouBao Phone.
Last December, it made its debut with cool features like automatically ordering food and responding to messages. However, due to its excessive permissions, it was banned by major banks and payment platforms, resulting in only 30,000 units sold before it was quickly taken off the market. At the time, many thought this was just an embarrassing setback in the exploration of AI phones.
Unexpectedly, 10 months later, the official version of the DouBao Phone has made its comeback. This time, it’s under a new name, “SAEP” (Screen Automation Operation Declaration Protocol), claiming to be more secure and compliant. But upon closer inspection, you’ll find that the underlying logic remains the same: it’s still that “universal key,” only now it waits 30 days before “entering” if you don’t stop it.
Is this a victory of technological progress, or another test of the boundaries of privacy? Let’s break down the news and discuss it from five perspectives.
---
Summary: From “Wild Growth” to “Moderate Overreach”
In simple terms, this news reports that DouBao Phone, a product under ByteDance, has re-entered the market with an “upgraded” security protocol after facing industry resistance due to its previous excessive permissions.
- Last December: DouBao Phone used the highest level of permissions in the Android system (INJECT_EVENTS) to directly control other apps like a hacker, leading to its ban by banks, WeChat, and Alipay, and resulting in poor sales.
- Today: The official version of DouBao Phone has been released with the SAEP protocol, which seemingly gives third-party apps the option to refuse, and there’s a 30-day notice period.
- Essential Conflict: Despite the more formal packaging, DouBao still holds system-level “god-like” permissions. Other major manufacturers (Huawei, Xiaomi, Apple, etc.) use structured interfaces that require explicit authorization, while DouBao continues to use indirect methods (simulated clicks with default permissions).
- Industry Context: Financial regulations have tightened, explicitly prohibiting unauthorized automation. Even ByteDance’s own Volcano Engine has contributed to these standards, yet DouBao’s approach goes against them.
In one sentence: DouBao Phone isn’t truly “official” this time; it’s more like “waiting 30 days to see if you’ll lock the door before entering.” In a critical period for building trust in the AI ecosystem, this “default consent” logic may be even harder for the market to accept than last year’s aggressive behavior.
---
Analysis 1: Is the “Universal Key” Still There? – Unchanged Technical Underlying
Many users think “AI phones” are intelligent, but as professionals, we need to see how they achieve that.
- Last Year’s Problem: DouBao’s automation relied on INJECT_EVENTS, giving it control over apps like a hacker, allowing it to read bank passwords and chat records.
- Consequence: Banks and payment platforms banned it for posing a security risk.
- This Year’s Change: The official version still uses INJECT_EVENTS, indicating no change in technical foundation. DouBao still has system-level control over apps.
- Importance: With this permission, it can read and simulate any app’s actions. Other manufacturers use structured interfaces for safer interactions.
- Conclusion: As long as the underlying permissions remain, DouBao holds a sword of Damocles over user privacy.
---
Analysis 2: Is the SAEP Protocol a “Umbrella” or a “Trap”? – The Logic of the 30-Day Notice Period
The biggest selling point of the SAEP protocol is its professionalism.
- Official Claim: Third-party apps can choose to allow or deny DouBao’s actions, with options like restricting screenshots and inputs.
- Criticism: There’s a 30-day notice period; if developers don’t explicitly deny it, DouBao gets permission after 30 days.
- Opt-out vs. Opt-in: Major platforms require explicit consent, while DouBao relies on developers’ inaction.
- Risk: This passive authorization can lead to unforeseen consequences for both developers and users.
- Industry Standards: Financial regulations require explicit authorization, but DouBao’s approach contradicts these standards.
Conclusion: SAEP gives apps a choice, but it essentially uses silence as consent, lowering privacy protections.
---
Analysis 3: Double Standards in Industry Standards? – ByteDance as Both Judge and Player
The “Financial Intelligent Entity Security Group Standards” were jointly developed by leading firms, including ByteDance’s Volcano Engine.
- Conflict: ByteDance is both a standard setter and a violator of these same standards.
- Industry Consensus: Clear authorization is essential in sensitive financial fields.
- Implication for DouBao: Its approach may undermine trust in the AI ecosystem.
---
Analysis 4: User Attitudes Have Changed in 10 Months – From “Amazement” to “Caution”
In the past, users were amazed by AI’s capabilities, but now they’re more cautious.
- 10 Months Ago: AI’s functionality was the main selling point, and privacy concerns were secondary.
- Today: Users understand that AI relies on app ecosystems for functionality and trust.
- DouBao’s Dilemma: Its previous behavior has created trust issues, and industry standards require explicit authorization.
---
Conclusion
DouBao Phone’s re-entry is a battle for the development path of AI agents. Technically, it still relies on risky permissions, commercially it tries to lower barriers with default consent, and trust-wise, it faces challenges from both users and regulations.
For consumers, if you want automation but are willing to risk privacy, DouBao might be an option. However, for those concerned about data security and ecosystem stability, manufacturers like Huawei and Apple are more trustworthy.
Remember: In the AI era, trust is more valuable than power. Whether DouBao aims to gain market share through technology or trust remains to be seen.