Live data from Hacker News

Xiaomi Recording ‘Private’ Web and Phone Use

forbes.com

121–130 of 254 posts

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#122
Xiaomi produces one of the best bang for your bucks hardware in the market. Their software is crap though. Ads in the system apps, ui customization that arguably looks worse than stock android, and now blanket tracking like this, though it was always pinging their tracking servers frequently. My pihole logs pretty much full with blocked xiaomi requests until I flashed the phone.

Best thing to do when you got an android phone, especially from a chinese manufacturer, is to flash LineageOS on it.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#123

On a Xiaomi device myself. Recently I've setup Nextdns.io to resolve all the DNS requests through it. Very frequent callbacks to Xiaomi servers for tracking. Blocked a bunch of them now, but it's half a solution.

I use this[1] hosts list that's designed to block almost all useless domains Xiaomi tries to contact. In addition to that list I manually blocked this domain[2] that Xiaomi only connects to on certain countries.

I'm using a Xiaomi with Android One and despite having opted out of analytics the phone still tries to connect to Xiaomi servers.

I've been considering installing LineageOS on it for some time but unlocking the bootloader unfortunately deletes everything I have installed or downloaded. I've never used the stock browser though, always Firefox.

[1] https://raw.githubusercontent.com/jerryn70/GoodbyeAds/master...

[2] app.chat.global.xiaomi.net

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#124
post #10

The fucking huevos on Forbes to publish this article alongside the most godawful CCPA opt-out flow I've seen yet... Clicking the "do not sell my info" link takes you to a page where it asks you for your personal information to request to opt out... with the fine print telling you that you can actually opt out by going back to the previous dialog, selecting more info, then selecting one of the three cookie sections (w…

> The fucking huevos on Forbes to publish this article alongside the most godawful CCPA opt-out flow I've seen yet...

At least they aren't peddling malware anymore.

https://www.engadget.com/2016-01-08-you-say-advertising-i-sa...

> Pot calling the kettle black much.

Do you expect any better from authoritarian/authoritative sources? Welcome to the wonderful world of hypocrisy.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#125

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

OTOH Xiaomi also sent out dev devices to custom rom developers. Well technically it's Poco the Xiaomi subsidiary[1]

Is there any word on whether that is true for european region phones as well? From what I remember they disabled certain functionality like Face Unlock in the EU. Not sure if it was due to privacy or patents, but given the GDPR I wouldn't be surprised if it was due to privacy.

[1]: https://www.xda-developers.com/poco-x2-custom-rom-kernel-dev...

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#126
post #86

Stuff like this is why without fail, every phone I own gets LineageOS installed immediately. Xiaomi phones have a bootloader unlock timer to try and mitigate sites reselling their phones with modified software, so I had to leave my Mix 2s alone for a few days before I could make it safe to use.

Are there any resources describing what you lose and gain by installing LineageOS? I'd like to know what will stop working before I try it out...

If your device is officially supported, chance that you won't lose anything. Unofficial builds (made by community members for devices without official support) vary by quality though, and may not support all the hardware available in the phone.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#127
post #2

There's too much to quote, but scroll down to Xiamoi's responses. Man, that is the quintessential example of gaslighting. "No we didn't, that's not true at all. Well, we kinda did, but it's 'anonymized', so it's okay." "But we have video of your device sending data to..." "...but, but, anonymized!" "I thought you said you weren't sending data at all, now it's just anonymized browser data, but we see your devices send…

Rome was not built in a day! They need time to aquire the sophistication of the US data brokers.

And yet the empire was brought down from within...

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#128

Earlier quoted context omitted.

The question of the GDPR is not whether it's illegal but whether anything is done to crack down on offenders. Facebook, Google and thousands of marketing/analytics/advertising companies are still around and are stalking users with total disregard of the GDPR, so that's a clear negative.

Would someone who is downvoting this be willing to explain why? Because I have the same impression (that many GDPR rules are simply being ignored because enforcement is lacking).

The typical response I get to such comments is that Google did get fined 50M once in France. The problem is that not only is it pocket money to them but Google continues to violate people's privacy (Google Analytics still tries to stalk me everywhere without asking for consent first).

When it comes to Facebook I am not aware of any investigation or enforcement action being taken despite them being even worse than Google when it comes to privacy and having proven their malicious intent and complete disregard for the privacy multiple times.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#130

Earlier quoted context omitted.

Systemless root + root hiding is a thing. I run a custom rom and pass safety check and have access to all my apps including banking.

Any information on this. I thought rooting was essentially dead

I have an S5 with Magisk. It passes the safetynet checks, and I can choose to specifically hide root status from apps, which has worked well so far.
Post reply on HN