Live data from Hacker News

Xiaomi Recording ‘Private’ Web and Phone Use

forbes.com

181–190 of 254 posts

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#181
post #50
post #6

Earlier quoted context omitted.

There's no such thing as anonymized when it comes to data tracking. "Anonymized" tracking itself is gaslighting.

It's anonymized in the sense that you don't know who it will be sold to and what they will do with it. In all seriousness, this is a point GDPR struggles with. It's really hard to properly define what constitutes personal data.

Disclosure: I'm writing this with my DPO hat on.

The GDPR does specify what is personal data, but doesn't go out giving real-life interpretation examples. The categories given in the regulation are direct identifiers and indirect identifiers. The categories even include a good sampling of information types that belong in each.

Direct allows to identify an individual or a very small group from a single datapoint. Indirect allows to identify larger groups.

Or to put in terms most of us here understand.. Direct identifiers are personal information that would allow to send marketing junk to selected individuals. Indirect ones are those you would use to build marketing cohorts.

So if it's data your marketing department would like to grab, you can bet it's personal information under GDPR.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#182
post #4

I recently wiped my factory-unlocked Samsung S20, enabled debug mode, and ran "pm list packages" over ADB. The results were beyond startling. There were close to 100 packages running under com.samsung and other various namespaces with tons of sensitive permissions. Most of these processes I could not identify what they existed for. And I still can't figure out why a freshly wiped unlocked phone w/ a Sprint SIM is run…

I wonder if it is illegal under GDPR to include spying apps on phones without telling the user.

I work in GDPR-compliance related area in a multibillion UE corporation and I can say that right now, it's all a big joke. We have multiple huge violations and we don't do anything about it (partially because the law is so demanding that implementing it would be a massive effort). And yet, we don't get fined - partially probably because no one blew the whistle yet. I'm pretty sure the situation is very similar in all of our competitors. It seems to me that the lawyers who wrote GDPR might have been out of touch with realities of large and old companies and now the preference on regulators side might not to just not enforce the more bonkers parts of the bill? Interesting how it will play out over the next 5-10 years.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#183

Earlier quoted context omitted.

This is why, without fail, I buy iPhones.

And then you can't install anything Apple doesn't want you to install. I like being able to run gameboy emulators on my phone for games I already paid 20 years ago, change my launcher/dialer, browser, etc.

Emulators running here, from NES all the way up to PSP, on a 6s that's not jailbroken.

You can sideload it yourself if you have a mac, or you can use something like buildstore that gives you a provisioning profile, but that's 7$ a year or something.

Happily paid that. The buildstore also offers things like ad-free youtube and twitch.tv app tweaks, torrent clients, you name it.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#184
post #96

Earlier quoted context omitted.

Parents option would likely get around privacy regulations in some countries. So they can do the “much more work” you mentioned and also sell decent hardware for zero down on a contract, getting a bigger total market and more surveillance info.

Well the EU and Canada seem to be terrified of putting a foot wrong with the CPC, so my guess is that Chinese companies will violate people's privacy until it becomes so blatant that they get a polite request to tone it down (and obfuscate the collection).

This brand of sharp minded and well sourced political analysis is what I appreciate about HN. The good thing is, I keep seeing more and more of it.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#185

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

I wonder how many devices already do this.

> I wonder how many devices already do this.

All Android phones. But they send the data to google and facebook so they must be good.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#186

Earlier quoted context omitted.

It probably depends on the device, but in the best case you are not losing anything. Especially as you can install google services, so Google Play and everything around it works. The only apps that stopped working on my Poco F1 are apps that check for modified Android. For example my Australian digital drivers license app doesn't work as it detects the Android environment as non-standard. I believe you can do some ro…

> but in the best case you are not losing anything. This is starting to not be the case, I couldn't get the wide angle camera working on my newer Xiaomi Mi 10 Lite for example. I had to fall back to miui.eu based rom to get it to work.

That's not an officially supported device. The most recent supported model from that line is the Mi 8, afaik.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#187
post #108

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

You can still open the firmware update file in ghidra, cutter or ida pro. But yeah the trend is troubling. I also believe that it's only a matter of time once the "smart" devices (fridges, TVs, etc) start shipping with 5G modules enabled that send data to the mothership whether you set up WiFi for them or not. Because while you can't buy non-smart TVs, many users don't enable smart features by not connecting them to…

Perhaps a counter trend will emerge from spyware appliances will emerge, where people will pay a premium for "dumb" TVs or fridges from privacy respecting manufacturers. I've read about people already trying to purchase display model/commercial versions of TVs, which doesn't have any unnecessary smart features. The attraction is avoiding unneeded bloat, presumably longevity, and of course, privacy.

There was an interesting discussion on HN recently regarding appliances that can handle open source firmware[1]. Several advantages I've found with open firmware include stability, security, avoiding unnecessary e-waste, you're not locked into a manufacturer that might discontinue support for the device, and privacy. If such appliances existed, I would certainly consider them when purchasing an appliance.

[1] https://news.ycombinator.com/item?id=23001017

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#188
post #50
post #6

Earlier quoted context omitted.

There's no such thing as anonymized when it comes to data tracking. "Anonymized" tracking itself is gaslighting.

It's anonymized in the sense that you don't know who it will be sold to and what they will do with it. In all seriousness, this is a point GDPR struggles with. It's really hard to properly define what constitutes personal data.

> It's anonymized in the sense that you don't know who it will be sold to and what they will do with it.

So "It's anonymized" but It's not anonymized.

> In all seriousness, this is a point GDPR struggles with. It's really hard to properly define what constitutes personal data.

GDPR is good. The problem is that GDPR is not enforced because it might upset Uncle Sam

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#189

Don't use Xiaomi, Huawei or other Chinese smart phone brands if you don't want to your information collected by those Chinese companies and the CCP. That being said Google, Apple and other American companies collect your information too, maybe not as bad, just maybe. We really need good free and open source OS options for smart phones. Like the GNU/Linux options available on desktops.

Off-handedly casting Google and Apple in the same lot with CPC sponsored phone companies is absurd.

Maybe so, but you're not making much of an argument of it.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#190

Earlier quoted context omitted.

If you are a native English speaker kudos for writing "huevos" and not "Cahones" or other of its similar cringy misspellings. But 90% chance you are from the south cone so carry on.

my brain's classifier would predict upon hearing just huevos => mexican spanish. i'd imagine southern cone speakers would say pelotas, but might be way off here.

Not necessarily Mexican: I'm from Spain, and we use huevos (as well as pelotas and cojones). In the context of this post, I would probably use huevos: "qué huevos tiene Forbes publicando este artículo cuando (...)" would be perfectly idiomatic Spanish from Spain.
Post reply on HN