Live data from Hacker News

Xiaomi Recording ‘Private’ Web and Phone Use

forbes.com

211–220 of 254 posts

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#211
post #184
post #96

Earlier quoted context omitted.

Well the EU and Canada seem to be terrified of putting a foot wrong with the CPC, so my guess is that Chinese companies will violate people's privacy until it becomes so blatant that they get a polite request to tone it down (and obfuscate the collection).

This brand of sharp minded and well sourced political analysis is what I appreciate about HN. The good thing is, I keep seeing more and more of it.

You expect a URL for every word written? The stories showing how everyone in the West bends in order not to anger CPC are out there and well known. You can't have a recap of human history in every comment.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#213
post #184
post #96

Earlier quoted context omitted.

Well the EU and Canada seem to be terrified of putting a foot wrong with the CPC, so my guess is that Chinese companies will violate people's privacy until it becomes so blatant that they get a polite request to tone it down (and obfuscate the collection).

This brand of sharp minded and well sourced political analysis is what I appreciate about HN. The good thing is, I keep seeing more and more of it.

HN comments aren't scientific papers. While (good) references will strengthen any argument and are welcome, I find opinions here valuable even when sources are not immediately available. You can always do your own research and paste links confirming/rejecting any statement if you so desire.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#214

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

OTOH Xiaomi also sent out dev devices to custom rom developers. Well technically it's Poco the Xiaomi subsidiary[1] Is there any word on whether that is true for european region phones as well? From what I remember they disabled certain functionality like Face Unlock in the EU. Not sure if it was due to privacy or patents, but given the GDPR I wouldn't be surprised if it was due to privacy. [1]: https://www.xda-devel…

Oh! That explains why my F1 has such good ROM support, it was a major reason for buying it (another one is cheap replacement parts).

They still disrespect ROM users: You have to go through a convoluted process involving Windows software and a Xiaomi account AND wait 3 days to unlock the phone - but that's way down from the 6 weeks I've read about on other Xiaomis, so you can be sure I'm not going to buy one of those.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#215

Earlier quoted context omitted.

I thought it went: DRM, spyware, then co-opted for malware by others.

Unfortunately I tend to think RM Stallman is right - smartphones are a prison with tracking enabled. We're all foolish to yield that much power to vendors. Most software on the smartphones aren't under our control, we aren't able to stop them, disable them, inspect them, or see the source code. I think we should undo everything done in the smartphone since 2008 and come up with a true open source smartphone.

Purism is working on it. I think they're selling them now.

No idea if it is good just that it's happening.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#216
post #210

Earlier quoted context omitted.

You still have more control compared to iPhone where you cannot change your default SMS messaging app, or even your default browser. And you have no choice in browser engine either. And it's hardly a walled garden when I can sideload any app on any Android phone. Xiaomi even has their own store that's not Google Play.

The assumption is that bad guys have a much harder time swapping out the SMS app for a trojan.

The assumption is that the apps you choose on iOS just won’t be default. You can still have an SMS or mail app that invades your privacy by uploading everything to a remote server, it just wont be given the GUI conveniences of a default app — a big competitive edge.

But it will be difficult to clamp down on leaking user security and privacy when Apple itself has unencrypted backups, so they can’t pressure other companies to proactively protect user data at rest.

I’ve stopped using higher quality non Apple apps because even something like a calendar app or todo app warrants a special private cloud that slurps up your data with a legitimate argument for why they should have everything.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#217

Earlier quoted context omitted.

Problem is lately many banking app required you to use non-root phone, at least in my country. There used to be workaround, but it is not work anymore. I have Redmi phone and I hates it as soon as I found that there is ads in their rom. It's so disappointing. I mean, other Chinese brand have their own crapware yes, but ads? I then flash my phone to pure Pixel rom and never been happier, until the bank app incident ha…

Actually, I installed LineageOS but skip installing root binary (it's an optional step when flashing LineageOS) as I don't need root anymore. Without root I can still use my banking app because Google safetynet is passing on my phone.

There are ways to get around safetynet, though it's a cat-and-mouse game of "detect the root".

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#218
post #199

Google accusing apple of "Selling privacy as a luxury good", well, isn't it? Clearly, if you don't want to be spied on you're going to have to pay a premium.

The profit from your data offsets the cost of the hardware.

If they're not selling your data, then you get to pay full price for the phone. Not a crazy idea, really, but I wish that was made clearer.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#219
So if you do not use preinstalled Xiaomi software, you are mostly OK? (until they start stealing Firefox browsing history)

Having a Xiaomi phone myself there's a trade-off between using the official ROM, that provides full device encryption and SE Linux enforcement, but tracks what you do in settings, and unofficial LineageOS (PHH GSI), that does not encrypt the device data and has SE Linux off on most Xiaomi phones, I ended up sticking with MIUI.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#220
post #4

I recently wiped my factory-unlocked Samsung S20, enabled debug mode, and ran "pm list packages" over ADB. The results were beyond startling. There were close to 100 packages running under com.samsung and other various namespaces with tons of sensitive permissions. Most of these processes I could not identify what they existed for. And I still can't figure out why a freshly wiped unlocked phone w/ a Sprint SIM is run…

I wonder if it is illegal under GDPR to include spying apps on phones without telling the user.

> I wonder if it is illegal under GDPR to include spying apps on phones without telling the user.

It is illegal but it is not enforced.

Post reply on HN