Live data from Hacker News

Xiaomi Recording ‘Private’ Web and Phone Use

forbes.com

231–240 of 254 posts

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#231

Earlier quoted context omitted.

Wow, didn't realize android got that bad recently. Makes me not want to leave the iPhone ecosystem. The only benefit Android had was the control. You take that away and make it a walled garden, its just an iPhone...but worse

You still have more control compared to iPhone where you cannot change your default SMS messaging app, or even your default browser. And you have no choice in browser engine either. And it's hardly a walled garden when I can sideload any app on any Android phone. Xiaomi even has their own store that's not Google Play.

More control of apps, but less control over snooping

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#232
post #86

Stuff like this is why without fail, every phone I own gets LineageOS installed immediately. Xiaomi phones have a bootloader unlock timer to try and mitigate sites reselling their phones with modified software, so I had to leave my Mix 2s alone for a few days before I could make it safe to use.

Are there any resources describing what you lose and gain by installing LineageOS? I'd like to know what will stop working before I try it out...

Push notifications are the only downside. However, push notifications are bad for being distracting, so it’s not really a downside. You still get normal notifications

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#233

Earlier quoted context omitted.

The typical response I get to such comments is that Google did get fined 50M once in France. The problem is that not only is it pocket money to them but Google continues to violate people's privacy (Google Analytics still tries to stalk me everywhere without asking for consent first). When it comes to Facebook I am not aware of any investigation or enforcement action being taken despite them being even worse than Goo…

Well you can get rid of Google analytics, you just have to install their Opt-out Google Analytics browser extension and fill in some data. I really wish the EU actually did something worthwhile with the GDPR.

The point of the GDPR is that you don’t have to opt-out, you have to opt-in if you are happy with tracking.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#236

Earlier quoted context omitted.

Source needed. The amount in the article is staggering compared to what Google claims to collect which is in line with the (admittedly not definitive) DNS query logs I monitor every now and then. Also, much of it (e.g. location) can be disabled and there are Android phones that are entirely free of Google and Facebook.

As I said elsewhere on this page, Google Play gets an update from your phone every 2 minutes 24/7 with a lot of privacy settings enabled. Turn on a firewall, I think it was disconnect that showed me this

The content of these updates is what is potentially concerning. Considering how much Play Services now handles, regular updates aren't that surprising, and like I said Android ≠ Google so this doesn't apply to all Android phones. The mechanism described in the article sent every visited URL in the browser and opened app or settings menu on the phone to Xiaomi.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#237

Earlier quoted context omitted.

Source needed. The amount in the article is staggering compared to what Google claims to collect which is in line with the (admittedly not definitive) DNS query logs I monitor every now and then. Also, much of it (e.g. location) can be disabled and there are Android phones that are entirely free of Google and Facebook.

I do know for a fact that Android contacts querries Google severs to pull data from Google services, like YouTube, to fill in extra contact details on the phone. Knowing what Google's business is, I doubt they don't merge that data for a more complete profile. You can try this yourself: Create a YouTube account, upload a picture for the account, don't add details like a phone number. Now create a contact on Android,…

Unfortunately I can't easily test this as my phone doesn't have the Google Contacts app and I sync my contacts with a CardDAV server, not my Google account.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#238

Xiaomi produces one of the best bang for your bucks hardware in the market. Their software is crap though. Ads in the system apps, ui customization that arguably looks worse than stock android, and now blanket tracking like this, though it was always pinging their tracking servers frequently. My pihole logs pretty much full with blocked xiaomi requests until I flashed the phone. Best thing to do when you got an andro…

WRT “bang for the buck”: you have to take the whole picture into account, not just cpu speed/battery life plus price. Taken as a whole, it has a negative bang for the buck Also curious: can you trust the hardware even if you do flash lineageOS? Honestly curious

That's depend your threat model, isn't it? All Android phones rely on black box baseband blobs from the hardware manufacturers. If there is an exploit hidden there, I believe they won't use it just for blanket data collection like this, but only use it for targeted attacks on high value targets (politicians, journalists, magacorp execs, etc). Hopefully they won't bother to use that kind of low level exploits on normal plebs like me. I'm not even sure if iPhones are safe enough when your threat model requires trusting the low level hardware. The only way to avoid it is by using a phone with fully trusted stacks like pine phone or librem 5.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#239

Earlier quoted context omitted.

Maybe those innocent content creators will think twice at contract renewal time, then.

Or just ... buy the DVD / other content type legally available?

Which is what I did for a long time, but now I don't even own a disc player...

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#240
post #145

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

Excuse my naïveté, but who would actually work on such things? How can someone have such low moral standards to, day after day, build systems that secretly remove privacy from otherwise innocent people?

Most people are just following orders at their job, where they've got bills to pay. Morals are not so important on the hierarchy of needs. It might not even be something that crosses those worker's minds because of a much different upbringing/education than yours.
Post reply on HN