Live data from Hacker News

Lithuania says throw away Chinese phones due to censorship concerns

reuters.com

171–180 of 427 posts

Re: Lithuania says throw away Chinese phones due to censorship concerns

#171

I'm really not sure how serious I should take the threat of Chinese made electronics - almost all electronics are made China, not just Xaiomi and Hauwei. My iphone is made in China by Chinese contract manufacturer (Foxconn) - does that mean all iphones could be compromised with Chinese malware? It could be possible, but how can you tell? Is it possible to observe network packets going form my phone to a Chinese or Ch…

As far as I can tell, the meta solution here is open source hardware and software. Otherwise it just doesn't matter who is doing this, why they do it, or who is affected. The core issue is the lack of end to end encryption and open source hardware and software. Options today are okay, but they need to be great to reach the right people. See my post in this thread about Pinephone and Librem.

[deleted]

Re: Lithuania says throw away Chinese phones due to censorship concerns

#172

What's "decomposition analysis" and how can I do it at home? Since others here are curious, how would one go replicating these results to find the MiAdBlacklistConfig file? Can I download the OS from a website and just search for strings in the MiAdBlacklistConfig file? I'm genuinely interested, rather than using this question to cast doubt on the 32 page research report.

I am curious about this too.

From what I can gather from the report it should be possible to reproduce the analysis. Probably it is even possible to run the apps in question in an emulator.

Also it should be possible to get the full url of the censorship configuation file and also its full contents.

Given the extreme politics around this, I think it would be better if this type of analysis was done as open source and in a completely reproducible manner.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#173
post #169
post #164

Earlier quoted context omitted.

So, what are the other entries, and why were they redacted out?

PDF is here: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi... ...do you want me to post 449 items? :-)

The PDF only have the selected entries. Does anyone have the contents or actual url of the full file?

Re: Lithuania says throw away Chinese phones due to censorship concerns

#174

I'm really not sure how serious I should take the threat of Chinese made electronics - almost all electronics are made China, not just Xaiomi and Hauwei. My iphone is made in China by Chinese contract manufacturer (Foxconn) - does that mean all iphones could be compromised with Chinese malware? It could be possible, but how can you tell? Is it possible to observe network packets going form my phone to a Chinese or Ch…

Presumably Apple ensures there is nothing nefarious in the hardware, but it seems an unlikely avenue for compromise. Most of the "phone" is Apple-provided software. In theory sure, you could have a chip snooping on the bus. But it would have to have a lot of OS-level knowledge and then how would it exfiltrate the data without OS-level access to the IP stack? Like the Bloomberg/Supermicro story, I am extremely skeptic…

how would it exfiltrate the data without OS-level access to the IP stack

Do iPhones use modems embedded in the SoC? Modem firmware can communicate with the cell network without the OS.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#175
post #3

I think you would have to be mad to leave the stock ROM running on a Xiaomi phone, IIRC they were caught logging peoples browser history a few years ago. Several models have mainline LineageOS support, I'm running Lineage on my Mix 2S and hope to have years worth of updates going forward. The hardware is really good value as long as you install an non-tainted OS.

What about Android One?

Android One is moribund and is basically just Nokia now[0].

[0] https://en.wikipedia.org/wiki/Android_One#2020

Re: Lithuania says throw away Chinese phones due to censorship concerns

#176
post #159

Earlier quoted context omitted.

It probably will never be. It just takes one OEM to fuck it up and everyone can use their device ID. That's why hardware backed attestation doesn't work, OnePlus fucked it up and now Magisk can pretend to be that phone and get exempted.

If a Chinese oem loses their keys why not just revoke them?

And cut off the phone from SafetyNet? That would hurt SafetyNet adoption and be bad for Google, which is presumably why they didn't do it for OnePlus.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#177

I wonder how long it will take until $RANDOMCOUNTRY says the same thing about US phones.

There are no mass-produced US phones. Hand-made boutique Purism US-edition doesn’t count.

Technically all phones today have parts sourced or designed in the US. I do not understand how and why HN has such a hate boner for China.

What China does today has been done ad nauseum by the US. China is merely following its footsteps.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#178
post #152

From the shared PDF page 23... "It has been established that during the initialisation of the system applications factory-installed on a Xiaomi Mi 10T device, these applications contact a server in Singapore at the address globalapi.ad.xiaomi.com (IP address 47.241.69.153) and download the JSON file MiAdBlacklistConfig, and save this file in the metadata catalogues of the applications. A list of applications for whic…

Is it me or is this an extremely clumsy way of doing censorship?

Why not do this at network or server-side level? Why not use some kind of hash (ala Apple'e proposed child pornography hunter)?

In this design, everyone would have to have this plain text configuration file ... also other brands (Oppo, Huawei etc.) would have to have it. What if it needs an update? Suppose the hui muslims starts causing trouble ... Or if people starts using slang or deliberate misspelling ...

Re: Lithuania says throw away Chinese phones due to censorship concerns

#179
post #6

Earlier quoted context omitted.

You can replace the user-facing software, but can/would you trust the baseband?

Isn't the baseband Qualcomm code? Do you think Qualcomm allowed Xiaomi to run their own baseband on it?

Only when CPU is Qualcomm I think. I'm not knowledgeable with QPST/QXDM scenes but it didn't sound like firmware integrity mechanisms on qcom modems are too tight.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#180

Earlier quoted context omitted.

> I think the focus on China with respect to privacy is misplaced. This is a problem with many tech companies now. Yes and no. Yes, it is a problem with many tech companies, I agree. But the way China does this is something completely different. Tech companies do this for their profit. China as a country exploits every single avenue to steal information and protect their position.

Stealing information and protecting their position is pretty common in the corporate world, in fact that's how many corporations ensure their continued profitability. What you have in China is equivalent to "US Government" + "Big Tech" - "Bill of Rights".

Given the erosion in the bill of rights here, I suspect things are on a similar playing field. The main difference is the US government only censors using indirect means or by attacking the providers of information like Julian Assange.

Did we forget that the NSA is collecting most of the traffic on the internet?

Post reply on HN