Live data from Hacker News

Lithuania says throw away Chinese phones due to censorship concerns

reuters.com

281–290 of 427 posts

Re: Lithuania says throw away Chinese phones due to censorship concerns

#281
post #234

Earlier quoted context omitted.

I guess it comes down to, why bother when the simplest solution works ? Make no mistake: As and when they get caught out doing such things, the sophistication of their implementation is bound to increase, in response to it. Money is no object for state-actors and mega-corps.

It may not be a state actor. I am the last person to defend the CCP, but as the chinese phones are made by companies that have lots of reason to fear the government, this may be proactive censorship added by the vendor to avoid getting in trouble, and it might even have been accidentally left in foreign models. We don't know the full story yet.

I think the distinction between being compelled by the sword and compelled by fear of the sword is pretty meaningless here. Unless these companies are independently deciding to push this out due to some internal zealous managers that reject the general CCP platform I think it's pretty safe to lay the blame at the feed of the party.

There's also all sorts of pretty reasonable whataboutism to be thrown about here but it's wrong either way.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#282

Earlier quoted context omitted.

Banking has to be the dumbest "security" industry there is. Restrict apps, but can still log in via browser. I have one bank app that actually says to screenshot a payment screen for your records, while blocking screenshots via app policy.

Bank websites in some (developed, European) countries restrict you to 6-8 digit passwords (not alphanumeric), and don't have a 2FA option like Facebook or Google do. It's a massive joke.

Granted that is on a phone where you can usually just swipe left to their email application and run through some forgot your password steps - also the 2FA that most people use is just SMS which goes to the same place.

Assume that if someone has your unlocked phone they own your life.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#283
post #215

The blacklist is interesting, because it maybe shows China's government interests - some of which are not widely known: - "Independence of Mongolia" - Does this show they would like to acquire Mongolia (when the time will be appropriate)? - "The Organisation for the Liberation of Palestine" - Does this show pro-Israel support?

[deleted]

Re: Lithuania says throw away Chinese phones due to censorship concerns

#284
post #187
post #129

Earlier quoted context omitted.

Even apps like Netflix are configured not to be available on Google play if the device is not a certified one. That certification is lost AFAIK on rooting. I have two perfectly good android tablets that can’t run Netflix

Is there anyone who knows how to root a device that doesn't know how to torrent?

I'm far too lazy to torrent crap at my age - it takes too long and it can be a pain to find what I want.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#285

Earlier quoted context omitted.

? Lithuania has been capitalist for 20+ years and quality of life has increased by a lot ever since. the three baltic states are frontrunners in gov digitalization, for example

> Lithuania has been capitalist for 20+ years and quality of life has increased by a lot ever since. That's what I said. Lithuania had it bad under communism (USSR). Maybe they are simply not interested in having an other communist regime (the CCP) meddle into it's internal affairs.

Ah yes, I agree completely with that

Re: Lithuania says throw away Chinese phones due to censorship concerns

#286
post #152

From the shared PDF page 23... "It has been established that during the initialisation of the system applications factory-installed on a Xiaomi Mi 10T device, these applications contact a server in Singapore at the address globalapi.ad.xiaomi.com (IP address 47.241.69.153) and download the JSON file MiAdBlacklistConfig, and save this file in the metadata catalogues of the applications. A list of applications for whic…

Similar lists existed within Google for their ("on hold" last I heard) project Dragonfly [0]. I saw a bunch of banned terms like these in the Dragonfly repo before they hid it from regular employees. It was a very long list. On it were also the names of specific activists and human rights lawyers, including some who'd been disappeared [1] or forcibly confined to mental institutions [2]. My impression is that Sundar w…

> Word of warning for those who trust Google as a defender of digital privacy and human rights.

Surely that is literally nobody?

At this stage I would be seriously concerned for anyone who identifies with this description.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#287

Earlier quoted context omitted.

I was stupid enough to buy a Xiaomi phone without enough due diligence. Aside from all spying that is going on, the software is abysmal. The problem with replacing the OS is that I believe most banking apps I use will stop working. Might just need to write this phone off.

Banking has to be the dumbest "security" industry there is. Restrict apps, but can still log in via browser. I have one bank app that actually says to screenshot a payment screen for your records, while blocking screenshots via app policy.

Not to mention the widespread SMS two factor.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#288

Earlier quoted context omitted.

I was stupid enough to buy a Xiaomi phone without enough due diligence. Aside from all spying that is going on, the software is abysmal. The problem with replacing the OS is that I believe most banking apps I use will stop working. Might just need to write this phone off.

Banking has to be the dumbest "security" industry there is. Restrict apps, but can still log in via browser. I have one bank app that actually says to screenshot a payment screen for your records, while blocking screenshots via app policy.

Totally agree, on my stock Pixel 4a using NextDNS breaks my banking apps (presumably because they're using analytics that get blocked, sigh).

Re: Lithuania says throw away Chinese phones due to censorship concerns

#289
post #152

From the shared PDF page 23... "It has been established that during the initialisation of the system applications factory-installed on a Xiaomi Mi 10T device, these applications contact a server in Singapore at the address globalapi.ad.xiaomi.com (IP address 47.241.69.153) and download the JSON file MiAdBlacklistConfig, and save this file in the metadata catalogues of the applications. A list of applications for whic…

Is it me or is this an extremely clumsy way of doing censorship? Why not do this at network or server-side level? Why not use some kind of hash (ala Apple'e proposed child pornography hunter)? In this design, everyone would have to have this plain text configuration file ... also other brands (Oppo, Huawei etc.) would have to have it. What if it needs an update? Suppose the hui muslims starts causing trouble ... Or i…

Maybe it's a "privacy preserving" censorship mechanism.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#290

Earlier quoted context omitted.

Banking has to be the dumbest "security" industry there is. Restrict apps, but can still log in via browser. I have one bank app that actually says to screenshot a payment screen for your records, while blocking screenshots via app policy.

> Restrict apps, but can still log in via browser. This isn't paradoxical. You treat the browser as a less trusted security domain than a phone, which usually has a secure boot chain, strong sandboxing, encrypted disk, reliable hardware cryptography etc, and therefore provide a different/better service on the phone. If a phone is missing one of these expected components then you're not the target market for the app,…

I disagree. My main bank allows several high-risk actions to be performed when logged in from a web browser, which are entirely impossible from the mobile banking app.

It's completely ridiculous that I can't use my mobile banking app for day to day low risk, low volume transactions if my phone is rooted, yet I can do anything and everything with high values of cash and credit from a Linux machine running any web browser I wish, as root.

The reality is, the mobile app development is outsourced to incompetent teams for presumably the lowest price who "ensure security" by just saying, "lets chuck a library in that prevents running if the device is detected as being rooted, and call it a day".

These are protections any reasonably technical user can circumvent with the likes of Magisk and still, all to do far, far less damage than is possible than if they were to use a web browser.

Post reply on HN