Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

11–20 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#11
I recently bought a Xiaomi phone (Poco m3) for development. I was shocked to learn that in order to enable USB debug mode in developer settings, I needed to BOTH:

1) make a Xiaomi account with

and

2) insert a SIM card to the device (!)

Is that not insane? Other people seem to think so too: https://android.stackexchange.com/a/186052

Apparently the only alternative to this is rooting the device, which may break it.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#13

Really interesting. But whether what Xiaomi browser does it's a spyware, what's is Google? Does Google collects our navigation data? (Yes if we are using chrome or android and logged in) Does Google knows what videos and what kind of videos do we watch? (Do you need an answer?) Call it's a spyware because is a chinese company? Really? Nah. Google does the same or at least worst than it. I'm neither defending Xiami no…

Google doing something bad is not an excuse for others doing the same thing.

Also Google isn't under the control of an authoritarian government who is committing genocide as we speak.

I'm no Google fan and I dislike what big tech have become but I rather let Google have my data than the CCP.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#14
post #7

I truly don't understand, from a security and privacy perspective, why would anyone outside of China would voluntarily choose to run closed-source software from a company that's subject to domestic laws and regulations in China. The MSS is no joke. https://www.google.com/search?client=firefox-b-d&q=china+mss... This is the same reason that Zoom is banned at my workplace and many other partner companies. You've actual…

Could it be the same reason anyone outside of the US would voluntarily choose to run close-source software from a company that's subject to domestic laws and regulations in the US? The ECPA is no joke.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#15
post #5
post #3

I'm using a firewall to block tens of IP addresses and several apps. Why would Xiaomi tell me to download a 26MB update from their store if the one from Google Play, where I downloaded the app it's less than 15MB? I'll be getting rid of this phone by the end of the month.

Most Xiaomi phones are relatively easy to root/unlock and install a new rom on.

Yep, here's the link to the LineageOS device list with installation instructions. https://wiki.lineageos.org/devices/#xiaomi

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#16
This paragraph stood out to me:

> The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated is: this method wasn’t called for 90 days, meaning that the browser wasn’t started for 90 days. And that’s rather unlikely, so one has to consider this ID permanent.

If we assume that Xiaomi aren't literally trying to spy for a government and are in fact just poorly calibrated on what's legitimate to collect for product analytics purposes, this paragraph highlights why that's still incredibly dangerous despite "good intentions".

I remember the UK government investigation into Huawei concluding that not only was their security posture insufficient for critical infrastructure, but their engineering practices were likely a decade away from being at a point where they could start to claim good security practice.

This paragraph seems to suggest a similar problem at Xiaomi. This should have been caught at a security review stage during design, it should have been caught at the code review stage, it should have been caught by automated tests, it should have been caught by QA, it should have been caught once live by data tests, it should have been seen once live by analysts, it should have been fixed at so many different points. The fact it wasn't suggests that these stages either don't exist or are insufficient.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#17
post #11

I recently bought a Xiaomi phone (Poco m3) for development. I was shocked to learn that in order to enable USB debug mode in developer settings, I needed to BOTH : 1) make a Xiaomi account with and 2) insert a SIM card to the device (!) Is that not insane? Other people seem to think so too: https://android.stackexchange.com/a/186052 Apparently the only alternative to this is rooting the device, which may break it.

Yes, I returned it and got a Samsung instead for this exact reason.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#18
post #8

Really interesting. But whether what Xiaomi browser does it's a spyware, what's is Google? Does Google collects our navigation data? (Yes if we are using chrome or android and logged in) Does Google knows what videos and what kind of videos do we watch? (Do you need an answer?) Call it's a spyware because is a chinese company? Really? Nah. Google does the same or at least worst than it. I'm neither defending Xiami no…

What does Google have to do with Xiaomi spyware? Or Google being spyware somehow makes Xiaomi spyware less shitty?

I think it comes down to which companies and governments are on the other end. I'm far from trusting the US government, but I trust the Chinese government even less.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#19

Really interesting. But whether what Xiaomi browser does it's a spyware, what's is Google? Does Google collects our navigation data? (Yes if we are using chrome or android and logged in) Does Google knows what videos and what kind of videos do we watch? (Do you need an answer?) Call it's a spyware because is a chinese company? Really? Nah. Google does the same or at least worst than it. I'm neither defending Xiami no…

Yes, it does matter that it's outside of US laws. Just like the inverse matters too. ( an American company collecting Chinese user data should matter to Chinese users ).

This "whataboutism" is getting tiring. What Xiaomi does here is really bad. if google does/did the same thing it would ALSO be bad.

There is no "but they do it too!". It's bad, period.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#20
post #15
post #5

Earlier quoted context omitted.

Most Xiaomi phones are relatively easy to root/unlock and install a new rom on.

Yep, here's the link to the LineageOS device list with installation instructions. https://wiki.lineageos.org/devices/#xiaomi

But why would you have to root and reflash it? Couldn't they, you know, respect their customer instead?
Post reply on HN