Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

181–190 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#181

Earlier quoted context omitted.

How much political influence do you think someone like Bezos really has? Everyone in washington hates him. No one wants to do favors for him. They drag him in front of congress do get a bunch of soundbites to play next election cycle. They win elections on shutting down his headquarter plans. They want to break up his company, raise his taxes on unrealized capital gains, they want to force him to divest his personal…

On the flip side, there were municipal governments literally giving Amazon powers over taxation and spending[1] to get them to set up their headquarters in their city. I think this is quite a bit of political power myself. [1] https://www.huffingtonpost.ca/entry/amazon-city-benefits-sec...

I wouldn't call someone with sway over municipal governments an oligarch though.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#182

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust. Whether caused by inept software devs, scope for malicious code / backdoors in firmware, analytics spyware, and whether this stuff is well intentioned or not, if it can be abused, it will be. Open source and verifiable down to the firmware is the only chance…

The problem is that purism doesn't pay as much as all the tracking, preinstalled bloatware, random 3rd party utilities and other stuff. This will never ever be solved through competition,because people either don't care, or there aren't enough of those who do. Legislation is the only way to make it work, but then again, that's hardly an option for most of the world.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#183
post #35
post #11

I recently bought a Xiaomi phone (Poco m3) for development. I was shocked to learn that in order to enable USB debug mode in developer settings, I needed to BOTH : 1) make a Xiaomi account with and 2) insert a SIM card to the device (!) Is that not insane? Other people seem to think so too: https://android.stackexchange.com/a/186052 Apparently the only alternative to this is rooting the device, which may break it.

I've been told that the reasoning behind this is shady resellers loading unremovable system malware to the system partition (which runs as device admin++) before reselling this to you. Apparently this is a huge problem in China, where there seems to be quite literally no trust at all on online shopping. This actually does seem to be the case if you try buying devices from any NON-xiaomi-official store Aliexpress shop…

Jesus, do you have any sources (Chinese is fine) for this? This is horribly anti-consumer and I'm surprised there's not more of a push back if it's so common.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#184
post #29

Chinese browser collects your data? Spyware. American company collects your data? $1,400,000,000,000 valuation. This reminds me of how we call Russian billionaires "oligarchs" but we just call American billionaires...billionaires.

> This reminds me of how we call Russian billionaires "oligarchs" but we just call American billionaires...billionaires.

Russian billionaires came to their wealth purely through corruption - i.e. using via their connections during the crucial years of transformation to market economy to buy huge state-owned industrial companies for 0.1-1% of their real value.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#185
post #35

Earlier quoted context omitted.

I've been told that the reasoning behind this is shady resellers loading unremovable system malware to the system partition (which runs as device admin++) before reselling this to you. Apparently this is a huge problem in China, where there seems to be quite literally no trust at all on online shopping. This actually does seem to be the case if you try buying devices from any NON-xiaomi-official store Aliexpress shop…

Jesus, do you have any sources (Chinese is fine) for this? This is horribly anti-consumer and I'm surprised there's not more of a push back if it's so common.

Try search for phrase "fakerom" or "fake rom" or "rottensys" with xiaomi.

The resellers get paid a few dollars for the malware install. I think the most common is people reselling to ship out to other countries, and not sold in China itself.

The aliexpress shops get shut down, negative feedback, but they just open another. Note that aliexpress actually shuts these down in the first place and is "reputable" end of things. Never ever buy devices from gearbest, wish, etc. - ever .

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#186
post #109

That's amongst the reason I do my AOSP GSI ( https://github.com/phhusson/treble_experimentations/releases... ; Generic System Image, an Android that works on pretty much all recent Android phones). Xiaomi devices are usually at sweet spots price/performance-wise (not really great hardware imo, but well). With custom ROMs (including my GSIs, but other custom ROMs are fine as well), buy a phone for their hardware, not…

My problem with GSI was last I checked (1 year ago) it still did not support storage encryption (Max 3), and SELinux was off.

Awesome project though.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#187

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

|This should have been caught at a security review stage during design, it should have been caught at the code review stage, it should have been caught by automated tests, it should have been caught by QA, it should have been caught once live by data tests, it should have been seen once live by analysts, it should have been fixed at so many different points.|

If the very first people (presumably the "higher ups"/more prestigious designers) in the design process miss such things, it is very hard to call them out in a societal construct that is the business construct that has become Xiaomi and the Chinese Government.

It's hard enough in some companies for QA to question software engineers and not catch backlash in the US when making games. Companies like EA, Atari and Nintendo are notorious for it. Apple used to shitcan QA who didn't treat "the talent" nice enough, and they weren't a quasi governmental entity.

You're right, of course. But man, that's a big frog in your throat to go up to your manager and say, "Sir, I'm sorry but this whole process has issues. Here's the fix, but it means a redesign of a core process." That's tough. That's double tough.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#188

Earlier quoted context omitted.

I believe the implication would be they are spying for China in this case, and therefore as legal as they want it to be.

Right, I meant is it allowed by Chinese law to NOT spy for the government. As I understand it, to be allowed to operate in China as a Chinese company, you are under the obligation to provide any information you collect to the gov't upon request. Is that not the case?

Splitting hairs here, but the wording of your question gives the impression that one could choose not to collect any data and then be free of said obligations, but I don't think that's the case. Does anyone know?

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#189
post #160
post #149

Earlier quoted context omitted.

> why would anyone outside of China would voluntarily choose to run closed-source software from a company that's subject to domestic laws and regulations in China Because outside US it doesn't really matter whether it's Chinese or American company that has your data.

It is critically important depending on your country's relationship with either country.

if your Country has good relationships with both of them it doesn't really matter.

EDIT: you have to understand that the cold war is over and you can't replace USSR with modern China, my country has good relationships with both the US and China so it doesn't really matters who's spying on you, they are "good friends" anyway...

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#190

Earlier quoted context omitted.

Xiaomi phones have unlockable bootloaders, so rooting is really trivial, but guess what? You need a Xiaomi account to unlock the bootloader too! And they make you wait several days to do it. And no, you can't break an Android device by rooting it. Worst case you'll have to reflash the system partition through recovery.

Went through this recently. Had to download xiaomi unlock software to unlock the bootloader. Probably sent an image of my hard drive back to china in the process. And the 7 day wait period. Really is an example of price too good to be true because they collect your data and probably get huge government subsidies to do so. Nice phone though once you flash it.

Yeah I did do that too several years ago too, but I ran it on a VM because I didn't have a real Windows machine anyway.
Post reply on HN