Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

201–210 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#201

Earlier quoted context omitted.

> significantly cheaper compared to a samsung or apple phone. Shouldn't that be a huge red flag? Any time someone offers something too good to be true, it never is. > Also it is likely the Chinese are spying on me indirectly Why? > I really have nothing significant on me that the Chinese would want to be concerned with me. It's not just about you, dammit. [0] By accepting their offer, you validate their actions. You…

Everyone of yours statements is equally applicable to Chrome, right?

Yeap. Don't use Chrome if you can avoid it. I'm using Brave for years already and I am very happy with it.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#202

Earlier quoted context omitted.

> significantly cheaper compared to a samsung or apple phone. Shouldn't that be a huge red flag? Any time someone offers something too good to be true, it never is. > Also it is likely the Chinese are spying on me indirectly Why? > I really have nothing significant on me that the Chinese would want to be concerned with me. It's not just about you, dammit. [0] By accepting their offer, you validate their actions. You…

> Shouldn't that be a huge red flag? Any time someone offers something too good to be true, it never is does that include the free tiers that many US companies are offering? For example: Google, Facebook, Twitter, YouTube

Yes. It also includes any free social media, any free messenger platform and any ad-based "freemium" service.

Surveillance Capitalism is bad and we should be fighting it.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#203

Earlier quoted context omitted.

Trying to get legal to sign-off on allowing no-privacy-policy access to anything is going to be hard every time, especially if you do keep personal information like IP addresses for any amount of time (hello gdpr).

But how can one prove whether a third party stores something? Especially if it's the IP address that it must receive anyway.

While I don't think there would be much investigation on a simple currency API storing user info, most companies aren't in the business of increasing legal risk for the tradeoff of user experience.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#204

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust. Whether caused by inept software devs, scope for malicious code / backdoors in firmware, analytics spyware, and whether this stuff is well intentioned or not, if it can be abused, it will be. Open source and verifiable down to the firmware is the only chance…

as much as I am eager to see open source mobile OS succeed, tracking happens at the app level.

What happens when I install the FB app on a Purism enabled device?

My way to go until now has been installing as many OSS apps on my smartphone as possible, to the point that even the keyboard and the launcher on my smartphone are installed through f-droid.

That's the main reason why I prefer Android phones over Apple ones.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#205

Earlier quoted context omitted.

Could it be the same reason anyone outside of the US would voluntarily choose to run close-source software from a company that's subject to domestic laws and regulations in the US? The ECPA is no joke.

It goes the same for any of the "Eyes" countries. They share intelligence and tracking of citizens as well. It's not just the US, so don't act like it is.

Don't pretend any other country have as much surveillance capability as the US does. There are levels to the awfulness and not everyone is at final boss level. Most are random green scrubs comparatively.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#206
What's worse is that the whole OS is actually spying on you, not just the Mi browser. Even when idle my phone is trying to send bits of data to their servers.

Xiaomi are great but for me this is the end of the line with their phones. Privacy comes at a premium nowadays and lots of us are willing to pay for it.

Those affected can block the following domains from resolving:

- data.mistat.intl.xiaomi.com

- sdkconfig.ad.intl.xiaomi.com

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#207
post #199

Earlier quoted context omitted.

I'm writing this from a Xiaomi smartphone. I know Xiaomi is not the best brand to buy for privacy, but I consider their products one of the best in terms of value for money I own a few Xiaomi devices, I simply install Blokada on each one of them and I think you would be surprised by how many non Chinese domains it blocks, Google being one of the worst offenders. EDIT: see this screenshot https://imgur.com/a/UO0BGCy E…

About your second edit: If you live anywhere on earth that isn't in the geographical area of China it would likely be better to have data going to China than the big US corps. For most it is unlikely the data could be used against you in anything from ads to a police raid, unlike with something like Google collecting it where it will almost for sure be used and useful.

I hear this a lot, but it strikes me as being short sighted. That only works if the status quo remains so forever. Maybe 5 or 10 years from now, relations between the Chinese and US governments gets cozier, and part of their deal includes sharing of this kind of data.

Or maybe the US government knows it can't legally collect certain information on its own citizens, but can rely on China to collect it, and then purchase it from the Chinese government.

Then there's the overall argument against: I don't want any government collecting data about me, period. It's none of their damn business, regardless of the chances of me having to interact with them in any capacity.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#208
post #165

Earlier quoted context omitted.

> American company will collect data to show you ads and profit. 7 years later and it's like Snowden never even existed. https://en.wikipedia.org/wiki/PRISM_(surveillance_program)

Fair enough, if we want argue along those lines - if you're in country X, would you like to be spied on by your country's gov AND China? I, for one, would prefer, if I have a choice, it to be just my Gov and not a foreign Gov that I consider to be hostile..

> I, for one, would prefer, if I have a choice, it to be just my Gov and not a foreign Gov that I consider to be hostile..

This seems intuitive at first sight but doesn't make sense to me: is it your Gov or a foreign Gov that can more likely bother your life?

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#209
post #99

Earlier quoted context omitted.

Same could be said for countries outside of the USA buying US tech equipment.

That's not true, because US companies are allowed to export E2E technology in products. Chinese companies are not given the same leeway. All Chinese messenger clients are not encrypted and are fully surveilled. That is not true for US messenger clients.

And yet from the free to export US we keep finding backdoors and hardcoded admin passwords in things that are supposed to be way more secure than a random chat client. Even if all of them are actually bugs I'm not sure that is any better. No E2EE to share my shopping list with my girlfriend versus the piss poor security in enterprise hardware from manufacturers like Cisco etc? At least I can download another chat client. Purging US enterprise equipment from my company, home and ISP? Not so much.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#210
post #160
post #149

Earlier quoted context omitted.

> why would anyone outside of China would voluntarily choose to run closed-source software from a company that's subject to domestic laws and regulations in China Because outside US it doesn't really matter whether it's Chinese or American company that has your data.

It is critically important depending on your country's relationship with either country.

Yes, if you are in a country friendly with the US it is better to have Xiaomi harvest the data than Apple.
Post reply on HN