Live data from Hacker News

Xiaomi Recording ‘Private’ Web and Phone Use

forbes.com

221–230 of 254 posts

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#221
post #145

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

Excuse my naïveté, but who would actually work on such things? How can someone have such low moral standards to, day after day, build systems that secretly remove privacy from otherwise innocent people?

Money lowers moral standards.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#222

Earlier quoted context omitted.

> I wonder how many devices already do this. All Android phones. But they send the data to google and facebook so they must be good.

Source needed. The amount in the article is staggering compared to what Google claims to collect which is in line with the (admittedly not definitive) DNS query logs I monitor every now and then. Also, much of it (e.g. location) can be disabled and there are Android phones that are entirely free of Google and Facebook.

I do know for a fact that Android contacts querries Google severs to pull data from Google services, like YouTube, to fill in extra contact details on the phone.

Knowing what Google's business is, I doubt they don't merge that data for a more complete profile.

You can try this yourself: Create a YouTube account, upload a picture for the account, don't add details like a phone number.

Now create a contact on Android, add a phone number (as most people do with contacts on their phone) and add the email address you registered the YouTube account, the Android contacts app will pull the profile picture from the YouTube account, and put it on the phone as the picture for the contact.

Gave me quite a little scare when I discovered this by seeing my YouTube profile picture as the contact picture on a (rather privacy and tech-illiterate) friend's Android phone, even tho I never added any phone number to any of my Google accounts, all he did was add my email address to the contact.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#223

Earlier quoted context omitted.

Unfortunately I tend to think RM Stallman is right - smartphones are a prison with tracking enabled. We're all foolish to yield that much power to vendors. Most software on the smartphones aren't under our control, we aren't able to stop them, disable them, inspect them, or see the source code. I think we should undo everything done in the smartphone since 2008 and come up with a true open source smartphone.

Purism is working on it. I think they're selling them now. No idea if it is good just that it's happening.

Purism phones aren’t as polished as other phones, but it’s amazing that they exist. We need to support them until they get to version 2-3 and have everything slick and polished

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#224

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

I wonder how many devices already do this.

I ran a firewall on my Android once. It blocked a request to google play services every 2 minutes, 24/7. I use an iPhone now and really want a librem

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#225

Xiaomi produces one of the best bang for your bucks hardware in the market. Their software is crap though. Ads in the system apps, ui customization that arguably looks worse than stock android, and now blanket tracking like this, though it was always pinging their tracking servers frequently. My pihole logs pretty much full with blocked xiaomi requests until I flashed the phone. Best thing to do when you got an andro…

Is that a recent thing? My Xiaomi Mi A1 ran Android One that gets official updates to this day, as far as I could tell it was pretty stock and the data collection in their "Mi Services" could be disabled in the settings UI, so not unlike pretty much any cheap manufacturer.

Mi A1 is probably an exception as it's part of Android One program. The rest of xiaomi lineups are using their miui rom which contains ads and tracking mentioned in the article.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#226

Earlier quoted context omitted.

> I wonder how many devices already do this. All Android phones. But they send the data to google and facebook so they must be good.

Source needed. The amount in the article is staggering compared to what Google claims to collect which is in line with the (admittedly not definitive) DNS query logs I monitor every now and then. Also, much of it (e.g. location) can be disabled and there are Android phones that are entirely free of Google and Facebook.

As I said elsewhere on this page, Google Play gets an update from your phone every 2 minutes 24/7 with a lot of privacy settings enabled. Turn on a firewall, I think it was disconnect that showed me this

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#227
post #145

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

Excuse my naïveté, but who would actually work on such things? How can someone have such low moral standards to, day after day, build systems that secretly remove privacy from otherwise innocent people?

lawyers?

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#228
post #145

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

Excuse my naïveté, but who would actually work on such things? How can someone have such low moral standards to, day after day, build systems that secretly remove privacy from otherwise innocent people?

“Money makes a man act funny” -Eminem.

I have had friends suddenly get very selfish when the chance to get even $10 is available. I had a regular at a retail job once who came in every day... he asked to borrow $1 once to help pay for something. To avoid paying it back, he never returned, likely walking an extra several km to the next nearest store of the type every day. For $1

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#229

Earlier quoted context omitted.

Checkm8 is a tethered exploit, so probably not super useful if you want to sideload another OS and not have a bad time.

I remember back in the days of the iPhone 3G(s?) there was an attempt at a battery-powered dongle that could re-jailbreak a phone in the field in case of a reboot. The same technology could be built into a battery case or similar, not to mention recent technological advances mean it can be done in a small package the size of a Lightning connector or a Yubikey and you can carry it on your keyring.

If the jailbreak script can run on arm linux, you probably can get close enough by using a raspberry pi and a power bank. Configure the pi to automatically run the jailbreak as script on boot or when the phone connected via USB and you'll get a portable plug and play jailbreaking device.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#230

Xiaomi produces one of the best bang for your bucks hardware in the market. Their software is crap though. Ads in the system apps, ui customization that arguably looks worse than stock android, and now blanket tracking like this, though it was always pinging their tracking servers frequently. My pihole logs pretty much full with blocked xiaomi requests until I flashed the phone. Best thing to do when you got an andro…

WRT “bang for the buck”: you have to take the whole picture into account, not just cpu speed/battery life plus price. Taken as a whole, it has a negative bang for the buck

Also curious: can you trust the hardware even if you do flash lineageOS? Honestly curious

Post reply on HN