Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

231–240 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#231

What's worse is that the whole OS is actually spying on you, not just the Mi browser. Even when idle my phone is trying to send bits of data to their servers. Xiaomi are great but for me this is the end of the line with their phones. Privacy comes at a premium nowadays and lots of us are willing to pay for it. Those affected can block the following domains from resolving: - data.mistat.intl.xiaomi.com - sdkconfig.ad.…

Using pihole is effective but don't try blocking a Chromecast like this. I did and even using two piholes the network got killed by these hundreds of DNS requests per second to Google.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#232

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

That can be explained as a bug, but tracking what you typed into youtube search boxes doesn't seem like a bug and has no justification in terms of performance optimization.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#233
post #117

> If you use Mint Browser (and presumably Mi Browser Pro similarly), Xiaomi doesn’t merely know which websites you visit but also what you search for, which videos you watch, what you download and what sites you added to the Quick Dial page Yet people in Europe they LOVE Xiaomi. I swear I’ve seen so many of my friends with those high end 500$ phones. Even if they are tech guys it’s like they just don’t care , they wa…

I live in Europe. If I weren't a privacy nut I'd pick Xiaomi any day over Apple or Google. Now I use Android with OPNsense in front of it via VPN. Chinese phones doesn't log more than the other smartphones.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#234

Earlier quoted context omitted.

Everyone of yours statements is equally applicable to Chrome, right?

Yeap. Don't use Chrome if you can avoid it. I'm using Brave for years already and I am very happy with it.

Except Brave itself also collects telemetry and has been caught whitelisting cross site apis from sites like Facebook.

https://nakedsecurity.sophos.com/2019/02/12/privacy-browser-...

Honestly, when Brave makes the kind of claims that they do, an oversight like this is inexcusable. Privacy should mean privacy, even if that means losing functionality on a select few sites.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#236

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

>I remember the UK government investigation into Huawei concluding that not only was their security posture insufficient for critical infrastructure, but their engineering practices were likely a decade away from being at a point where they could start to claim good security practice. This paragraph seems to suggest a similar problem at Xiaomi.

ASFAIK, Xiaomi does not sell any critical infrastructure equipment, nor is it installed anywhere; not entirely sure why GCHQ or NCSC would be involved, especially when there is ambiguity around which/what equipment they should be conducting a code review upon?

With regard to Huawei, there was no decisive conclusion, despite a comprehensive security review. Furthermore, it has been business as usual for currently installed equipment. All future decisions will be based around the 5G infrastructure.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#237
post #226

Xiaomi phones are insane, at least BlackShark. They replace virtually all the major user level stuff of Android with extreme data collecting alternatives. They then make it so that you cannot disable many of them (via adp, custom ROMs etc.) without bricking the phone, I'm talking wallpaper or clock apps that run with full, non-modifiable privileges. They subsidize cheap hardware with truly insane level of tracking. T…

So how is it different from a regular Android again?

stock android apps have sensible default permissions and are modifiable, e.g. clock does not have unmodifiable access to every aspect of your phone. clearer?

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#238
post #226

Xiaomi phones are insane, at least BlackShark. They replace virtually all the major user level stuff of Android with extreme data collecting alternatives. They then make it so that you cannot disable many of them (via adp, custom ROMs etc.) without bricking the phone, I'm talking wallpaper or clock apps that run with full, non-modifiable privileges. They subsidize cheap hardware with truly insane level of tracking. T…

So how is it different from a regular Android again?

If you cannot replace the software on the Black Shark with alternatives without possibly bricking the phone, I would say that's a substantial deviation from the norm where most other devices have unlockable bootloaders and Rom support using LineageOS.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#239
post #8

Really interesting. But whether what Xiaomi browser does it's a spyware, what's is Google? Does Google collects our navigation data? (Yes if we are using chrome or android and logged in) Does Google knows what videos and what kind of videos do we watch? (Do you need an answer?) Call it's a spyware because is a chinese company? Really? Nah. Google does the same or at least worst than it. I'm neither defending Xiami no…

What does Google have to do with Xiaomi spyware? Or Google being spyware somehow makes Xiaomi spyware less shitty?

>What does Google have to do with Xiaomi spyware?

False equivalence. If people in here actually broke down the differences, they would have to admit that their "Grr, Google just as bad!" hyperbole is more than just a tad disingenuous.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#240
post #209
post #99

Earlier quoted context omitted.

That's not true, because US companies are allowed to export E2E technology in products. Chinese companies are not given the same leeway. All Chinese messenger clients are not encrypted and are fully surveilled. That is not true for US messenger clients.

And yet from the free to export US we keep finding backdoors and hardcoded admin passwords in things that are supposed to be way more secure than a random chat client. Even if all of them are actually bugs I'm not sure that is any better. No E2EE to share my shopping list with my girlfriend versus the piss poor security in enterprise hardware from manufacturers like Cisco etc? At least I can download another chat cli…

Huawei's security doesn't come close to Cisco's security practices. Mostly because the vast majority of their hardware and software was sourced from stolen IP (Huawei had cash bounties for employees to provide stolen IP to the company). If you sell stolen technology, you don't truly understand how it works or how to secure it.

Given the choice, I'd choose Cisco every day of the week. It's not perfect but then again there's no such thing as perfect security.

With an E2E messenger, you can be sure that most likely your communications are not being intercepted. With a Chinese company, your communications are never secure.

Not only are Chinese software products not secure, but they'll lie to you about their security. Zoom claimed to have E2E encryption on calls which turned out to be an egregious fabrication (on top of them exporting calls to Chinese servers).

Post reply on HN