Live data from Hacker News

Xiaomi Recording ‘Private’ Web and Phone Use

forbes.com

241–250 of 254 posts

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#241
post #40

Earlier quoted context omitted.

This is why I root my device and only allow apps I trust internet access.

Doesn't that permanently disable some features on Samsung? I read they use a goddamn eFuse for it

Yup, IIRC that disables Knox features and secure folder permanently (trips an e-fuse so there's no turning back). I don't remember if Samsung also intentionally degraded camera quality like some other vendors (Sony at least used to once you unlocked your bootloader).

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#242

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

Yeah, it would be indistinguishable from what Google does. Oh, wait...

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#243
post #199

Google accusing apple of "Selling privacy as a luxury good", well, isn't it? Clearly, if you don't want to be spied on you're going to have to pay a premium.

The profit from your data offsets the cost of the hardware. If they're not selling your data, then you get to pay full price for the phone. Not a crazy idea, really, but I wish that was made clearer.

Yet Apple ecosystem is an insane walled garden and you don't really own your hardware, because you can't even run applications not downloaded from the app store.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#244
post #173

Earlier quoted context omitted.

> For those more expert than I, is Apple any better in this regard? Yes, and unequivocally so. Apple is not know to track browsing behavior, search terms, etc. Most of the data that your phone collects about you either remains in your phone (that’s why they’ve been shipping with NPUs for several years - they do A lot of machine learning in device rather than in-cloud) or is analyzed using differential privacy mechani…

You ignored iCloud though, which isn't E2E reencode and uploads personal photos, contacts, location and some other data to Apple. They can decrypt this data and regularly share it with the governments. So your post is kinda misleading when you leave these details out - it creates a false sense of safety. (And before someone complains: Yes, Apple is infinitely better at privacy than Xiaomi. We still shouldn't hide pri…

However, there is an elephant in the room - any Xiaomi device can unlock its bootloader, and the flash an open firmware, like LOS. This instantly makes it much better than Apple phones or any phones on the market - you can even ignore google software. With Apple you cant even run apps that haven't gotten through Apple censors, and the closest you can get to owning your hardware is "jailbreaking" it.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#245
post #176

Earlier quoted context omitted.

Actually, I installed LineageOS but skip installing root binary (it's an optional step when flashing LineageOS) as I don't need root anymore. Without root I can still use my banking app because Google safetynet is passing on my phone.

I use LinageOS myself but I would never use a smartphone for anything related to personal finance. Without an extensive research project there is no telling what's going on under the hood imho.

Most banking apps have extensive telemetry enabled themselves. Even keyboards are trying to phone home constantly

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#246

Earlier quoted context omitted.

OTOH Xiaomi also sent out dev devices to custom rom developers. Well technically it's Poco the Xiaomi subsidiary[1] Is there any word on whether that is true for european region phones as well? From what I remember they disabled certain functionality like Face Unlock in the EU. Not sure if it was due to privacy or patents, but given the GDPR I wouldn't be surprised if it was due to privacy. [1]: https://www.xda-devel…

Oh! That explains why my F1 has such good ROM support, it was a major reason for buying it (another one is cheap replacement parts). They still disrespect ROM users: You have to go through a convoluted process involving Windows software and a Xiaomi account AND wait 3 days to unlock the phone - but that's way down from the 6 weeks I've read about on other Xiaomis, so you can be sure I'm not going to buy one of those.

the delay appears to be random. my first one was 3 days, my second was more than a week until just a day before the person that i wanted to give the phone to was leaving.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#247

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

I know I am being naive, but what I can do? A normal used that is wants privacy?

I expected some Volkswagen like defeat device to in phones to evade security audit.

But what can "I" do, considering that the bodies & Govt that are suppose to do something are busy stuffing their own pockets and busy with petty politics.

Open-source hardware progress is very slow and low RAM. How safe will I be if I just run LineageOS on a Xiaomi device?

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#248

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

I know I am being naive, but what I can do? A normal used that is wants privacy? I expected some Volkswagen like defeat device to in phones to evade security audit. But what can "I" do, considering that the bodies & Govt that are suppose to do something are busy stuffing their own pockets and busy with petty politics. Open-source hardware progress is very slow and low RAM. How safe will I be if I just run LineageOS o…

As a normal user who wants privacy, you'll be just fine with LineageOS on Xiaomi. Assuming you don't install spyware later. You don't even have to install Google apps (see f-droid and Aurora store).

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#249

Stuff like this is why without fail, every phone I own gets LineageOS installed immediately. Xiaomi phones have a bootloader unlock timer to try and mitigate sites reselling their phones with modified software, so I had to leave my Mix 2s alone for a few days before I could make it safe to use.

This is why, without fail, I buy iPhones.

It is a pity iPhones are tied to Apple and iOS (mostly - see the recent news about Android on an iPhone 8) without the possibility of escape which many Android devices offer. For iPhone to be an alternative to Android in this respect it would need a few extra features:

- the possibility to install your own distribution, whether that be alternative versions of iOS or a totally different OS

- expandable storage, preferably with a boot option

- an official method to side-load software outside of the 'walled garden'

- either more extensive access to the innards of iOS or root, this to allow e.g. a true firewall (with ingress and egress blocking), a system-wide network blocker ('adblock' et al), etc.

- the possibility to run interpreters and compilers

- a real browser choice, not just a shell around Safari

In short, the possibility to have a less restrictive system.

Since I don't see Apple opening up in this way unless they're forced to by law or by declining sales I don't see myself buying any of their products in the near future.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#250
post #96

Earlier quoted context omitted.

Well the EU and Canada seem to be terrified of putting a foot wrong with the CPC, so my guess is that Chinese companies will violate people's privacy until it becomes so blatant that they get a polite request to tone it down (and obfuscate the collection).

Americans are not? Look at how they bent the knee with Huawei and ZTE. Also can’t figure out how to produce hardware in their home soil, as much as they’d like to.

oh we can most definitely manufacture a phone, but since we don’t have slave labor and questionable human rights it costs us more to do so.
Post reply on HN