Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

251–260 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#251
Quote: "However, you have to make sure that you have “Incognito Mode” turned on and “Enhanced Incognito Mode” turned off – that’s the only configuration where you can have your privacy."

Does the article's author really believe this or is put there because of outside pressure? I, for one, would not believe that for a single second.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#252
post #7

I truly don't understand, from a security and privacy perspective, why would anyone outside of China would voluntarily choose to run closed-source software from a company that's subject to domestic laws and regulations in China. The MSS is no joke. https://www.google.com/search?client=firefox-b-d&q=china+mss... This is the same reason that Zoom is banned at my workplace and many other partner companies. You've actual…

I’m running a Xiaomi air filter. Not connected to wifi.

Even without wifi access it is vastly superior to previous choices. At similar pricing to my previous one.

I’m quite wary of the whole monitoring scene but my next air filter purchase will be a Xiaomi again.

Can’t really speak to their other products but on that front they have made a convert out of me despite my aversion to questionable data practices.

Also apparently it’s home assistant compatible. So HA it and firewall it off is the plan

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#253

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

> This should have been caught at a security review stage during design, it should have been caught at the code review stage, it should have been caught by automated tests, it should have been caught by QA, it should have been caught once live by data tests, it should have been seen once live by analysts, it should have been fixed at so many different points.

Seems more likely this was done on purpose so if they got caught they could say "Junior engineer made a mistake. So sorry."

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#254

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

> This should have been caught at a security review stage during design, it should have been caught at the code review stage, it should have been caught by automated tests, it should have been caught by QA, it should have been caught once live by data tests, it should have been seen once live by analysts, it should have been fixed at so many different points. Seems more likely this was done on purpose so if they got…

Hanlon's razor is a principle or rule of thumb that states "never attribute to malice that which is adequately explained by stupidity"

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#255

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust. Whether caused by inept software devs, scope for malicious code / backdoors in firmware, analytics spyware, and whether this stuff is well intentioned or not, if it can be abused, it will be. Open source and verifiable down to the firmware is the only chance…

Purism is never going to end up with fully open source baseband firmware. It's not going to happen because the radios are subject to several regulations which means customers can't be able to modify that firmware. There's going to always be a trust hole.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#256

A very good rule of thumb: Freedom-respecting (fully, 100% open-source) software won't screw you. Simply knowing someone could be watching you and your source code reduces the chance of malicious code.

The Linux kernel is 100% open-source. Yet it's growing user-hostile features --- https://news.ycombinator.com/item?id=26285683 --- and guess what all the locked-down Android phones run...?

Open-source doesn't mean anything for freedom if all you can do is look, because you don't have the signing keys and such to modify what you want. It just means they get to show you exactly how they put the noose on you, that's all.

Firefox is also chock-full of "telemetry" and it's 100% open-source. That one you do get to modify, but it's still a bloody bastard to strip it all out and recompile to your liking.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#257

Earlier quoted context omitted.

But in context: - Australia has similar laws. - Snowden releases showed the US don’t even ask, they just take it. So it’s not like there is a huge amount of difference around the world.

> But in context: > > - Australia has similar laws. > > - Snowden releases showed the US don’t even ask, they just take it. > > So it’s not like there is a huge amount of difference around the world. I am not familiar with Australia privacy law, could you give me a rough idea what is look like? Snowdon case made the US government look bad, please don't use the same reason to make the Chinese Communist Party look good…

No, I was pointing out the "Don't by Xiaomi because you can't trust them" is logically flawed... because you can't trust any of the countries involved with the manufacture of phones.

This isn't excusing the behaviour, it's pointing out that "privacy" is not a justification for not using Chinese goods, because American goods have evidence of exactly the same compromise.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#258

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust. Whether caused by inept software devs, scope for malicious code / backdoors in firmware, analytics spyware, and whether this stuff is well intentioned or not, if it can be abused, it will be. Open source and verifiable down to the firmware is the only chance…

> Open source and verifiable down to the firmware

While I agree with your intent, the problem is that, many open source software is not verifiable.

Remember that a Kaggle competitor was openly cheating with his published code? (cf. https://www.theregister.com/2020/01/21/ai_kaggle_contest_che... ) Eventually he got caught, but it's sometimes extremely difficult to spot a well-hidden malicious code in a plain sight. We need to be much better at analyzing software.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#259
post #224
post #220

Earlier quoted context omitted.

If you're going to cite Snowden, please be accurate. Remember that one of the leaks was that the NSA tapped unencrypted Google backhaul in transit without Google's knowledge . There's a difference between panopticon fearmongering and citing specific information we should be wary of. The former leads to apathy. The latter leads to action.

How about this one? https://en.wikipedia.org/wiki/Room_641A

Whoa. I'm surprised I'd never heard of this before. Thank you.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#260
post #224
post #220

Earlier quoted context omitted.

If you're going to cite Snowden, please be accurate. Remember that one of the leaks was that the NSA tapped unencrypted Google backhaul in transit without Google's knowledge . There's a difference between panopticon fearmongering and citing specific information we should be wary of. The former leads to apathy. The latter leads to action.

How about this one? https://en.wikipedia.org/wiki/Room_641A

That was ATT. It (and all the other exposed operations) hardly support the statement that "all telecom companies and very likely all major tech companies are spying for the US government".
Post reply on HN