Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

261–270 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#261
post #205

Earlier quoted context omitted.

It goes the same for any of the "Eyes" countries. They share intelligence and tracking of citizens as well. It's not just the US, so don't act like it is.

Don't pretend any other country have as much surveillance capability as the US does. There are levels to the awfulness and not everyone is at final boss level. Most are random green scrubs comparatively.

> Don't pretend any other country have as much surveillance capability as the US does.

The level of surveillance in Xinjiang vastly exceed that of anywhere else in the world except for military installations.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#262
post #252
post #7

I truly don't understand, from a security and privacy perspective, why would anyone outside of China would voluntarily choose to run closed-source software from a company that's subject to domestic laws and regulations in China. The MSS is no joke. https://www.google.com/search?client=firefox-b-d&q=china+mss... This is the same reason that Zoom is banned at my workplace and many other partner companies. You've actual…

I’m running a Xiaomi air filter. Not connected to wifi. Even without wifi access it is vastly superior to previous choices. At similar pricing to my previous one. I’m quite wary of the whole monitoring scene but my next air filter purchase will be a Xiaomi again. Can’t really speak to their other products but on that front they have made a convert out of me despite my aversion to questionable data practices. Also app…

Why does an air filter need wifi?

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#263
post #220

Earlier quoted context omitted.

You guys are familiar with the Snowden disclosures and how all telecom companies and very likely all major tech companies are spying for the US government right? At this point, this is table stakes for big tech and it's completely anti-democratic. China may have a very good domestic dragnet but clearly it's playing catch up compared to the foreign intelligence assets the USG (and five eyes) has.

If you're going to cite Snowden, please be accurate. Remember that one of the leaks was that the NSA tapped unencrypted Google backhaul in transit without Google's knowledge . There's a difference between panopticon fearmongering and citing specific information we should be wary of. The former leads to apathy. The latter leads to action.

Right, that's why I said "very likely" instead of "proven". However, at the point it's pretty clear the tech companies are all competing for pentagon contracts (e.g. Project Maven, JEDI, etc) so the 2013 information has significant potential to be dated.

Also, there's these nuggets:

https://www.fastcompany.com/40481463/facebook-wants-to-hire-...

https://www.rt.com/usa/399256-mattis-amazon-bezos-trump/

Thinking America's largest monopolies and America's government and foreign policy are at odds over more than superficial things is probably not an accurate view of the world. America uses our corporations to advance nebulously defined "national security interests" and corporations use the government to get rich(er).

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#265

Earlier quoted context omitted.

> But in context: > > - Australia has similar laws. > > - Snowden releases showed the US don’t even ask, they just take it. > > So it’s not like there is a huge amount of difference around the world. I am not familiar with Australia privacy law, could you give me a rough idea what is look like? Snowdon case made the US government look bad, please don't use the same reason to make the Chinese Communist Party look good…

No, I was pointing out the "Don't by Xiaomi because you can't trust them" is logically flawed... because you can't trust any of the countries involved with the manufacture of phones. This isn't excusing the behaviour, it's pointing out that "privacy" is not a justification for not using Chinese goods, because American goods have evidence of exactly the same compromise.

All mobile phone manufacturers are spying on you does not automatically follow from the fact that Xiaomi browsers are spyware.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#266
post #260
post #224

Earlier quoted context omitted.

How about this one? https://en.wikipedia.org/wiki/Room_641A

That was ATT. It (and all the other exposed operations) hardly support the statement that "all telecom companies and very likely all major tech companies are spying for the US government" .

The US defense and intelligence apparatuses have been deeply intertwined with private enterprise for many decades. This is a matter of historical fact. But I totally understand if it's more comfortable for you to believe that now things are different despite the fact that no one was ever held to account for what happened in the past.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#267
post #26
post #17

Earlier quoted context omitted.

Yes, I returned it and got a Samsung instead for this exact reason.

Any model to recommend? Not sure if our usecases are the same -- I wanted to find a cheap "lower end of the market" phone to test my mobile game on. Frankly, the poco m3 might even be too powerful for that purpose...

I recently ordered the 2020 version of the Moto G Power (XT2041-4) from Costco for personal use, upgrading from the Moto G6 Play.

And although Lenovo is now China-owned, the Moto line is still pure Android and no bloat.

Did a lot of research and the the last gen G Power is the best spec'd budget phone around this price point that is not a Samsung and sold in typical NA big box stores.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#268
For anyone trying to be privacy conscious, by deleting their FB accounts, not using all the Google services etc. It should be obvious that a good rule of thumb would also be to not use software built in China.

Even if they were not built with malicious purpose, they have both excellent state-funded hackers and poor security practices in most of their consumer products.

Unfortunately, from what I've seen, I think the same can be said about software from Korea/Japan...

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#269

Earlier quoted context omitted.

Could it be the same reason anyone outside of the US would voluntarily choose to run close-source software from a company that's subject to domestic laws and regulations in the US? The ECPA is no joke.

It goes the same for any of the "Eyes" countries. They share intelligence and tracking of citizens as well. It's not just the US, so don't act like it is.

Don't forget our laws here in Australia. (I know you mentioned eyes countries, which we are, but I wanted to highlight this).

Our laws are so damn barbaric in relation to security that it's scary.

It's gotten to the point where I nearly gave up on security. Who's compromised?

I definitely missed out on a job because I was Australian. (Confirmed later over drinks with one of the devs who I am friends with).

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#270

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust. Whether caused by inept software devs, scope for malicious code / backdoors in firmware, analytics spyware, and whether this stuff is well intentioned or not, if it can be abused, it will be. Open source and verifiable down to the firmware is the only chance…

> we need tools that don't require so much blind trust

Completely agree.

> Open source and verifiable down to the firmware is the only chance we have at any real level of trust

The hardware itself could be compromised though. There's just no way to know what's really inside these black boxes.

https://youtu.be/_eSAF_qT_FY

We'll never have real trust until we get the ability to fabricate our own processors in our own home just like we already have the ability to write our own software.

Post reply on HN