Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

311–320 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#311
post #305

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

> The devices require a wi-fi connected hub, not too strange for things that use Zigbee Wait, why would Zigbee devices require Wi-Fi connection? That would be a red flag for me, I would have avoided products like this.

They don't. You can use Aqara-branded zigbee devices just fine with Home Assistant (open source), no propietary cloud services required. With most manufacturer's own hubs it's a whole different story, basically they all talk to their cloud, that's how they are designed. I can see why, that's the easiest option for average consumer, plug & play.

https://www.home-assistant.io/integrations/xiaomi_aqara/

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#312
post #305

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

> The devices require a wi-fi connected hub, not too strange for things that use Zigbee Wait, why would Zigbee devices require Wi-Fi connection? That would be a red flag for me, I would have avoided products like this.

[deleted]

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#313

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

I use a couple of Aqara sensors to report temperature back to my Home Assistant instance via a HUSBZB-1 USB Zigbee dongle[0]. They work pretty well, although they report data pretty infrequently absent any large temperature swings, so not great for data-viz purposes.

I'm not at all surprised the hub thing constantly chats with its family back in China, but a properly security-paranoid home automation aficionado wouldn't be caught dead giving some proprietary black box power and network inside their own home.

[0] https://shop.homeseer.com/products/nortek-usb-zigbee-zwave-i...

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#314
post #7

I truly don't understand, from a security and privacy perspective, why would anyone outside of China would voluntarily choose to run closed-source software from a company that's subject to domestic laws and regulations in China. The MSS is no joke. https://www.google.com/search?client=firefox-b-d&q=china+mss... This is the same reason that Zoom is banned at my workplace and many other partner companies. You've actual…

> I truly don't understand, from a security and privacy perspective, why would anyone would voluntarily choose to run closed-source software from a company that's subject to domestic laws and regulations in the United States.

Fixed that for you. Xiaomi offer an official bootlock unloader for their shitty MIUI roms which no one else on the planet does and is one of two companies out there that sells stock android phones. They are the easiest mobiles on the planet to install LineageOS on.

Imagine being on HackerNews and not at least slightly acknowledging the fact this company makes the most hacker friendly phones on Earth. It's honestly embarrassing.

Feel free to sniff the packets on any other device and realise how prevalent phonehomes are and how the eyes can access all of it on a whim if it's going to non-Chinese companies.

If you were an activist in the Western world I would only recommend a Chinese phone to protect yourself.

Cointelpro is still roaring hard today.

https://en.wikipedia.org/wiki/COINTELPRO

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#316

Did you really need to investigate this to realize it's spyware? This and chrome and most web browsers are spyware at this point.

Chromes "Software Reporter Tool" basically scans your whole computer and sends that data off to Google/NSA. It's literal spyware.

Firefox doesn't do this.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#317

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

I have a cheap air quality meter which basically connects to an MQTT broker server in China to transmit its readings constantly. The phone app connects to the same MQTT server, subscribes to a topic and receives the readings. I guess this is a very simple way to do it. Too bad the MQTT server has no authentication so you can actually subscribe to any topic. Many IoT solutions seem to be made by developers not very experienced in security.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#318

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

It’s absolutely infuriating how many IoT devices round trip to the cloud for no good reason at all.

Not quite for no good reason at all. For someone else who programmed them to do this, it is for a very self-servingly good reason of data vacuuming obsession, it just happens to be no good reason for the customer.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#319

Earlier quoted context omitted.

It goes the same for any of the "Eyes" countries. They share intelligence and tracking of citizens as well. It's not just the US, so don't act like it is.

Don't forget our laws here in Australia. (I know you mentioned eyes countries, which we are, but I wanted to highlight this). Our laws are so damn barbaric in relation to security that it's scary. It's gotten to the point where I nearly gave up on security. Who's compromised? I definitely missed out on a job because I was Australian. (Confirmed later over drinks with one of the devs who I am friends with).

Can you relate anymore about the industry and size of company you applied for?

I'm an aussie dev, and I hadn't even considered my eligibility to foreign companies may be compromised.

Post reply on HN