Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

351–360 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#351
post #7

I truly don't understand, from a security and privacy perspective, why would anyone outside of China would voluntarily choose to run closed-source software from a company that's subject to domestic laws and regulations in China. The MSS is no joke. https://www.google.com/search?client=firefox-b-d&q=china+mss... This is the same reason that Zoom is banned at my workplace and many other partner companies. You've actual…

I am using Xiaomi phone for roughly the same reasons as I am using Gmail. I dislike results of either, replacement of both is on my oversized TODO list - and was there since at least two years. I dislike that USA government, China government and God knows who else has full (partial?) copy of whatever I ever typed on my phone but I did nothing beyond selecting Android Zero, declining "send all what I typed to Google"…

I have massive respect for OSM maintainers. People don't appreciate how much work goes into the map data.

Anyway, you're right. In practice, protecting your privacy is a massive hassle. I just do it step by step, knowing that even half-assing it is better than nothing.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#352

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

> the Aqara/Xiaomi hub was talking to a bunch of Chinese servers constantly

It's not only Xiaomi issue: many Chinese top and noname smartphones stealing user data and show ads inside their UIs. Cheap hardware & users data mining - great business model.

The same with apps: https://www.vietnambreakingnews.com/2019/01/es-file-explorer...

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#353

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

> was talking to a bunch of Chinese servers constantly

Out of curiosity do you want Chinese companies to use US servers? Or where would servers be ideally placed for a Chinese brand to be accepted? I genuinely am curious to know.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#354

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

> was talking to a bunch of Chinese servers constantly Out of curiosity do you want Chinese companies to use US servers? Or where would servers be ideally placed for a Chinese brand to be accepted? I genuinely am curious to know.

Is this a serious question? How about don't contact any external server unless the user clicks an update button (or possibly on a schedule time the user has specifically allowed). After that, there is no legit reason for a device sensing the temperature in my home, a light switch, an electrical plug to ever call "home" about how it is being used. Maybe, just maybe, if the device detects that it is failing or other serious errors that might be okay, but if and ONLY if the user has specifically allowed that to happen. I don't care if the server is located in the US, China, Timbuktu, or Atlantis, and I don't care if the company is based in the US, China, or Martian. Just don't do it.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#355
post #7

I truly don't understand, from a security and privacy perspective, why would anyone outside of China would voluntarily choose to run closed-source software from a company that's subject to domestic laws and regulations in China. The MSS is no joke. https://www.google.com/search?client=firefox-b-d&q=china+mss... This is the same reason that Zoom is banned at my workplace and many other partner companies. You've actual…

Xiaomi phones are frighteningly popular here in Russia because they're very cheap. Like, a-phone-could-not-cost-this-little cheap. A 7000₽ (around $100) phone? Why not, seems legit! And not many people really understand what Xiaomi is actually doing to offset that cost. Heck, when you open the built-in calculator app in MIUI, it has a freakin privacy policy and refuses to operate if you don't accept that. Same for th…

How is that different from stock Android, besides this being per app and having to give blanket permission for all things Google right at installation of stock Android?

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#356
post #254

Earlier quoted context omitted.

> This should have been caught at a security review stage during design, it should have been caught at the code review stage, it should have been caught by automated tests, it should have been caught by QA, it should have been caught once live by data tests, it should have been seen once live by analysts, it should have been fixed at so many different points. Seems more likely this was done on purpose so if they got…

Hanlon's razor is a principle or rule of thumb that states "never attribute to malice that which is adequately explained by stupidity"

My corollary to Hanlon's Razor is "When you and/or your associates have been caught being malicious multiple times, Hanlon's Razor no longer applies to you."

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#357

Earlier quoted context omitted.

> was talking to a bunch of Chinese servers constantly Out of curiosity do you want Chinese companies to use US servers? Or where would servers be ideally placed for a Chinese brand to be accepted? I genuinely am curious to know.

Is this a serious question? How about don't contact any external server unless the user clicks an update button (or possibly on a schedule time the user has specifically allowed). After that, there is no legit reason for a device sensing the temperature in my home, a light switch, an electrical plug to ever call "home" about how it is being used. Maybe, just maybe, if the device detects that it is failing or other se…

I think you're both on the same page here, but (and I'm also guessing here) I think OP implies there's a certain bias when it comes to chinese servers. And I too have this feeling, that if it's a server in the "western world" not a lot of people would bat an eye. But if it's a chinese or russian server, now that's something "we don't want".

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#358

Earlier quoted context omitted.

Every radio regulation agency on the planet? Most radio hardware is capable of operating outside of regulated limits. The device firmware is usually what keeps the devices running within their regulated limits and gets those components licenses to be sold. Anyone selling regulated devices running outside of their regulated envelope faces fines and even criminal charges. Cell phones only work because the millions of d…

No, pretty of radio transmitting equipment are fully open soft modems. As far as I know, there is no licensing whatsoever for baseband makers? Where did you get that it is?

In the US a baseband processor's entire software stack that controls the radio front end must be certified. They'll also have the modems to talk to the cellular networks. BPs use their own CPU(s) and an RTOS firmware that's FCC certified.

This is why a baseband processor is a fully separate component from a device's application processor(s). Since the AP doesn't talk directly to the radio it doesn't need to be certified and can be updated without recertification. The BP can also get certification and any manufacturer using that BP doesn't need to re-certify it. The interfaces are also such that the AP can't (or shouldn't be able to) tell the BP firmware to boost the output power above legal limits or something.

Radios that have "open" soft modems don't typically have fully software controlled radio front ends. The radio front end will have its statutory limits baked in electrically or have very limited software control. The modulation on the back end isn't as important as the front end. Broken modulation just means you can't talk to anyone, an overdriven transmitter is effectively a radio jammer or can give someone an RF burn.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#359
post #337

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

I blocked all Chinese subnets because of the constant tries to log in to my servers. Obviously Xiaomi devices do not work in my network anymore.

How also can you make a guide of how to do it?

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#360
post #337

Earlier quoted context omitted.

I blocked all Chinese subnets because of the constant tries to log in to my servers. Obviously Xiaomi devices do not work in my network anymore.

How also can you make a guide of how to do it?

    iptables -I INPUT -m geoip --src-cc CH -j DROP
    iptables -I OUTPUT -m geoip --src-cc CH -j DROP
No guide needed.
Post reply on HN