Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

371–380 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#371
Xiaomi devices are officially sold in EU. Wouldn't a GDPR violation basically kill the company??

Note that Xiaomi is a Chinese startup hub, started by former googlers. 90% of what they sell is produced by Chinese startups.

(That being said, I would use never Xiaomi software myself. I only use their hardware with open source 3rd party apps)

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#372
post #51
post #29

Chinese browser collects your data? Spyware. American company collects your data? $1,400,000,000,000 valuation. This reminds me of how we call Russian billionaires "oligarchs" but we just call American billionaires...billionaires.

Chinese browser collects data for CCP which will use it for spying and for action against you, your family and your country. American company will collect data to show you ads and profit. Are they really same?

Remember anything about Snowden's leaks? American companies happily share all the data they collect with local police departments and intelligence agencies, in bulk, with absolute impunity.

If anything, you face a much greater threat from the American intelligence apparatus than one in a foreign country.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#373
post #370
post #317

Earlier quoted context omitted.

I have a cheap air quality meter which basically connects to an MQTT broker server in China to transmit its readings constantly. The phone app connects to the same MQTT server, subscribes to a topic and receives the readings. I guess this is a very simple way to do it. Too bad the MQTT server has no authentication so you can actually subscribe to any topic. Many IoT solutions seem to be made by developers not very ex…

Are you saying you can actually read the air quality readings of other users? That's... quite an oversight. :-/

Free big data for everyone.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#374
post #337

Earlier quoted context omitted.

I blocked all Chinese subnets because of the constant tries to log in to my servers. Obviously Xiaomi devices do not work in my network anymore.

How also can you make a guide of how to do it?

V2ray has the option to route based on geoip, but it creates a socks/http proxy, not a whole system solution.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#375

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

> temp/humidity sensors

If you're into writing your own code, https://ruuvi.com/ has bluetooth low energy sensors that transmit temperature/humidity/air pressure/3d-acceleration data with an open protocol, also their firmware is open source. They have a mobile app that displays readings from sensors, but for anything else you'd need to set up your own data logging or home automation server.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#376

Spyware is based off intent. Collecting data doesn't necessarily make you spyware. You can literally call anything spyware depending on how schizo you want to be at this point.

This is bad argument nowadays.

Even if they just collect the data now, they might sell it 5 years down the line.

You have to consider the worst possible interpretation, even if its not true today. Companies can be sold or taken over, go bust and their assets get sold.

Companies can change too. Look at google. In 2000's I trusted google a lot more than I trust it now. You can bet google still has all my data from 2000's.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#377

Earlier quoted context omitted.

Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust. Whether caused by inept software devs, scope for malicious code / backdoors in firmware, analytics spyware, and whether this stuff is well intentioned or not, if it can be abused, it will be. Open source and verifiable down to the firmware is the only chance…

> we need tools that don't require so much blind trust Completely agree. > Open source and verifiable down to the firmware is the only chance we have at any real level of trust The hardware itself could be compromised though. There's just no way to know what's really inside these black boxes. https://youtu.be/_eSAF_qT_FY We'll never have real trust until we get the ability to fabricate our own processors in our own h…

Well, I would love to print out my own cpu in the garage, but until then, I would also be happy, if the factories producing security critical HW, get frequent audits by qualified personel. Certifying and reviewing the build process.

Not very likely on a broader scale, though.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#378
post #99

Earlier quoted context omitted.

That's not true, because US companies are allowed to export E2E technology in products. Chinese companies are not given the same leeway. All Chinese messenger clients are not encrypted and are fully surveilled. That is not true for US messenger clients.

IIRC American companies (specially service companies, but surely also hardware companies) can be forced to introduce backdoors and other spying mechanisms and then force them not to disclose such a thing (i.e. Lavabit, Groklaw, Room 641 and equivalent Google and Facebook programms). For us that don't live in the US or China, it is just a matter of choosing between two evils. And in being pragmatics, the 90% of the po…

> IIRC American companies (specially service companies, but surely also hardware companies) can be forced to introduce backdoors and other spying mechanisms and then force them not to disclose such a thing (i.e. Lavabit, Groklaw, Room 641 and equivalent Google and Facebook programms).

You recall incorrectly. By extension of the First Amendment, US companies are protected from being forced to introduce functionality so as to collect or decrypt information (or for any other purpose). Carrying out original work for the government is considered to be speech, and as a result cannot be compelled. If the data is already collected and available in a decrypted form to the company a court order can compel the data to be turned over as evidence, as is the case with any data (or any thing) held by anyone (with narrow exceptions related to the 5th amendment).

This was a topic of national attention several years ago when the FBI tried (and failed) to compel Apple to create and sign a custom software update to unlock an iPhone.

https://en.m.wikipedia.org/wiki/FBI–Apple_encryption_dispute

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#379
post #35

Earlier quoted context omitted.

I've been told that the reasoning behind this is shady resellers loading unremovable system malware to the system partition (which runs as device admin++) before reselling this to you. Apparently this is a huge problem in China, where there seems to be quite literally no trust at all on online shopping. This actually does seem to be the case if you try buying devices from any NON-xiaomi-official store Aliexpress shop…

Jesus, do you have any sources (Chinese is fine) for this? This is horribly anti-consumer and I'm surprised there's not more of a push back if it's so common.

another reason being some eBay/re-sellers buy in low cost places (like India/China) - reinstall EU ROM and sell it at high cost. (Even now many devices in Asian markets come with a label like - Only for India-SIM)

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#380
post #351

Earlier quoted context omitted.

I am using Xiaomi phone for roughly the same reasons as I am using Gmail. I dislike results of either, replacement of both is on my oversized TODO list - and was there since at least two years. I dislike that USA government, China government and God knows who else has full (partial?) copy of whatever I ever typed on my phone but I did nothing beyond selecting Android Zero, declining "send all what I typed to Google"…

I have massive respect for OSM maintainers. People don't appreciate how much work goes into the map data. Anyway, you're right. In practice, protecting your privacy is a massive hassle. I just do it step by step, knowing that even half-assing it is better than nothing.

I really hope that privacy situation will start getting better - or at least not getting worse.

For email I basically gave up (for now) as it will likely leak on other side anyway.

But I aggressively avoid cloud sync, and my files on cloud are either public or locally encrypted before uploading. Well, at least it protects against non-targeted attacks.

> I have massive respect for OSM maintainers. People don't appreciate how much work goes into the map data.

:)

Just in case that you have an Android phone - I recommend StreetComplete, it allows limited editing with zero OSM-specific knowledge. Registering for OSM account is the most difficult part.

It works by asking about already mapped elements, while you are in front of them. See https://github.com/streetcomplete/StreetComplete#screenshots

Post reply on HN