Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

381–390 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#381
post #137

Earlier quoted context omitted.

How much political influence do you think someone like Bezos really has? Everyone in washington hates him. No one wants to do favors for him. They drag him in front of congress do get a bunch of soundbites to play next election cycle. They win elections on shutting down his headquarter plans. They want to break up his company, raise his taxes on unrealized capital gains, they want to force him to divest his personal…

> Everyone in washington hates him. In public, sure. Behind the scenes, they're taking meetings with his lobbyists, and somehow the tax raise never happens despite politicians talking about ad nauseam. Part of modern politics is running a kabuki theatre of performative populism on the campaign trail. Not much happens once they are in office, because you need quick wins ahead of the next election.

+ 1

also note that the Asian billionaires are learning for people like bezos/gates. In public they may be hate figures - but everyone orders from Amazon. Tax breaks for large companies.

(i.e) use thinktank to pass legislation to make everything they do legal.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#382

Earlier quoted context omitted.

Xiaomi phones are frighteningly popular here in Russia because they're very cheap. Like, a-phone-could-not-cost-this-little cheap. A 7000₽ (around $100) phone? Why not, seems legit! And not many people really understand what Xiaomi is actually doing to offset that cost. Heck, when you open the built-in calculator app in MIUI, it has a freakin privacy policy and refuses to operate if you don't accept that. Same for th…

I love Xiaomi phones, I've owned a couple. But I wouldn't dream of using them without first replacing MIUI with Lineage OS.

Any chance of getting Lineage OS support for the Poco X3?

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#383
post #375

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

> temp/humidity sensors If you're into writing your own code, https://ruuvi.com/ has bluetooth low energy sensors that transmit temperature/humidity/air pressure/3d-acceleration data with an open protocol, also their firmware is open source. They have a mobile app that displays readings from sensors, but for anything else you'd need to set up your own data logging or home automation server.

I can also recommend ESPhome, it supports many sensors and runs on basically anything with a ESP32 or 8266. It's open source and super easy to integrate with home assistant.

edit: and -> a

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#384
post #339
post #305

Earlier quoted context omitted.

> The devices require a wi-fi connected hub, not too strange for things that use Zigbee Wait, why would Zigbee devices require Wi-Fi connection? That would be a red flag for me, I would have avoided products like this.

Usually so you can control the devices from your smartphone. Phone talks to hub over local wi-fi, hub talks to devices over Zigbee. They might have a web interface where you can program schedules for the lights, define "scenes" and such. So it's not entirely pointless. There is however no reason why the hub should have internet access though.

I believe they are used to allow the users to control their devices outside the network.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#385

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

Xiaomi did one thing wrong: It is a Chinese brand.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#386

Earlier quoted context omitted.

I think you're both on the same page here, but (and I'm also guessing here) I think OP implies there's a certain bias when it comes to chinese servers. And I too have this feeling, that if it's a server in the "western world" not a lot of people would bat an eye. But if it's a chinese or russian server, now that's something "we don't want".

This is what I am trying to figure out. I have a UK focused website therefore I use UK based servers, US focused website I use US based servers. Aren't most processing chips/hardware made in China for all major western tech companies anyway? I get the RU/China server suspiciousness but as far as I can tell, US unicorns are up to the same tricks and openly/brazenly pillaging data without any threat or fear.

We're in a western/US-centric bubble here on HN. People are aware data collection is bad, they'd rather not have it at all even if they'll accept some from Google, MS, Amazon, etc., but most of all they'd rather not have China/Russia/NK/etc. have any that data. As you can already tell, just asking the question is enough to get flak.

Otherwise most consumer products (devices or software) phone home for one reason or another, whether it's telemetry and data collection, basic functionality that's implemented exclusively via cloud, or more advanced cloud features. It's down to deciding whether you trust western legal system and increased transparency to deal with the nefarious aspect of data collection, rather than the Russian, Chinese, etc. legal systems and transparency.

Almost every device or software with network connectivity I played with phoned home: the Philips Hue gateway (Netherlands), Tado (Germany), Apple Homepod (US), Amazon Alexa/Fire* stuff (US), Synology (Taiwan), Unifi Controller (US), LG/Samsung smart TVs (South Korea), Google Chromecast (US), random assortment of network connected cameras (China, Taiwan), and a big etc. here. Some do a better job than others and just connect for basic stuff as far as I can tell, some enabled telemetry without asking and after the backlash ask again after every update, some have no option to disable this connectivity, etc.

One thing that trips most people looking at this for the first time is when they start off with blocking internet connectivity for the least trustworthy devices (Chinese brands) and immediately see a zillion attempts being blocked, even if the device keeps working. They conclude the devices are trying to exfiltrate that much data. They're most likely constantly reattempting until they get a response. Some of my network cameras would try every second but after a successful connection the flood stopped and they barely sent anything.

I chose to "complicate" my life a bit and buy hardware that I can flash with some open source firmware cutting out the cloud features completely, or connecting via "home made" solutions everywhere I can then using my home VPN to control them if needed. Whether China or the US have that data is of little real consequence to me right now but it's a matter of principle and I'd rather not shift my principles based on geography.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#388

Earlier quoted context omitted.

But in context: - Australia has similar laws. - Snowden releases showed the US don’t even ask, they just take it. So it’s not like there is a huge amount of difference around the world.

> But in context: > > - Australia has similar laws. > > - Snowden releases showed the US don’t even ask, they just take it. > > So it’s not like there is a huge amount of difference around the world. I am not familiar with Australia privacy law, could you give me a rough idea what is look like? Snowdon case made the US government look bad, please don't use the same reason to make the Chinese Communist Party look good…

> I am not familiar with Australia privacy law, could you give me a rough idea what is look like?

I assume it's the Australian Assistance and Access Bill that's being referred to here. It has nothing to do with privacy. It's prime job (which isn't hidden - it's spelt out in the explanatory notes) is to circumvent encryption by accessing the data at the end points, where it isn't encrypted. It must be unencrypted at the end points because humans can't read or listen to encrypted data. https://searchsecurity.techtarget.com/definition/Australian-...

The bill gives several government agencies the legal right to coerce any software company to "assist" them by writing a bug that is invisible to the OS. The "access" part gives them right to coerce a software company to distribute software to any device they target (there is legal oversight on who they can target).

To fill this out with a concrete example, they could compel Google to provide a version of the Android Google Keyboard that records all key strokes and the name of the application it is are sending them to. They can then force Google to install that keyboard via their auto update mechanism. Notice that using an open source program like Signal that securely and correctly encrypts everything, and comes from a trusted source is not a useful defence against this.

Both of these powers are accompanied by an automatic gag mechanism, meaning if Google revealed they were asked to do either of these things someone would go to jail. The provisions in the act for reporting when and where these powers are used, so the voters could have some say are to put it mildly weak.

Although Australia is very clearly a country that operates around "the rule of law", in the end the only difference that has made is we know they are doing it, whereas China could deny they are doing it. In reality, I don't think China tries to deny the Great Firewall of China, or the invasive probes they force citizens to install to support their social credits system.

So yeah in my view OP is quite correct. If there are differences they revolve around how widely these things are deployed, not over whether they exist. I presume my home country, Australia, deploys them a lot less, but they go to a great deal of trouble to ensure there is no way to be sure.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#389

Earlier quoted context omitted.

Could it be the same reason anyone outside of the US would voluntarily choose to run close-source software from a company that's subject to domestic laws and regulations in the US? The ECPA is no joke.

Responses like this are so predictable and shed no further light or provide no new insight. They're unproductive and flame-war prone. I downvoted your comment.

The original message was saying they couldn't understand / couldn't empathise with someone making a conscious decision to use xiaomi. I gambled that they make the same conscious decisions using US software, but only see their decision to do so differently due to a set of pro-US biases that others won't have.

It's difficult to look past such biases if they're deeply ingrained but I think this can definitely be productive to do so. If you can empathise better with conscious xiaomi users, and understand why people use non-optimal software, such understanding can have a lot of benefits.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#390

Earlier quoted context omitted.

Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust. Whether caused by inept software devs, scope for malicious code / backdoors in firmware, analytics spyware, and whether this stuff is well intentioned or not, if it can be abused, it will be. Open source and verifiable down to the firmware is the only chance…

The problem is that purism doesn't pay as much as all the tracking, preinstalled bloatware, random 3rd party utilities and other stuff. This will never ever be solved through competition,because people either don't care, or there aren't enough of those who do. Legislation is the only way to make it work, but then again, that's hardly an option for most of the world.

Purism are trying to lobby for the legislation [0] and to change the industry [1].

[0] https://puri.sm/posts/purisms-ceo-todd-weaver-testifies-at-s...

[1] https://wp.puri.sm/posts/breaking-ground/

Post reply on HN