Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

391–400 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#391

Earlier quoted context omitted.

I think you're both on the same page here, but (and I'm also guessing here) I think OP implies there's a certain bias when it comes to chinese servers. And I too have this feeling, that if it's a server in the "western world" not a lot of people would bat an eye. But if it's a chinese or russian server, now that's something "we don't want".

This is what I am trying to figure out. I have a UK focused website therefore I use UK based servers, US focused website I use US based servers. Aren't most processing chips/hardware made in China for all major western tech companies anyway? I get the RU/China server suspiciousness but as far as I can tell, US unicorns are up to the same tricks and openly/brazenly pillaging data without any threat or fear.

Of course (almost?) no government is a saint. However, China is a totalitarian non-democratic government. I would fear the Chinese government much more than the US or UK governments, for example. But I might be too naive.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#392
post #240
post #209

Earlier quoted context omitted.

And yet from the free to export US we keep finding backdoors and hardcoded admin passwords in things that are supposed to be way more secure than a random chat client. Even if all of them are actually bugs I'm not sure that is any better. No E2EE to share my shopping list with my girlfriend versus the piss poor security in enterprise hardware from manufacturers like Cisco etc? At least I can download another chat cli…

Huawei's security doesn't come close to Cisco's security practices. Mostly because the vast majority of their hardware and software was sourced from stolen IP (Huawei had cash bounties for employees to provide stolen IP to the company). If you sell stolen technology, you don't truly understand how it works or how to secure it. Given the choice, I'd choose Cisco every day of the week. It's not perfect but then again t…

What are your thoughts on Ubiquity?

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#393
post #11

I recently bought a Xiaomi phone (Poco m3) for development. I was shocked to learn that in order to enable USB debug mode in developer settings, I needed to BOTH : 1) make a Xiaomi account with and 2) insert a SIM card to the device (!) Is that not insane? Other people seem to think so too: https://android.stackexchange.com/a/186052 Apparently the only alternative to this is rooting the device, which may break it.

I just bought the same phone as a gift for my girlfriend, and was considering getting one for me one day since it's a really nice piece of hardware for the price. Some searches around brought this link of a community of non official developers attempting to clean up the system from some preinstalled junk. https://xiaomi.eu/community/

You are probably better off wiping it and installing stock android or some popular custom ROM over trying to hack away the MIUI spyware.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#394
post #258

Earlier quoted context omitted.

Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust. Whether caused by inept software devs, scope for malicious code / backdoors in firmware, analytics spyware, and whether this stuff is well intentioned or not, if it can be abused, it will be. Open source and verifiable down to the firmware is the only chance…

> Open source and verifiable down to the firmware While I agree with your intent, the problem is that, many open source software is not verifiable. Remember that a Kaggle competitor was openly cheating with his published code? (cf. https://www.theregister.com/2020/01/21/ai_kaggle_contest_che... ) Eventually he got caught, but it's sometimes extremely difficult to spot a well-hidden malicious code in a plain sight. We…

> many open source software is not verifiable

Open source software is more verifiable than closed source though.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#395

Earlier quoted context omitted.

Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust. Whether caused by inept software devs, scope for malicious code / backdoors in firmware, analytics spyware, and whether this stuff is well intentioned or not, if it can be abused, it will be. Open source and verifiable down to the firmware is the only chance…

Purism is never going to end up with fully open source baseband firmware. It's not going to happen because the radios are subject to several regulations which means customers can't be able to modify that firmware. There's going to always be a trust hole.

People should push for open source as much as possible. At some point it will be easier to lobby for the new regulations when everything else is fully open source. See also: https://forum.pine64.org/showthread.php?tid=11815

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#396

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

the company is also doing some sketchy things in the smart home space under their brand "Aqara"

The whole idea of connecting everything to the internet is getting out of hand.

1. Internet and digital infrastructure has no integrity as how it is currently.

2. Anything for home, machinery, all should work when there is NO internet connection. Just like an app should work (to some extend) in airplane mode. It really comes down to the idea of data/device sovereignty.

Is this my device or not? If I need to ping some place in China to get this working. Then make it clear on your front page that it is is a lease.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#397

Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xi…

I use some xiaomi connected lamps. First thing I did was connect them to home assistant via a dedicated VLAN that has no internet access. I see pages and pages of denied connections in the firewall from the smart lamps. They work with HA just fine, I just wonder what they’re trying to do with these servers. This is pure speculation but I’m convinced that all these smart devices from China are the largest state sponso…

I was thinking the same. The Mi ecosystem seems nice, has good reviews, and is relatively inexpensive. You can control everything from one app and they make things easy for you. Among many appliances they also have inexpensive IP cameras. When you think about it, it's really scary. They have all possible sensors and several actuators. With time, it may get much worse.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#398
post #222
post #162

Earlier quoted context omitted.

> Your assertion is just a variation of "if you're not doing anything wrong you shouldn't worry about spying". Really, that is what you got from my comment. In the case of CCP it can even be who you are, as in Tibetan, Uighur and so on.. Or, a national of a different country that China wants to spy on, or a relative of someone that China thinks has a differing opinion from CCP and so on.. It's not even on the same pl…

well under the trump administration, we were at the state where ICE was getting tips from unlawful traffic stops and deporting said immigrants/refugees. They're both evil, just that US is less so.

Immigration violations are crimes the world over. Disliking the CCP's policies, not so much.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#399

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

|This should have been caught at a security review stage during design, it should have been caught at the code review stage, it should have been caught by automated tests, it should have been caught by QA, it should have been caught once live by data tests, it should have been seen once live by analysts, it should have been fixed at so many different points.| If the very first people (presumably the "higher ups"/more…

This is something that a company with a mature security posture needs though. Yes it's hard, but that's the point.

There are many ways to work around this, having teams whos incentives are tied to finding issues, maybe in a different reporting chain or office or country to those writing the software is one way.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#400

Earlier quoted context omitted.

No, pretty of radio transmitting equipment are fully open soft modems. As far as I know, there is no licensing whatsoever for baseband makers? Where did you get that it is?

In the US a baseband processor's entire software stack that controls the radio front end must be certified. They'll also have the modems to talk to the cellular networks. BPs use their own CPU(s) and an RTOS firmware that's FCC certified. This is why a baseband processor is a fully separate component from a device's application processor(s). Since the AP doesn't talk directly to the radio it doesn't need to be certif…

> In the US a baseband processor's entire software stack that controls the radio front end must be certified.

Can you point where it is stated?

Post reply on HN