Live data from Hacker News

Are Xiaomi browsers spyware? Yes, they are (2020)

palant.info

501–505 of 505 posts

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#501
post #499

Earlier quoted context omitted.

My problem with GSI was last I checked (1 year ago) it still did not support storage encryption (Max 3), and SELinux was off. Awesome project though.

Uh, both have been forever wrong using my GSIs? I've never made any GSI without storage encryption, and My GSI have always been running SELinux enforcing. Some kinds of GSIs have those kind of issues, but it's only those that are binary ports from OEM ROMs, like port from Xiaomi or OnePlus ROMs, but proper source-based GSIs shouldn't have those issues.

Prompted by your comment I reflashed my Xiaomi today with the latest A/B GSI [1], and the phone seems to be encrypted. Many thanks for your great work!

https://github.com/phhusson/treble_experimentations/releases...

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#503

This paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated…

|This should have been caught at a security review stage during design, it should have been caught at the code review stage, it should have been caught by automated tests, it should have been caught by QA, it should have been caught once live by data tests, it should have been seen once live by analysts, it should have been fixed at so many different points.| If the very first people (presumably the "higher ups"/more…

If your design is "accidentally" indistinguishable from intentional state-sponsored surveillance, does it really matter whether you arrived at it through malice or incompetence?

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#504
post #236

Earlier quoted context omitted.

>I remember the UK government investigation into Huawei concluding that not only was their security posture insufficient for critical infrastructure, but their engineering practices were likely a decade away from being at a point where they could start to claim good security practice. This paragraph seems to suggest a similar problem at Xiaomi. ASFAIK, Xiaomi does not sell any critical infrastructure equipment, nor i…

Presumably phones used by government employees in relation to sensitive data are security critical? I'm not aware if their phones are being used in the wild in such a way but it's not hard to imagine such use cases.

Here in Europe, Huawei and Xiaomi are two of the most popular phone brands I see in shops. Even if the government isn't actually buying them to issue as "work phones" for employees, those employees are certainly buying them for personal use, carrying them to sensitive places, and leaking their own life details.

You'd have to be a complete idiot to believe that the CCP isn't happily digging through all the data they send back.

Re: Are Xiaomi browsers spyware? Yes, they are (2020)

#505

Earlier quoted context omitted.

I believe the implication would be they are spying for China in this case, and therefore as legal as they want it to be.

Right, I meant is it allowed by Chinese law to NOT spy for the government. As I understand it, to be allowed to operate in China as a Chinese company, you are under the obligation to provide any information you collect to the gov't upon request. Is that not the case?

There is a difference between being required to collect data that they wouldn't otherwise need for a legitimate business purpose, and being required to provide access to data they've already collected to their government. I'm no expert but it seems like a Chinese company could design products that don't collect a bunch of extraneous information, without violating Chinese law.
Post reply on HN