Live data from Hacker News

Xiaomi Recording ‘Private’ Web and Phone Use

forbes.com

91–100 of 254 posts

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#91
post #4

I recently wiped my factory-unlocked Samsung S20, enabled debug mode, and ran "pm list packages" over ADB. The results were beyond startling. There were close to 100 packages running under com.samsung and other various namespaces with tons of sensitive permissions. Most of these processes I could not identify what they existed for. And I still can't figure out why a freshly wiped unlocked phone w/ a Sprint SIM is run…

I wonder if it is illegal under GDPR to include spying apps on phones without telling the user.

The question of the GDPR is not whether it's illegal but whether anything is done to crack down on offenders. Facebook, Google and thousands of marketing/analytics/advertising companies are still around and are stalking users with total disregard of the GDPR, so that's a clear negative.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#92

Earlier quoted context omitted.

With the Bootloader exploit on iPhone X and older, its actually worth looking at them now.

Checkm8 is a tethered exploit, so probably not super useful if you want to sideload another OS and not have a bad time.

I remember back in the days of the iPhone 3G(s?) there was an attempt at a battery-powered dongle that could re-jailbreak a phone in the field in case of a reboot. The same technology could be built into a battery case or similar, not to mention recent technological advances mean it can be done in a small package the size of a Lightning connector or a Yubikey and you can carry it on your keyring.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#93

I recently wiped my factory-unlocked Samsung S20, enabled debug mode, and ran "pm list packages" over ADB. The results were beyond startling. There were close to 100 packages running under com.samsung and other various namespaces with tons of sensitive permissions. Most of these processes I could not identify what they existed for. And I still can't figure out why a freshly wiped unlocked phone w/ a Sprint SIM is run…

> And I still can't figure out why a freshly wiped unlocked phone w/ a Sprint SIM is running a Verizon provisioning process.

Samsung has a rather "interesting" (to say the least) firmware development process (if you can call it a process). It seems that most handsets certainly used to ship with if-gated Verizon specific hacks all over the firmwares, regardless of market the device was for. I believe this was just for simplicity's sake. It sounds like nothing has changed there.

As much as Samsung loves to advertise enterprise security like Knox, it only takes a few minutes of digging through the history of Knox to see some blunders from the early days, like storing the plaintext Knox PIN, to really wonder how on earth they can secure it.

Call me old fashioned, but I just don't have any confidence in the development practices of any phone vendor these days - even plain pure AOSP Android has so many external library dependencies, each of which is receiving CVEs and patches regularly (hopefully), and needs to be kept updated by AOSP maintainers.

I used to track the ancient kernel CVEs that were being rediscovered in Android due to poor or non existent source code control in OEM kernels. I gave up as it was pretty much a flood of 2 or 3 year old bugs being rediscovered as unlatched on Android or Qualcomm kernels.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#94
Wow, just... Wow.

> Xiaomi said, “The research claims are untrue,”

and

> When Forbes provided Xiaomi with a video made by Cirlig showing how his Google search for “porn” and a visit to the site PornHub were sent to remote servers, even when in incognito mode, the company spokesperson continued to deny that the information was being recorded. “This video shows the collection of anonymous browsing data, which is one of the most common solutions adopted by internet companies to improve the overall browser product experience through analyzing non-personally identifiable information,” they added.

"We're not doing that. And everyone does that, so it's OK that we do that".

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#95

Stuff like this is why without fail, every phone I own gets LineageOS installed immediately. Xiaomi phones have a bootloader unlock timer to try and mitigate sites reselling their phones with modified software, so I had to leave my Mix 2s alone for a few days before I could make it safe to use.

This is why, without fail, I buy iPhones.

And then you can't install anything Apple doesn't want you to install. I like being able to run gameboy emulators on my phone for games I already paid 20 years ago, change my launcher/dialer, browser, etc.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#96

Earlier quoted context omitted.

Why would they go to all that trouble? Just 1. keep sending any and all data without any obfuscation 2. blanket denial of any wrong doing, regardless of how obvious 3. decent hardware for zero down on a contract profit!!! your way is so much more work...

Parents option would likely get around privacy regulations in some countries. So they can do the “much more work” you mentioned and also sell decent hardware for zero down on a contract, getting a bigger total market and more surveillance info.

Well the EU and Canada seem to be terrified of putting a foot wrong with the CPC, so my guess is that Chinese companies will violate people's privacy until it becomes so blatant that they get a polite request to tone it down (and obfuscate the collection).

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#97

Just wait till they: - start encrypting all the data they collect (with real encryption, not base64 encoding) - saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server) - sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia) - monitoring at the kernel or firmware level so that it doesn't matter what browser or…

With some fleshing out, this is an excellent rendition of the { DRM, malware, spyware } evolutionary path, pretty close to what was described to me by RealNetworks back in the dotcom era. Need to add anti-reverse-engineering techniques - obfuscation, self-modifying code, custom and hard to reason about embedded VMs, etc. other than anti-debugger and test harness detection. I think earlier on.

I thought it went: DRM, spyware, then co-opted for malware by others.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#98
"Your privacy is very important to us and the CCP, because we profit when we violate it"

Don't buy anything from a company that ultimately answers only to the Party. What else is there to say? Other products may be just as crap, but they'll never be potentially crappier.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#99
post #86

Stuff like this is why without fail, every phone I own gets LineageOS installed immediately. Xiaomi phones have a bootloader unlock timer to try and mitigate sites reselling their phones with modified software, so I had to leave my Mix 2s alone for a few days before I could make it safe to use.

Are there any resources describing what you lose and gain by installing LineageOS? I'd like to know what will stop working before I try it out...

It has been a long time since I used stock Android, but depending on your phone you don't lose much. The base install doesn't have any google apps, but adding them is simple. The biggest loss is in manufacturer unique apps, which can also be seen as a gain considering how companies like Xiaomi use those apps.

Besides that, there can be some security gain if set up properly, I think some additional configuration tweaks, and LineageOS often a longer support cycle.

It really depends on your phone though, try searching your model +lineageos and you should find out the details.

Re: Xiaomi Recording ‘Private’ Web and Phone Use

#100

Earlier quoted context omitted.

Systemless root + root hiding is a thing. I run a custom rom and pass safety check and have access to all my apps including banking.

This is why people need to start rejecting closed ecosystems. If you own the hardware you can control everything that happens on it including companies trying to force their will upon you

more people would reject them if there were alternatives, but the only things on the horizon are pinephone and purism (neither which are really shipping/working)
Post reply on HN