Xiaomi Recording ‘Private’ Web and Phone Use
forbes.com
forbes.com
- start encrypting all the data they collect (with real encryption, not base64 encoding)
- saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server)
- sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia)
- monitoring at the kernel or firmware level so that it doesn't matter what browser or apps you use
- turning off data collection when it suspects a security researcher (due to signs of debuggers, development tools, network monitoring, usual network settings like to proxies or DNS, etc)
We won't be able to prove anything. So disheartening.
Then that's your counter measure... run a debugger 24/7.
All Android phones. But they send the data to google and facebook so they must be good.
Knowing what Google's business is, I doubt they don't merge that data for a more complete profile.
You can try this yourself: Create a YouTube account, upload a picture for the account, don't add details like a phone number.
Now create a contact on Android, add a phone number (as most people do with contacts on their phone) and add the email address you registered the YouTube account, the Android contacts app will pull the profile picture from the YouTube account, and put it on the phone as the picture for the contact.
Gave me quite a little scare when I discovered this by seeing my YouTube profile picture as the contact picture on a (rather privacy and tech-illiterate) friend's Android phone, even tho I never added any phone number to any of my Google accounts, all he did was add my email address to the contact.
profit!!!
your way is so much more work...
Look at how they bent the knee with Huawei and ZTE. Also can’t figure out how to produce hardware in their home soil, as much as they’d like to.
Hand-labor today is used as an interim solution, when the scale doesn't justify bespoke automated assembly line. When factories are 'brought back' to the West, its because they scaled up and automation is now affordable.
Serious note - welcome to the future. Nothing is private anymore.
Need to add anti-reverse-engineering techniques - obfuscation, self-modifying code, custom and hard to reason about embedded VMs, etc. other than anti-debugger and test harness detection. I think earlier on.
Most software on the smartphones aren't under our control, we aren't able to stop them, disable them, inspect them, or see the source code.
I think we should undo everything done in the smartphone since 2008 and come up with a true open source smartphone.
To make what you mention work, that smartphone will not only need to be open source, but also be much better in both UX and features and cheaper than anything similar.
No idea if it is good just that it's happening.
But yeah the trend is troubling. I also believe that it's only a matter of time once the "smart" devices (fridges, TVs, etc) start shipping with 5G modules enabled that send data to the mothership whether you set up WiFi for them or not. Because while you can't buy non-smart TVs, many users don't enable smart features by not connecting them to the network. The 5G module will probably only exist for tracking purposes and maybe firmware updates, but not for the netflix/youtube app.
There was an interesting discussion on HN recently regarding appliances that can handle open source firmware[1]. Several advantages I've found with open firmware include stability, security, avoiding unnecessary e-waste, you're not locked into a manufacturer that might discontinue support for the device, and privacy. If such appliances existed, I would certainly consider them when purchasing an appliance.
Is there any word on whether that is true for european region phones as well? From what I remember they disabled certain functionality like Face Unlock in the EU. Not sure if it was due to privacy or patents, but given the GDPR I wouldn't be surprised if it was due to privacy.
[1]: https://www.xda-developers.com/poco-x2-custom-rom-kernel-dev...
They still disrespect ROM users: You have to go through a convoluted process involving Windows software and a Xiaomi account AND wait 3 days to unlock the phone - but that's way down from the 6 weeks I've read about on other Xiaomis, so you can be sure I'm not going to buy one of those.
I have had friends suddenly get very selfish when the chance to get even $10 is available. I had a regular at a retail job once who came in every day... he asked to borrow $1 once to help pay for something. To avoid paying it back, he never returned, likely walking an extra several km to the next nearest store of the type every day. For $1
I expected some Volkswagen like defeat device to in phones to evade security audit.
But what can "I" do, considering that the bodies & Govt that are suppose to do something are busy stuffing their own pockets and busy with petty politics.
Open-source hardware progress is very slow and low RAM. How safe will I be if I just run LineageOS on a Xiaomi device?
I do not trust any of these Android manufacturers to do right by people. Even the Pixel phones have a "Support" application that has camera permissions -- which last I checked, couldn't be changed regardless of whether you need support or not. What's going to happen when some obscure team within Google pushes an update to this app to do something without user approval?
When it comes to Facebook I am not aware of any investigation or enforcement action being taken despite them being even worse than Google when it comes to privacy and having proven their malicious intent and complete disregard for the privacy multiple times.
Sort by amount fined.
It is illegal but it is not enforced.
I run a custom rom and pass safety check and have access to all my apps including banking.
https://developer.android.com/training/articles/security-key...
Hah. If properly paying for films requires you to install quasi-rootkits that spy 24/7 on your personal life, and pirating gives you a high-quality .mkv you can play anywhere you want, I damn fucking well know which one I'll choose. "Brave but big sacrifice"? That's just devaluing those words.
Unfortunately, Android has emerged as the tracking and advertising platform. Look at every single Android TV on the market, they're privacy-invading garbage and such practices are explicitly enabled and encouraged by Google.
Samsung has a rather "interesting" (to say the least) firmware development process (if you can call it a process). It seems that most handsets certainly used to ship with if-gated Verizon specific hacks all over the firmwares, regardless of market the device was for. I believe this was just for simplicity's sake. It sounds like nothing has changed there.
As much as Samsung loves to advertise enterprise security like Knox, it only takes a few minutes of digging through the history of Knox to see some blunders from the early days, like storing the plaintext Knox PIN, to really wonder how on earth they can secure it.
Call me old fashioned, but I just don't have any confidence in the development practices of any phone vendor these days - even plain pure AOSP Android has so many external library dependencies, each of which is receiving CVEs and patches regularly (hopefully), and needs to be kept updated by AOSP maintainers.
I used to track the ancient kernel CVEs that were being rediscovered in Android due to poor or non existent source code control in OEM kernels. I gave up as it was pretty much a flood of 2 or 3 year old bugs being rediscovered as unlatched on Android or Qualcomm kernels.
"But we have video of your device sending data to..."
"...but, but, anonymized!"
"I thought you said you weren't sending data at all, now it's just anonymized browser data, but we see your devices sending device usage outside the brows..."
"ANONYMIZED!!!!11"
In all seriousness, this is a point GDPR struggles with. It's really hard to properly define what constitutes personal data.
The same data can be both PII and not PII depending on the context.
Not sure what the struggle is?
The GDPR does specify what is personal data, but doesn't go out giving real-life interpretation examples. The categories given in the regulation are direct identifiers and indirect identifiers. The categories even include a good sampling of information types that belong in each.
Direct allows to identify an individual or a very small group from a single datapoint. Indirect allows to identify larger groups.
Or to put in terms most of us here understand.. Direct identifiers are personal information that would allow to send marketing junk to selected individuals. Indirect ones are those you would use to build marketing cohorts.
So if it's data your marketing department would like to grab, you can bet it's personal information under GDPR.
So "It's anonymized" but It's not anonymized.
> In all seriousness, this is a point GDPR struggles with. It's really hard to properly define what constitutes personal data.
GDPR is good. The problem is that GDPR is not enforced because it might upset Uncle Sam
> Xiaomi said, “The research claims are untrue,”
and
> When Forbes provided Xiaomi with a video made by Cirlig showing how his Google search for “porn” and a visit to the site PornHub were sent to remote servers, even when in incognito mode, the company spokesperson continued to deny that the information was being recorded. “This video shows the collection of anonymous browsing data, which is one of the most common solutions adopted by internet companies to improve the overall browser product experience through analyzing non-personally identifiable information,” they added.
"We're not doing that. And everyone does that, so it's OK that we do that".
One often hears from undemocratic regimes that they aren't torturing people in the manner accused, and that if they were it wouldn't be so bad, and that if it were bad it would still be well justified. On hearing these three in combination, little doubt should remain that the accusers have it right.
Best thing to do when you got an android phone, especially from a chinese manufacturer, is to flash LineageOS on it.
I have Redmi phone and I hates it as soon as I found that there is ads in their rom. It's so disappointing. I mean, other Chinese brand have their own crapware yes, but ads?
I then flash my phone to pure Pixel rom and never been happier, until the bank app incident happened. So I have to use their original rom for now until I get a new phone.
No matter how rave the Mi phone review be, or how it is great 'bang for the bucks' brand, I will never touch their phone again.
The only benefit Android had was the control. You take that away and make it a walled garden, its just an iPhone...but worse
But it will be difficult to clamp down on leaking user security and privacy when Apple itself has unencrypted backups, so they can’t pressure other companies to proactively protect user data at rest.
I’ve stopped using higher quality non Apple apps because even something like a calendar app or todo app warrants a special private cloud that slurps up your data with a legitimate argument for why they should have everything.
Without an extensive research project there is no telling what's going on under the hood imho.
Buying a phone that allows custom ROM is really beneficial. Not just it gives you more fre<Censored>edom and choose, it can also expand the lifespan of the device and thus save you a bit of money.
A side note: Fairphone looked quite nice, but that €450 price tag pushed me out far far away :(
Also curious: can you trust the hardware even if you do flash lineageOS? Honestly curious
Xiaomi phones have a bootloader unlock timer to try and mitigate sites reselling their phones with modified software, so I had to leave my Mix 2s alone for a few days before I could make it safe to use.
The dongle idea I'm talking about would be to have a convenient way to exploit the vulnerability for the benefit of the user to boot the device into a jailbroken mode in case of an unexpected restart (battery runs out and you're away from your computer).
You can sideload it yourself if you have a mac, or you can use something like buildstore that gives you a provisioning profile, but that's 7$ a year or something.
Happily paid that. The buildstore also offers things like ad-free youtube and twitch.tv app tweaks, torrent clients, you name it.
- the possibility to install your own distribution, whether that be alternative versions of iOS or a totally different OS
- expandable storage, preferably with a boot option
- an official method to side-load software outside of the 'walled garden'
- either more extensive access to the innards of iOS or root, this to allow e.g. a true firewall (with ingress and egress blocking), a system-wide network blocker ('adblock' et al), etc.
- the possibility to run interpreters and compilers
- a real browser choice, not just a shell around Safari
In short, the possibility to have a less restrictive system.
Since I don't see Apple opening up in this way unless they're forced to by law or by declining sales I don't see myself buying any of their products in the near future.
I'd like to know what will stop working before I try it out...
Besides that, there can be some security gain if set up properly, I think some additional configuration tweaks, and LineageOS often a longer support cycle.
It really depends on your phone though, try searching your model +lineageos and you should find out the details.
That as well as much better battery life and more control over what apps are and aren't allowed to access.
The only apps that stopped working on my Poco F1 are apps that check for modified Android. For example my Australian digital drivers license app doesn't work as it detects the Android environment as non-standard. I believe you can do some root magic to work around it, but I could never be bothered to do so. Interestingly enough the three different banking apps I use all work fine.
Have a look at the installation instructions to see how you feel about it [0]. They are usually really good. The devil is in the detail though and you probably have to plan in an afternoon to use google to find workaround for bits that don't work. For example when I was upgrading to the latest Android version I had to install a different bootloader as the previous one wasn't compatible. It took a bit of looking around, but going from the error messages usually brings up the right solutions in various forums.
This is starting to not be the case, I couldn't get the wide angle camera working on my newer Xiaomi Mi 10 Lite for example. I had to fall back to miui.eu based rom to get it to work.
Is there even a single way to run lineageos without making significant tradeoffs?
I have a tissot with LineageOS 16.0, not sure yet whether it will get 17 ported to it as well. The hardware is great for the price (bought it a year after launch, heavily discounted). I bought it specifically to run LineageOS on it, so I have no idea what the stock experience is like.
Running it for 2 years now.
The bootloader is locked by default but if you ask for it to be unlocked they will do it. The process is intentionally manual to prevent hacking, but ultimately smooth.
Not only you need a Windows computer to unlock, but then it takes literally months to proceed and if you happen to do something that you're not told you should not do (like logging out or re-trying to unlock), the counter is reset and you have to wait even more. Plus the unlocking program on Windows randomly doesn't work and error messages are not helpful at all.
My Xiaomi is an impressive, nice and powerful phone that hasn't cost much. But it was so much pain to root that I won't probably ever buy a phone from them in the future.
It's gross.
It would've been a good opportunity to allow people to install whatever they want, to show that they're different than Samsung and other competitors, but no, they went and locked that down because of "safety". Mhmmm.
I'm using a Xiaomi with Android One and despite having opted out of analytics the phone still tries to connect to Xiaomi servers.
I've been considering installing LineageOS on it for some time but unlocking the bootloader unfortunately deletes everything I have installed or downloaded. I've never used the stock browser though, always Firefox.
[1] https://raw.githubusercontent.com/jerryn70/GoodbyeAds/master...
[2] app.chat.global.xiaomi.net
If they're not selling your data, then you get to pay full price for the phone. Not a crazy idea, really, but I wish that was made clearer.
I would expect this to carry the heaviest penalties possible including massive penalties against China if they fail to enforce them, but I guess nothing is going to happen given the current state of society.
It's a lot worse than Chrome ?
The Xiaomi browser tracks your browsing. The Google browser in combination with the most of the sites in the internet track your browsing, your location, and a lot of other things.
Choosing the lesser evil is quite popular now days, and it's obvious which one it is.
Indeed: it's Firefox.
Safari?
https://en.m.wikipedia.org/wiki/List_of_mobile_phone_brands_...
I’ve visited Taiwan for work quite a few times and met with some of the big tech manufacturers. Very professional teams of engineers and a beautiful country.
It would be super interesting if a Taiwanese manufacturer developed a smartphone + ecosystem whose selling point was no spyware and openness, at the price point of the Chinese manufacturers.
Right now their only influence is financial, which Taiwan work pretty hard to resist where possible.
Having a Xiaomi phone myself there's a trade-off between using the official ROM, that provides full device encryption and SE Linux enforcement, but tracks what you do in settings, and unofficial LineageOS (PHH GSI), that does not encrypt the device data and has SE Linux off on most Xiaomi phones, I ended up sticking with MIUI.
Screw Xiaomi and screw Google and Microsoft.
Clicking the "do not sell my info" link takes you to a page where it asks you for your personal information to request to opt out... with the fine print telling you that you can actually opt out by going back to the previous dialog, selecting more info, then selecting one of the three cookie sections (which is not labeled "do not sell my info" or anything similar). There's then a timer where it takes about a minute to update the cookie preferences.
I know Forbes has turned into a glorified blogging site for "journalists" these days but come on. Talking about privacy and misleading information on the same site that makes you jump through hoops to remain anonymous while browsing? Pot calling the kettle black much.
[0] https://en.wikipedia.org/wiki/Spanish_profanity#References_t...
Just not sure the point in alleging that the publication (or investigation?) somehow took a lot of guts or whatever.
Forbes isn't installing tracking software on every site you visit. They're monetizing to the nth degree visitors to the own site. And if we want to do what-about-isms I just don't know how we have a conversation without starting at FB and Google.
Maybe I'm paranoid, but your comment strikes me as exactly the kind of thing I'd write if I was Xiaomi. Also I just don't think it helps the cause of privacy to discourage these kinds of investigations by any publication, regardless of their own track record.
At least they aren't peddling malware anymore.
https://www.engadget.com/2016-01-08-you-say-advertising-i-sa...
> Pot calling the kettle black much.
Do you expect any better from authoritarian/authoritative sources? Welcome to the wonderful world of hypocrisy.
That being said Google, Apple and other American companies collect your information too, maybe not as bad, just maybe.
We really need good free and open source OS options for smart phones. Like the GNU/Linux options available on desktops.
Can you point to examples of Apple collecting your browsing behavior or other similar data?
If not, which mobile is ideal?
Yes
Yes, and unequivocally so. Apple is not know to track browsing behavior, search terms, etc. Most of the data that your phone collects about you either remains in your phone (that’s why they’ve been shipping with NPUs for several years - they do A lot of machine learning in device rather than in-cloud) or is analyzed using differential privacy mechanisms.
The amount of data that Apple refuses to collect in Apple Maps for example is astounding. Start and end points of any journey are not used for example. Your trip is broken up into a bunch of segments, and only the middle ones are analyzed for traffic pattern, and even then only after being anonymized.
And most of the details behind all of this are published in a well written and frequently updated privacy whitepapers.
So your post is kinda misleading when you leave these details out - it creates a false sense of safety.
(And before someone complains: Yes, Apple is infinitely better at privacy than Xiaomi. We still shouldn't hide privacy risks though.)
???
In what way does this benefit the user?
The horror!
So does one or more of: Google, Facebook, Samsung, Apple, Amazon
Is it? I never understood the reasoning. What makes you think Apple is better than Xiaomi/Samsung/Google/whatever?
Otherwise, I have yet to see any evidence or indication that Apple collects data in a manner similar to what’s described in this article.
- https://www.gsmarena.com/counterpoint_smartphone_sales_in_q1...
The draconian smartphone (as a a backdoor & tracking device) beloved by the intelligence officers are now an area of a bitter fight.
My own sense is android phones are MUCH less private and secure AND have much shorter useful lives.
Seems like they're mostly in the news for the exact opposite.
Edit: People asking for sources, go to Settings -> Diagnostics & Feedback. See the part where it says "Send ... info about websites you browse"? You might also be interested in the setting below it; when you enable it "Microsoft will collect samples of the content you type"[1].
It also says that "data items collected in Windows diagnostics are subject to change to give Microsoft flexibility to collect the data needed", so even if they aren't collecting that data today, they reserve the right to take whatever they want whenever they feel like it.
Only the things under "End-to-end encrypted data" are actually encrypted in a meaningful way - everything else just sits on servers that use disk encryption, but that fails to defend from 99% of realistic attack scenarios.
A lot of content - including photos (which I used to use to take pictures of sensitive personal data, like ID cards) - is not meaningfully encrypted.
Thankfully, Safari tab data is actually encrypted as of iOS 13.
While Apple has done a good job of protecting user privacy compared to the alternatives, they still have a lot of work to do before we can accurately say things like "iCloud backups are encrypted".