4 ms·
I've been trying to execute on this approach, as I'm very interested in checking out of the tracking-by-default ecosystems. We're using some Xiaomi devices we
by mdpm 6y ago
I've been trying to execute on this approach, as I'm very interested in checking out of the tracking-by-default ecosystems.
We're using some Xiaomi devices we purchased, and I'm currently seething. I can't root without 'unlocking', which is a process that requires me to activate a Mi Account, which then requires my email and a SIM (?!), and 'find my device' (location) to even allow installation of apps via USB. To unlock the computers I bought, so I can use the root account, to install an alternate.
Seems the prison walls are just set far enough away that we don't notice.
tl;dr, in order to get some privacy, I'm being asked to associate my IMEI, my IMSI, my email, and my location.
- asdfasgasdgasdg 6y agoThis situation won't change until these companies are legally required to change, or until they have an economic incentive to do so. If even people like yourself who are interested in rooting don't bother to research the issue before making a purchasing decision, I don't have high hopes for the economic path. So the question is whether there is a sufficiently interested political constituency to get a law passed.
- andysch 6y agoyea it's so annoying to unlock the bootloader on Mi phones.. Samsungs are less a pain
- mappu 6y agoThere was a massive wave of phones being sold with unlocked bootloaders with preinstalled malware. How do you stop this? Unscrupulous retailers would buy thousands of your latest phone, root it and sell it for $1 less than MSRP, and make much more than that from injecting extra ads and stealing data. Not to mention, all the bad press "you" get for "shipping a phone with ads in it". Mere tamper-evidence - having a "bootloader unlocked" warning on boot - isn't obvious enough for a new user who has just bought the phone for the first time. So all manufacturers have added time locks and anti-fraud detection for bootloader unlocking. The time lock in particular is the best way to cut down this effect during the early sales process after which time it's hard to catch up in review score. But a time lock can only be implemented securely via a remote server out of the user's hands. Xiaomi getting the telemetry is a cherry on top, but it's not originally nefarious - or at least - it's less nefarious than the problem it's intending to solve
- pbhjpbhj 6y agoHow about let adults wreck the phone they bought if they 'want' to. Bootloader unlock in a 'hidden' power-on menu is sufficient. If you really want to baby users just have this set a flag that requires a click box to be ticked on next boot in order to actually unlock it (eg "you selected to unlock your bootloader in the power-on menu; unlocking your bootloader may lead to you destroying your phone, do you want to continue?" "are you sure?" "pinky promise?"). The "we're protecting people from themselves" argument seems spurious.
- goatsi 6y ago>The "we're protecting people from themselves" argument seems spurious. Because it isn't the argument at all? The goal is to protect your reputation from having malware and ad laced versions of your latest hardware flooding the market (and hitting the news). Users are just a secondary concern.
- CountSessine 6y agoHis argument is that retailers are intercepting “the phone they bought” and preloading garbage on it and repackaging it before sending it to them. Maybe that’s something that happens a lot in China? If so, requiring registering on the Xiaomi website would be a pretty good way to thwart this. In a way, it’s to protect naive users. And it still allows you to root the phone - go through this idiocy once and then never worry about it again.
- DevopsTux 6y agoThe amount of data that is sent during the unlock process is absolutely ridiculous. Ever had an environment variable you don't want to share with Xiaomi, together with IP address, mail, phone number, geolocation, serial numbers, etc. ? Because all these gets sent. Unnecessary.
- rodgerd 6y agoYeah, Xiaomi seems like a terrible starting point if you're worried about surveillance.
- mdpm 6y agoI had the phones prior to the attempt (they're my previous handsets). Not wanting to buy fresh phones just to check feasibility. Sadly the choice just seems to be which nation-state-finance-intelligence cluster you want to feed your data to.
- ommz 6y agoXiaomi phones and their apps especially the freaking weather app are routine offenders on my firewall. I use NoRoot Firewall (beta version), that runs a local VPN, to whitelist connections and man, it's horrifying. I've enabled the "Always on VPN" and "Block connections without VPN" settings (Android 10) so NOTHING goes out unless through the firewall
- nasduia 6y agoYou should be able to disble those apps for your user with adb without root: adb shell pm uninstall -k --user 0 com.[miui,android,xiaomi].<appname> Have you investigated if xiaomi.eu firmwares successfully curtail those connections?
- JeremyNT 6y agoIf you're serious about this approach, the best option is (ironically I guess) just buying a Pixel device directly from Google. They tend to be well supported by third party ROMs and are easy to root or flash. You can also grab a used device with a confirmed unlocked bootloader. You usually have to ask a seller, and some won't know the answer, but you can provide the steps for them to determine this.