11 ms·
Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for
by goodells 6y ago
Related to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go.
Well, on cursory examination, the Aqara/Xiaomi hub was talking to a bunch of Chinese servers constantly. I didn't dive too deep into what all they were actually for. When I blocked the device from phoning home with my router, all the connected devices stopped working! None of the buttons or sensors would work, the RGB light on the hub couldn't even be changed. As soon as it lost the ability to ping its servers in China, the thing actually started strobe light flashing blue. Re-enable the outside network access on it, starts working again. This was totally antithetical to why I use HomeKit in the first place, so I removed the hub and paired all the Aqara accessories with a generic open source Zigbee hub (ConBee II) and added it to HomeKit with HomeBridge.
In the future I plan to give brands more scrutiny before investing time/money in them and granting them unfettered access to my LAN...
- bombcar 6y agoIt’s absolutely infuriating how many IoT devices round trip to the cloud for no good reason at all.
- baybal2 6y agoThe thing is, they really don't. They just stop working after few minutes of no connectivity. No real roundtrip happening.
- helloworld11 6y agoNot quite for no good reason at all. For someone else who programmed them to do this, it is for a very self-servingly good reason of data vacuuming obsession, it just happens to be no good reason for the customer.
- nialv7 6y ago> The devices require a wi-fi connected hub, not too strange for things that use Zigbee Wait, why would Zigbee devices require Wi-Fi connection? That would be a red flag for me, I would have avoided products like this.
- Yaggo 6y agoThey don't. You can use Aqara-branded zigbee devices just fine with Home Assistant (open source), no propietary cloud services required. With most manufacturer's own hubs it's a whole different story, basically they all talk to their cloud, that's how they are designed. I can see why, that's the easiest option for average consumer, plug & play. https://www.home-assistant.io/integrations/xiaomi_aqara/ https://www.home-assistant.io/integrations/xiaomi_aqara/
- deleted 6y ago[deleted]
- tirpen 6y agoUsually so you can control the devices from your smartphone. Phone talks to hub over local wi-fi, hub talks to devices over Zigbee. They might have a web interface where you can program schedules for the lights, define "scenes" and such. So it's not entirely pointless. There is however no reason why the hub should have internet access though.
- allyant 6y agoI believe they are used to allow the users to control their devices outside the network.
- nyx_ 6y agoI use a couple of Aqara sensors to report temperature back to my Home Assistant instance via a HUSBZB-1 USB Zigbee dongle[0]. They work pretty well, although they report data pretty infrequently absent any large temperature swings, so not great for data-viz purposes. I'm not at all surprised the hub thing constantly chats with its family back in China, but a properly security-paranoid home automation aficionado wouldn't be caught dead giving some proprietary black box power and network inside their own home. [0] https://shop.homeseer.com/products/nortek-usb-zigbee-zwave-interface https://shop.homeseer.com/products/nortek-usb-zigbee-zwave-i...
- methodsignature 6y ago> but a properly security-paranoid home automation aficionado wouldn't be caught dead giving some proprietary black box power and network inside their own home. That sounds like the definition of a cell phone.
- nyx_ 6y agoDon't even get me started. :( It gives me pangs of cognitive dissonance every time I use my Android phone to type up a rant about how creepy Google is. I'd love to walk the talk, but my impression is that FOSS Linux phones aren't really viable yet if you're interested in things like, you know, functional power management or a Bluetooth stack that actually works.
- kennu 6y agoI have a cheap air quality meter which basically connects to an MQTT broker server in China to transmit its readings constantly. The phone app connects to the same MQTT server, subscribes to a topic and receives the readings. I guess this is a very simple way to do it. Too bad the MQTT server has no authentication so you can actually subscribe to any topic. Many IoT solutions seem to be made by developers not very experienced in security.
- amenod 6y agoAre you saying you can actually read the air quality readings of other users? That's... quite an oversight. :-/
- Siira 6y agoFree big data for everyone.
- baybal2 6y agoThe whole of Internet will know when you spoil the air :P
- Foivos 6y agoI know that you are joking, but the data from an air quality monitor can reveal a lot of useful things, such as when somebody is at home.
- kennu 6y agoThe actual MQTT payload seemed to have some sort of custom encryption on it (not the usual MQTT-over-TLS). I didn't dig deep enough to find out how it works, but it didn't seem very sophisticated.
- bigphishy 6y agoHahaha holy shit
- gverrilla 6y agoCouldn't you just return the hardware to the store and receive payback where you live?
- txdv 6y agoI blocked all Chinese subnets because of the constant tries to log in to my servers. Obviously Xiaomi devices do not work in my network anymore.
- yurielt 6y agoHow also can you make a guide of how to do it?
- BelenusMordred 6y agoiptables -I INPUT -m geoip --src-cc CH -j DROP iptables -I OUTPUT -m geoip --src-cc CH -j DROP No guide needed.
- eznzt 6y agoCH is not China but Switzerland.
- zeepzeep 6y agoCN then?
- BelenusMordred 6y agoCorrect, I messed up the original country code.
- Siira 6y agoV2ray has the option to route based on geoip, but it creates a socks/http proxy, not a whole system solution.
- paulcarroty 6y ago> the Aqara/Xiaomi hub was talking to a bunch of Chinese servers constantly It's not only Xiaomi issue: many Chinese top and noname smartphones stealing user data and show ads inside their UIs. Cheap hardware & users data mining - great business model. The same with apps: https://www.vietnambreakingnews.com/2019/01/es-file-explorer-has-a-hidden-web-server-data-of-500-million-users-at-risk/ https://www.vietnambreakingnews.com/2019/01/es-file-explorer...
- jhvkjhk 6y agoThat’s why AI tech is much more advanced than any other Computing subjects in China, they get massive free data to train their networks.
- melomal 6y ago> was talking to a bunch of Chinese servers constantly Out of curiosity do you want Chinese companies to use US servers? Or where would servers be ideally placed for a Chinese brand to be accepted? I genuinely am curious to know.
- dylan604 6y agoIs this a serious question? How about don't contact any external server unless the user clicks an update button (or possibly on a schedule time the user has specifically allowed). After that, there is no legit reason for a device sensing the temperature in my home, a light switch, an electrical plug to ever call "home" about how it is being used. Maybe, just maybe, if the device detects that it is failing or other serious errors that might be okay, but if and ONLY if the user has specifically allowed that to happen. I don't care if the server is located in the US, China, Timbuktu, or Atlantis, and I don't care if the company is based in the US, China, or Martian. Just don't do it.
- pferdone 6y agoI think you're both on the same page here, but (and I'm also guessing here) I think OP implies there's a certain bias when it comes to chinese servers. And I too have this feeling, that if it's a server in the "western world" not a lot of people would bat an eye. But if it's a chinese or russian server, now that's something "we don't want".
- melomal 6y agoThis is what I am trying to figure out. I have a UK focused website therefore I use UK based servers, US focused website I use US based servers. Aren't most processing chips/hardware made in China for all major western tech companies anyway? I get the RU/China server suspiciousness but as far as I can tell, US unicorns are up to the same tricks and openly/brazenly pillaging data without any threat or fear.
- buran77 6y ago
- ornornor 6y agoI use some xiaomi connected lamps. First thing I did was connect them to home assistant via a dedicated VLAN that has no internet access. I see pages and pages of denied connections in the firewall from the smart lamps. They work with HA just fine, I just wonder what they’re trying to do with these servers. This is pure speculation but I’m convinced that all these smart devices from China are the largest state sponsored Trojan horse program in history. They’re probably not interested in you and me but since everyone and their dog has these devices, it’s possible to access and infiltrate any given high value target with these. No one even knows what’s in the firmware. I have no illusions other countries are doing the same, but none have the reach that Chinese branded electronics do. Bar google maybe.
- dvfjsdhgfv 6y agoI was thinking the same. The Mi ecosystem seems nice, has good reviews, and is relatively inexpensive. You can control everything from one app and they make things easy for you. Among many appliances they also have inexpensive IP cameras. When you think about it, it's really scary. They have all possible sensors and several actuators. With time, it may get much worse.
- nextos 6y agoI love some of their non-smart devices that can't spy me. For example, their Mijia precision screwdrivers are exceptionally good quality (Wiha heads) and the price is fair. Their phones running Android One are also fine and can be reflashed. But the rest of the items are quite shady. I have sniffed on the network traffic some devices generate and it's quite scary. The same thing applies to other Chinese industrial equipment. For example, I know some labs put BGI sequencers inside airgapped subnetworks because of industrial espionage fears.
- madacol 6y agoHow do you reflash those androids?, It's been hard for me trying to find a trustworthy ROM for an Mi A2 Lite
- 6y ago
- sampo 6y ago> temp/humidity sensors If you're into writing your own code, https://ruuvi.com/ https://ruuvi.com/ has bluetooth low energy sensors that transmit temperature/humidity/air pressure/3d-acceleration data with an open protocol, also their firmware is open source. They have a mobile app that displays readings from sensors, but for anything else you'd need to set up your own data logging or home automation server.
- La1n 6y agoI can also recommend ESPhome, it supports many sensors and runs on basically anything with a ESP32 or 8266. It's open source and super easy to integrate with home assistant. edit: and -> a
- cavendish3313 6y agoXiaomi did one thing wrong: It is a Chinese brand.
- deepstack 6y agothe company is also doing some sketchy things in the smart home space under their brand "Aqara" The whole idea of connecting everything to the internet is getting out of hand. 1. Internet and digital infrastructure has no integrity as how it is currently. 2. Anything for home, machinery, all should work when there is NO internet connection. Just like an app should work (to some extend) in airplane mode. It really comes down to the idea of data/device sovereignty. Is this my device or not? If I need to ping some place in China to get this working. Then make it clear on your front page that it is is a lease.
- mcv 6y agoThe only company I would trust with home automation at this point is IKEA. They're the only ones doing this who are actually in the business of making their customers' homes nice, rather than collecting and monetizing their customers' data. (And now I'm half expecting someone to respond that IKEA also collects our data. I don't know if they do, and I'd expect them not to, but I'd really like to know if they do.)
- amelius 6y agoIt's a company. With shareholders. Even if you can trust them now, that's no guarantee for the future. Trusting companies is just silly.
- conjectures 6y agoI realise this is an opinion du jour around here now, but it's a pretty paranoid take on the market economy. I trust that if I buy a can of coke, it will contain coke because coke want to keep selling me coke. They don't need to be good people, they just have to care about making money in the future. The fact that I think they care about that is why I can trust that the can of coke in fact contains coke with high probability.
- amelius 6y ago> I trust that if I buy a can of coke, it will contain coke because coke want to keep selling me coke. Perhaps but if the company could sell you more coke by having your personal data, it would be silly to assume they would not explore that route.
- riston 6y agoAbout the smart home space, there is also Home Assistant which basically provides all the tools to keep everything isolated from internet.
- jwr 6y agoMy Xiaomi devices (air purifiers) are on a different network, which I created specifically for sketchy "IoT" devices. It is physically separated, with separate addressing, and connected only at the exit router, where it is firewalled from the rest of my network. It doesn't mean Xiaomi doesn't learn everything about my air quality, temperature and humidity, but it at least decreases the attack surface.
- mensetmanusman 6y agoAmazon should be fined for selling IoT devices that do this. It is likely a threat to America’s infrastructure. Imagine if China could stop all smart homes from working if a politician said something about concentration camps. Do you think the average american cares more about their garage door opener working or the camps?
- ericd 6y agoDoes anyone know of any good resources on how to kit out a home with sensors that speak strictly locally/have no cloud connectivity? Is the answer just to find zigbee-only gear?
- CountSessine 6y agoReally, it’s probably just telemetry data. It’s probably for QA and maybe even follow-up sales. Not that that is at all ok - it’s really not. But China is a country where there’s no concept of privacy - when companies are actually required to keep tabs on their customers and report data back to the state on a regular basis without legal oversight from an independent judiciary, the notion that the company isn’t entitled to peek in on you must be an alien idea.