65 ms·
Lithuania says throw away Chinese phones due to censorship concerns
- amiga-workbench 5y agoI think you would have to be mad to leave the stock ROM running on a Xiaomi phone, IIRC they were caught logging peoples browser history a few years ago. Several models have mainline LineageOS support, I'm running Lineage on my Mix 2S and hope to have years worth of updates going forward. The hardware is really good value as long as you install an non-tainted OS.
- pier25 5y agoWhat about Android One?
- amiga-workbench 5y agoI believe Xiaomi left the Android One program last year.
- pier25 5y agoYes but there are plenty of Mi A1, A2, and A3 in use today.
- kspacewalk2 5y agoAndroid One is moribund and is basically just Nokia now[0]. [0] https://en.wikipedia.org/wiki/Android_One#2020 https://en.wikipedia.org/wiki/Android_One#2020
- alias_neo 5y ago> moribund 1. Approaching death, about to die. 2. Reaching obsolescence. I learned a new word today, thank you.
- EveYoung 5y agoNot to sound paranoid, but won't even LinageOS phones have to run closed-sourced firmware and drivers?
- amiga-workbench 5y agoCorrect, its entirely possible they could be doing more insidious stuff at the firmware level, but dumb keyword checking is almost certainly implemented in userspace. I don't think you can trust any proprietary firmware out there, its just a question of which you trust less than the others.
- halfstar91 5y agoAnd based on recent discoveries it sounds like Xiaomi should be trusted less than others.
- hef19898 5y agoAs stupid as it might sound, I do trust Pixel phones, and an hypothetical iPhone running a different OS, the most of all alternatives. If one want's a smartphone, if not just take a 20+ year old dumb phone. Or BlackBerry.
- summm 5y agoNot only firmware. Custom ROMs actually have to use binary blobs in kernelspace and userspace as well, in order to be able to use the hardware.
- DanAtC 5y agoYou can replace the user-facing software, but can/would you trust the baseband?
- sudosysgen 5y agoIsn't the baseband Qualcomm code? Do you think Qualcomm allowed Xiaomi to run their own baseband on it?
- nottorp 5y agoDo you think a Chinese company would even ask for permission? :)
- sudosysgen 5y agoYou can't exactly do it without permission though. You need to crack the bootloader for the baseband and that's way easier said than done and immediately noticeable.
- mschuster91 5y ago> You need to crack the bootloader for the baseband and that's way easier said than done There have been more than enough cases of people poking holes in bootloaders, including secret services. For what it's worth, Huawei and Xiaomi can be considered as part of the Chinese CCP dictatorship and I'd expect them to have access to such exploits. > and immediately noticeable. How is an user supposed to notice a modified baseband firmware? The only thing that a user can see is if the device has been rooted, but with a factory-supplied backdoor even that doesn't help.
- sudosysgen 5y agoThere's a difference between poking a hole the device bootloader and the baseband bootloader. The second is wayyy more lockdown and has a tiny attack surface. A user can directly download the baseband image from the chipset using for example QFIL. Then you can check if it's signed with Qualcomm's key or another. Exploiting this would require Xiaomi to hide two baseband firmwares in the baseband firmware which isn't feasible, and it would also require them to completely rewrite the baseband bootloader instead of just exploiting it. But even then you'd be able to read the eMMC and notice that there are two baseband firmwares. If you want to figure it out, you're free to buy any Xiaomi phone, read the eMMC, and check how many baseband images there are, then you'll be able to definitively know. Let me know if you do it. When I said immediately noticeable I meant by Qualcomm, not by the end user though. They have contractual obligations to lock down their baseband and their licensing system relies on it so they have a large incentive.
- gpderetta 5y agoI was stupid enough to buy a Xiaomi phone without enough due diligence. Aside from all spying that is going on, the software is abysmal. The problem with replacing the OS is that I believe most banking apps I use will stop working. Might just need to write this phone off.
- hxii 5y agoI have installed an AOSP-based rom on my Xiaomi 9T and banking apps (well, at least one) seems to be working fine.
- 5e92cb50239222b 5y agoDid you have any problems with AOSP? I want to replace the stock spyware on me mom's 9T, but the experience seems to be mixed, judging by a couple of forum discussions.
- hxii 5y agoMinor inconveniences mostly, but that's probably because I keep flashing different ROMs to try stuff out. My only "issue" is that because of my escapedes with flashing I now have only Widevine L3 support, so no full-HD videos on Netflix. But this should be easily fixed by flashing xiaomi.eu ROM and then going back to AOSP. This is my daily driver: https://forum.xda-developers.com/t/rom-11-0-official-davinci-crdroid-v7-x.4207823/ https://forum.xda-developers.com/t/rom-11-0-official-davinci...
- 5e92cb50239222b 5y agoCool, thank you.
- beerandt 5y agoBanking has to be the dumbest "security" industry there is. Restrict apps, but can still log in via browser. I have one bank app that actually says to screenshot a payment screen for your records, while blocking screenshots via app policy.
- dukeofdoom 5y agoMost people don't care if another country spies on them, since their laws don't apply to them. They would care much more if they are profiled by their own government. Or more like tech companies on behalf of the government spying on them, and them being discriminated, harassed, or jailed based on that data. So in a way its actually kind of smart to go with a Chinese phone if you live in America.
- zzzbra 5y agoGalaxy Brain take.
- deleted 5y ago[deleted]
- Causality1 5y agoGood value assuming you're on the right carrier. AT&T in the US and its MVNOs are moving to a whitelist model in February, making Xiaomi phones unusable for anyone in the US not on T-Mobile.
- selfhoster11 5y agoOn a related note, Realme recently bricked two (maybe more) phone models with an update that caused a soft-boot loop if the weather service (!) was removed by the user to reduce bloat. The problem is not fixed. People have lost data. I personally put Realme on my "never do business with" list. If their engineering is so poor that they haven't caught this in time, nor reacted by releasing a one-line software patch that can be applied manually (cause users sure as hell can't do it themselves - stock can only apply signed updates), they shouldn't be trusted with anything.
- EveYoung 5y agoWhat difference does it make to disable the censorship function compared to fully removing it from the code base? Considering that phone updates cannot be verified, every phone maker has the ability to secretly add such features at any time. And if the phone is link to a user account they could even do this in a targeted way.
- russli1993 5y agoThe thing is if these censorship is enabled, its going to be found out in a second by someone and explode in the news. All it does is that it deletes a word you typed on your phone or prevent you from seeing a piece of content that you want to see. It's going to be so obvious. It will not achieve the desired goal to censor in the first place and will make people realize what you don't want people to see. It will completely backfire. Given it is a broken and illogical plan, then it is highly unlikely there is a a multi year effort to build phones, sale to international markets, just to censor what people want to say and feed people about ccp propaganda. Even if someone is so stupid and want to do it anyway. What you fear is the censorship actually work. But you don't have to worry about that as it will not work.
- vanderZwan 5y agoI suppose this isn't important but I am really curious: in which languages? Also how did the Lithuanian government find out?
- reginold 5y agoIt seems like the keyword match is based on Chinese, based on the extract on page 23 of the report. Linked near the top of the thread, 32 pages of goodness: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysis_env3.pdf https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
- alliao 5y agoI wonder when it'd be accidentally turned on
- deleted 5y ago[deleted]
- throwaway4good 5y agoI would like to see concrete reproducible evidence for this.
- reginold 5y agoThe 35 page report has details that should make it easy to replicate. "This file contains a list composed of the titles, names and other information of various religious and political groups and social movements (at the time of the analysis, the MiAdBlacklistConfig file contained 449 elements). A fragment of the MiAdBlacklistConfig file is shown in Table 14." page 23 Linked elsewhere but here's the PDF report: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysis_env3.pdf https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
- fredgrott 5y agoHmm that is why that Huawie android fork flaw of running other mods as system allowed with hidden updates is screaming at me now. Its way to update that mod in real time without the user knowing about it as its system allowed due it running in a separate allowed system space.
- marcodiego 5y agoTime to pressure vendors to seek RYF certification.
- echelon 5y agoWe should be up in arms over this. But we should also be up in arms over Apple's "CSAM" plans. Surveillance doesn't belong on our devices. Period. Once it's in, the dictators can clamp down even harder. Over time, freedom atrophies and the window slides closer to totalitarian control. Don't invite the devil in. Scream it away.
- thebraxton 5y agoThere were multiple articles about apple's csm with discussions.
- echelon 5y agoAnd we should stop talking about it? That's what Apple and the intelligence orgs want.
- reginold 5y agoI'm totally up for talking about it, what more can we talk about tho? I'm switching vendors and advocating for open sw/hw. Open to more threads!
- marderfarker2 5y agoI don’t see Lithuania writing a report or making a fuss about it. Weird.
- adventured 5y agoNo, someone a lot more powerful did: "Member of the German parliament, Manuel Höferlin, who serves as the chairman of the Digital Agenda committee in Germany, has penned a letter to Apple CEO Tim Cook, pleading Apple to abandon its plan to scan iPhone users' photo libraries" https://www.macrumors.com/2021/08/18/german-politician-letter-tim-cook-csam-scanning/ https://www.macrumors.com/2021/08/18/german-politician-lette... https://appleinsider.com/articles/21/08/17/germany-writes-to-tim-cook-to-reconsider-csam-plans https://appleinsider.com/articles/21/08/17/germany-writes-to... Along with "Apple photo-scanning plan faces global backlash from 90 rights groups" https://arstechnica.com/tech-policy/2021/08/apple-photo-scanning-plan-faces-global-backlash-from-90-rights-groups/ https://arstechnica.com/tech-policy/2021/08/apple-photo-scan... And 487 other articles, reports, fusses that went against Apple's plans.
- gowld 5y agoPlease don't submit tweets that are just links to news articles. Here's the official report: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysis_env3.pdf https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
- ChemSpider 5y agoThanks. I used the tweet due to the paywall of the Reuters article. But this original source is of course much better.
- mzs 5y agoThanks, there was also this discussion earlier this morning which linked there as well: https://news.ycombinator.com/item?id=28613703 https://news.ycombinator.com/item?id=28613703
- jaywalk 5y agoWhy is this linked to some random tweet that adds absolutely nothing instead of the article the tweet links to? https://www.reuters.com/business/media-telecom/lithuania-says-throw-away-chinese-phones-due-censorship-concerns-2021-09-21/ https://www.reuters.com/business/media-telecom/lithuania-say...
- ChemSpider 5y agoI used the tweet due to the paywall of the Reuters article. Another user below found the best link, the true original source: Here's the official report: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysis_env3.pdf https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi... (link updated)
- jaywalk 5y agoSince when has Reuters employed a paywall? I know they had planned on implementing one earlier this year, but that was indefinitely postponed.
- ChemSpider 5y agoAh, it says "Register for Free". So not really a paywall, my mistake.
- nottorp 5y agoYou pay with your personal data :)
- aasasd 5y agoWell, I for one can't read the article other than in the private mode, because the site says it's time to register.
- aembleton 5y agoBypass it by blocking arcpublishing.com in uBO, hosts or DNS
- sorenjan 5y agoFree Tibet. I just typed that on my Xiaomi with stock MIUI, using Google Gboard.
- wavefunction 5y agoI don't think there were allegations that you couldn't type Free Tibet?
- avodonosov 5y agoWhat exactly are the allegations then? "have a built-in ability to detect and censor terms such as "Free Tibet" Censor by preventing one posting the phrase? Removing the phrase from web pages? What are the steps to reproduce?
- tyingq 5y agoThe allegation is that the censorship code is there. It's disabled on phones in western markets, but can be enabled remotely by the manufacturer.
- oblak 5y agoSo, it's better than US made spyware which cannot be removed from "our" PC CPUs? Best we can do is "disable" these features in the BIOS/UEFI and sleep well, even though we nothing's really stopped. Sorry for the whataboutism but I am lot less concerned about Chinese spyware because I know for a fact that my government serves the EU and the US. All this anti China propaganda is really tiresome. China this, China that. Someone seems really scared. Fuck this someone
- trasz 5y agoAs you can see, one gets downvoted quickly when pointing out double standards, or posting anything else that could interfere with anti-Chinese propaganda efforts.
- 1MachineElf 5y agoThey say the Apple doesn't fall far from the tree...
- marcellus23 5y agoHuh?
- fortuna86 5y agoSloppy attempt at Whataboutism
- kburman 5y ago> "Our recommendation is to not buy new Chinese phones, and to get rid of those already purchased as fast as reasonably possible," Defence Deputy Minister Margiris Abukevicius told reporters in introducing the report. This is applicable equally for every other country.
- Koshkin 5y agoXiaoyu for doing stuff like this.
- ph2082 5y agoWhat happens when you type - Winnie the pooh ?
- thinkingemote 5y agoWhilst the loveable bear was somewhat banned online for a little time a while ago, it's now not actually banned in China in itself and is and has been a popular children's toy. Disney stores also exist and sell winne the pooh in China. What's more accurate is the use of the bear with reference to their leader (who looks like him!) A better string would be "tianamen square massacre"
- zolosa 5y agoFrom the article: Relations between Lithuania and China have soured recently. China demanded last month that Lithuania withdraw its ambassador in Beijing and said it would recall its envoy to Vilnius after Taiwan announced that its mission in Lithuania would be called the Taiwanese Representative Office No one trust China but this sure looks like politically motivated. Was someone else able to authenticate or reproduce the results.
- fortuna86 5y agoYes the context is Lithuania dared state the obvious fact that Taiwan is a country, and now they are paying the price.
- no_way 5y agoYou can read the report and literally look up file on your Xiaomi phone which contains censored words.
- trasz 5y agoMost people don't have Xiaomi phones. And it's worth noting that the document only mentions some of those, from over 300 entries. What are the others and why were they redacted out?
- oseityphelysiol 5y agoThet are very common in Lithuania, to the point where I’d say around 20% of new phones being sold are from Xiaomi. They expanded heavily into other industries, like home automation, with prices that are a fraction of what other manufacturers would ask for their hardware.
- no_way 5y agoI am not sure how accurate this information is but quick google search says Xiaomi have 24% phone market share in EU, not just Lithuania.
- ignoramous 5y agoThere are no details really as to how Xiaomi censors those terms. If one does not use the bundled-in browser / app-store, I doubt Xiaomi can censor anything at all in other browsers unless they MiTM with client-cert. OTOH, many popular non-browser apps (at least the ones that matter) pin certificates, so even Lenovo-esque shenanigans wouldn't work [0]. What can they possibly be doing in the firmware or the ROM to break TLS (and other such authenticated key-exchange protocols)? The only thing I think of: Injecting a compromised https stack in to an app's classpath / ld_library_path. This may sound ambitious, but the Android modding community already uses such runtime swappers to great affect [1][2]. [0] https://news.ycombinator.com/item?id=9072424 https://news.ycombinator.com/item?id=9072424 [1] https://forum.xda-developers.com/f/magisk.5903/ https://forum.xda-developers.com/f/magisk.5903/ [2] https://forum.xda-developers.com/f/xposed-general.3094/ https://forum.xda-developers.com/f/xposed-general.3094/
- bitcurious 5y agoOff the top of my head, theu can censor at the keyboard level, at the SMS level, and at the camera level: https://www.reddit.com/r/Xiaomi/comments/pgk8y3/xiaomi_camera_censoring_german_postal_voting/ https://www.reddit.com/r/Xiaomi/comments/pgk8y3/xiaomi_camer...
- ignoramous 5y agoYikes, yes: The Input Methods are totally under their (ROM's) control even if one uses a non-Xiaomi keyboard.
- 2Gkashmiri 5y agoFree tibet", long live Taiwan independence", or "democracy movement". i sent this to a friend who owns a xiaomi phone and asked him to resent this back to me via sms. the message appeared just fine. note: i am from india so this might not be enabled on the phones here for now
- mekster 5y agoIt may appear fine but your friend may be logged.
- mytailorisrich 5y agoThanks to those who posted a link to the actual report [1] It may be worth clarifying that all those keywords and terms are in Chinese. So when they say "Free Tibet" they mean that the phone has a blacklist file that contains "西藏自由" and which use is disabled in the "European region". On the other hand, it seems that this blacklist file is actually downloaded into the phone, which suggests to me that they could update it to match any terms in any language if they wanted. I think that Chinese manufacturers will really need to produce 'clean' firmware that satisfies independent audits instead of these superficial feature flags if they want to continue to sell in the West long term. If not they will suffer Huawei's fate one after the other when this sort of thing is found out. [1] https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysis_env3.pdf https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
- nottorp 5y ago> which suggests to me that they could update it to match any terms in any language if they wanted. About the same thing as Apple scanning iPhones for what they say is child porn. suggests to me they could update it to match any images if they wanted...
- hef19898 5y agoPretty much the same thing, if you ask me.
- tasubotadas 5y agoAre there any good non-Chinese smartphone besides Samsung? Preferably someone who delivers a stock android?
- fortuna86 5y agoNew Pixel ?
- deleted 5y ago[deleted]
- tmoravec 5y agoiPhone?
- mrweasel 5y agoDepending on your definition that’s also a Chinese phone. You might be able to get one build in India, but that require a lot of effort. The problem is that you’re more or less screwed if you trust neither China nor Google. Generally speaking the iPhone is your best option, but partly due to a lack of options.
- karolist 5y agoJust buy Pixel phones, the pure Android experience and day 1 updates are worth it. The new Pixel 6 will use LTS kernel and custom SoC, rumored to have updates for 5 years instead of what was a standard of 3.
- deleted 5y ago[deleted]
- HanaShiratori 5y agoPixel with GrapheneOS
- vvatermelone 5y agoAnd if GrapheneOS is too hardcore for you, CalyxOS
- lmilcin 5y agoI wonder why is anybody still surprised. China has no qualms invading privacy of anybody. They will try any and every way to get whatever they need and they are pretty effective at it. Ever read about making business in China? What we call cheating or stealing is a standard business practice there. If you point it out they will back off and try somewhere else, ad nauseam. It is practically part of Chinese culture and upbringing. Why do you think "chinese" is practically synonym to "cheap and most likely defective"? Just say no to Chinese phones and TVs and internet services, because you WILL be exploited. It is not a question if but rather when and whether you will or will not know about it.
- gaoshan 5y agoWestern companies and business people have been remarkably myopic over the last few decades when it comes to the reality of doing business in China. The parent comment here is exactly right... this person knows what they are talking about yet somehow companies in the West seem to persist in trying to make a go of it. They almost all eventually learn their lesson but it doesn't have to be this way. This is not new info or new behavior.
- rualca 5y ago> I wonder why is anybody still surprised. This is the kind of claim that's deep in conspiracy theory territory until the smoking gun is uncovered, and once that's out (and only then) it becomes obvious and unsurprising.
- lmilcin 5y agoNo, it is not and has not been surprising for decades. In China there are no private companies. There are only companies that Chinese government lets you run as long as you cooperate with the government.
- vnchr 5y agoEven Jack Ma was put through the wringer after questioning the CCP publicly.
- reginold 5y agoWhat's "decomposition analysis" and how can I do it at home? Since others here are curious, how would one go replicating these results to find the MiAdBlacklistConfig file? Can I download the OS from a website and just search for strings in the MiAdBlacklistConfig file? I'm genuinely interested, rather than using this question to cast doubt on the 32 page research report.
- throwaway4good 5y agoI am curious about this too. From what I can gather from the report it should be possible to reproduce the analysis. Probably it is even possible to run the apps in question in an emulator. Also it should be possible to get the full url of the censorship configuation file and also its full contents. Given the extreme politics around this, I think it would be better if this type of analysis was done as open source and in a completely reproducible manner.
- bitcurious 5y agohttps://www.reddit.com/r/Xiaomi/comments/pgk8y3/xiaomi_camera_censoring_german_postal_voting/ https://www.reddit.com/r/Xiaomi/comments/pgk8y3/xiaomi_camer... Related, in this thread the OP discovered that he couldn’t take photos of an election ballot - they were being overwritten with a big green block.
- reginold 5y agoNo, the OP in the thread later retracted as they could not replicate and it seemed more like a random bug in the camera: "Yesterday I was a bit in a hurry and could not do all tests that I would have liked to. Today I tried to repeat the whole process with the same setup, documents still laying on the same table untouched etc. Just the lighting changed substantially (morning sun). I was unable to repeat the 'green picture effect' even once... all pictures taking with Xiaomi stock camera turned out well. I am sorry that I jumped to unproven conclusions (censoring) :( " Please read your full source in the future before posting. It clouds the discussion. (I just did this myself on another article)
- mvolfik 5y agothis turned out to not be true - the comments pointed out that the overwrite is likely an app interpreting it as different image format, which had happened before, and OP didn't replicate the issue the next day in different light
- chenster 5y agoI'm keeping an eye on this while waiting for breaking from more prominent news sources.
- jszymborski 5y agoWhy recommend against them and simply not ban the sale of Xiaomi and co. in Lithuania?
- EMM_386 5y agoI just helped someone remove the built-in Chinese malware from a US Government provided phone. It's insane. https://blog.malwarebytes.com/android/2020/07/we-found-yet-another-phone-with-pre-installed-malware-via-the-lifeline-assistance-program/ https://blog.malwarebytes.com/android/2020/07/we-found-yet-a...
- deleted 5y ago[deleted]
- reginold 5y agoWow thanks for all that you do and blogging about this. HN discussion here: https://news.ycombinator.com/item?id=28499918 https://news.ycombinator.com/item?id=28499918
- titzer 5y agoThis is what kinda terrifies me about today's digital landscape. Now it's so cheap to hide surveillance capabilities (spyware, hidden microphones or cameras) that bad actors can just embed surveillance into every cheap device, hoping just by sheer numbers to get one into a sensitive area (e.g. Pentagon, Langley), and then remotely activate surveillance. With the computational capabilities of today's data centers, they don't even have to be all that selective anymore. They could just be monitoring everyone, at some granularity, dumping logs into a massive database with just enough metadata to make it searchable/queryable. It's downright dystopian.
- EMM_386 5y ago> It's downright dystopian. It sure is. No stopping it now though. I'm old enough to remember being able to go to someone's place and expect privacy. These days literally anything can have an HD cam. Not great for paranoia but what can you do? > They could just be monitoring everyone, They are. Snowden already proved this, and we apparently got into that particular situation to keep pace with China. Not my job.
- reginold 5y ago
- fnord77 5y agoif one company is doing it, they're all doing it. From the snowden leaks we know the NSA puts their own firmware into enterprise hardware. One should assume that they're in american consumer hardware firmware as well
- marderfarker2 5y agoI know right? This post and the report it links reeks of political motive.
- mlang23 5y agoI wonder how long it will take until $RANDOMCOUNTRY says the same thing about US phones.
- coolspot 5y agoThere are no mass-produced US phones. Hand-made boutique Purism US-edition doesn’t count.
- marderfarker2 5y agoTechnically all phones today have parts sourced or designed in the US. I do not understand how and why HN has such a hate boner for China. What China does today has been done ad nauseum by the US. China is merely following its footsteps.
- mlang23 5y agoOh, right, I totally forgot that Apple and Google are chinese companies, my bad.
- 2Gkashmiri 5y agopfff... this is nothing. the government simply stop you on the roadside, demand you unlock your phone and if they find any vpn, or god forbid any "anti national content", beat you to a pulp and then charge you for terrorism. state sponsored mobile surveillance is too far away. edit: the downvoters think i am just bluffing? https://thekashmirwalla.com/not-pegasus-kashmiris-are-worried-about-next-checkpoint/ https://thekashmirwalla.com/not-pegasus-kashmiris-are-worrie...
- netcan 5y ago"Censorship" is part of a whole here, and it's not obvious what to call that whole. This is a complex of censorship, data gathering, personalization and such. A few months ago microsoft accidentally turned on some china settings globally, and "tank man" disappeared from search results. Tank man is conspicuous, I wonder what less conspicuous switches can be flipped. The main arteries of media & communication are strategic assets. These responsible for near 100% of Alphabet & FB's revenue. Ad businesses, app stores, etc. Google pay Apple more revenue for search defaults than MSFT earn in gross from their "2nd place in the market" position. Google pay OEMs and telecoms to be their default app stores. The complex is all about bottlenecks, Control over these is the financial asset behind several of the world's most profitable companies. It is a primary intelligence target/asset. It's a major part of china's information/narrative control mechanism... has been for a while. The thing that's changing is that china's mass is starting to cause tides elsewhere. This game is a "ring of power" game.
- MarkusWandel 5y agoThis may be kind of a dumb question, but what exactly is a "Chinese phone" and what is not? Is my current "Moto" branded phone (Lenovo) in the same boat and if not, why not?
- deleted 5y ago[deleted]
- reducesuffering 5y agoYes, Lenovo is a Chinese manufacturer
- game_the0ry 5y agoI'm really not sure how serious I should take the threat of Chinese made electronics - almost all electronics are made China, not just Xaiomi and Hauwei. My iphone is made in China by Chinese contract manufacturer (Foxconn) - does that mean all iphones could be compromised with Chinese malware? It could be possible, but how can you tell? Is it possible to observe network packets going form my phone to a Chinese or Chinese-allied country? Genuinely curious, btw. Any feedback would be very appreciated.
- eloisius 5y agoJust a nit because you’re mostly right, but Foxconn is a Taiwanese company that does its manufacturing in China.
- game_the0ry 5y agoFair nit, my friend. I did not know that.
- reginold 5y agoAs far as I can tell, the meta solution here is open source hardware and software. Otherwise it just doesn't matter who is doing this, why they do it, or who is affected. The core issue is the lack of end to end encryption and open source hardware and software. Options today are okay, but they need to be great to reach the right people. See my post in this thread about Pinephone and Librem.
- game_the0ry 5y ago> As far as I can tell, the meta solution here is open source hardware and software. Otherwise it just doesn't matter who is doing this, why they do it, or who is affected. I agree with you there, but I want to know how to analyze devices that are closed source.
- deleted 5y ago[deleted]
- 5y ago
- crhutchins 5y agoIsn't the better solution to this is to stop any activities relating to the Xiaomi phones?
- tjpnz 5y agoWhat would people suggest with regards to IoT devices? I own a Xiaomi robotic vacuum for instance. I've taken the usual step of putting it on a segregated IoT network but it's also got a builtin camera.
- AdrianB1 5y agoNot trying to be a jerk, but the S in IoT comes from Security. I work in an area where IoT is the top buzzword of the past 3-4 years, I have nothing in my house and so far nothing in my work area of influence. I have a "smart" Chinese air conditioning unit with WiFi disabled and a "smart" Samsung TV with Ethernet not connected, not because I am paranoid but because I am old enough to have some life experience.
- dehrmann 5y agoApple's getting remarkably close to the same place with its (on-hold) system for scanning for CSAM. It could be adapted for political censorship and "turned on remotely at any time."
- belter 5y agoFrom the shared PDF page 23... "It has been established that during the initialisation of the system applications factory-installed on a Xiaomi Mi 10T device, these applications contact a server in Singapore at the address globalapi.ad.xiaomi.com (IP address 47.241.69.153) and download the JSON file MiAdBlacklistConfig, and save this file in the metadata catalogues of the applications. A list of applications for which the MiAdBlacklistConfig file was found in metadata catalogues is presented in Table 13." ... "Once the applications have downloaded the file, the download date is recorded in order to facilitate periodically updating the list. The scheme for downloading the MiAdBlacklistConfig file is shown in Figure 11." "This file contains a list composed of the titles, names and other information of various religious and political groups and social movements (at the time of the analysis, the MiAdBlacklistConfig file contained 449 elements). A fragment of the MiAdBlacklistConfig file is shown in Table 14." Extract from table 14.... =================================================== No.: Original - Approximate translation 1 "宗教虔信者阵线", “Front of religious believers”, ... 22 "西藏自由", “Free Tibet”, ... 60 "蒙古独立", “Independence of Mongolia”, 61 "89民运", “89 Democracy Movement”, 62 "基督灵恩布道团", “Christian charismatic mission”, ... 145 "伊斯兰联盟", “Islamic League”, ... 201 "民运", “Democratic Movement”, 202 "妇女委员会", “Women’s Committee”, 203 "伊斯兰马格里布基地组织", “Al-Qaida in the Islamic Maghreb”, 204 "人民报", “People’s daily newspaper”, 205 "巴勒斯坦解放组织", “The Organisation for the Liberation of Palestine”, =======================================================
- trasz 5y agoSo, what are the other entries, and why were they redacted out?
- belter 5y agoPDF is here: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysis_env3.pdf https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi... ...do you want me to post 449 items? :-)
- throwaway4good 5y agoThe PDF only have the selected entries. Does anyone have the contents or actual url of the full file?
- dvh 5y ago"Free Tibet", "Long live Taiwan independence" or "democracy movement". Sent from my Xiaomi, let's see if it works. Anyway, I always thought if I have to use American phone backdoored by FBI or Chinese phone backdoored by China, I choose Chinese because they really cannot arrest me, unlike FBI.
- bassman9000 5y agoWhat can you send from your phone that will get you arrested by the FBI, vs what can get you arrested by Chinese forces? Is this a valid comparison?
- dvh 5y agoNice try!
- bassman9000 5y agoYou could always link some news article on the FBI abuses. But you also have a gmail address, so I don't understand the reaction.
- adolph 5y agoHaving a gmail address is important to not stick out. https://www.itstactical.com/intellicom/mindset/gray-man-strategies-101-peeling-away-the-thin-veneer-of-society/ https://www.itstactical.com/intellicom/mindset/gray-man-stra...
- bassman9000 5y agoIf you don't use it for anything interesting, you're sticking out even more. A void can be as revealing. If you're using it for something interesting, well, you're not sticking out in the "not having gmail" camp, but what's the point.
- 5y ago
- everdrive 5y agoIt's unfortunate that it's hosted in Singapore. I do a lot of geo-blocking on my router, and I often wonder to what degree it helps me at all.
- Scoundreller 5y agoCanada has unofficially banned the sale of theirdevices, or at least that’s why eBay said the Canadian government told them to not allow their sale. Though eBay.ca just blocked any listing containing the word “xiaomi”, though they make a ton of things that aren’t phones. I just took out xiaomi and left the model number and sold my thing. Still waiting for my government to respond to my request to find out why.
- sudosysgen 5y agoXiaomi devices are not and never were certified for use in Canada.
- Scoundreller 5y agoDoesn’t usually result in the government requesting a stop-sale on eBay. Happened on newegg too: (Amp link because Reddit is actually down) https://www.google.com/amp/s/amp.reddit.com/r/Xiaomi/comments/e763fi/redmi_note_7_not_certified_in_compliance_with/ https://www.google.com/amp/s/amp.reddit.com/r/Xiaomi/comment... Though you can still roam in Canada with them, so I don’t know how that works. Shouldn’t base stations reject uncertified device IMEIs? I guess it’s all okay as long as there’s revenue to be had.
- sudosysgen 5y agoIt can if a competitor complains. I don't know of any devices at all that get rejected on Canadian ISPs. Blocking Xiaomis would cause a lot of issues.
- Scoundreller 5y agoJust seemed strange that the radio-frequency regulator would demand that 3rd-party selling platforms stop transactions but not also demand ISPs to de-auth them too. Just suggests that the restrict them are BS or maybe spyware/intelligence related.
- nytgop77 5y agoworth noting, that blacklist filtering decompiled code looks this way (just one line; to show the naming) if (iNativeAd.getAdTitle() != null && m12161a(iNativeAd.getAdTitle(), str) If to believe the naming, it is filtering advertisements.
- throwaway4good 5y agoThat would be my interpretation as well - these non mangled names I guess they come from an api.
- deleted 5y ago[deleted]
- pulse7 5y agoThe blacklist is interesting, because it maybe shows China's government interests - some of which are not widely known: - "Independence of Mongolia" - Does this show they would like to acquire Mongolia (when the time will be appropriate)? - "The Organisation for the Liberation of Palestine" - Does this show pro-Israel support?
- miles 5y agoMongolia needs allies to withstand China's looming threat https://asia.nikkei.com/Opinion/Mongolia-needs-allies-to-withstand-China-s-looming-threat https://asia.nikkei.com/Opinion/Mongolia-needs-allies-to-wit... The implications of the rise of China's military for Mongolian security https://calhoun.nps.edu/handle/10945/5340 https://calhoun.nps.edu/handle/10945/5340 China accused of 'cultural genocide' in Inner Mongolia https://www.ucanews.com/news/china-accused-of-cultural-genocide-in-inner-mongolia/93698 https://www.ucanews.com/news/china-accused-of-cultural-genoc... China’s Crackdown on Mongolian Culture https://thediplomat.com/2020/09/chinas-crackdown-on-mongolian-culture/ https://thediplomat.com/2020/09/chinas-crackdown-on-mongolia...
- pphysch 5y ago"People's Daily newspaper" is a pretty big counterexample that everyone is conveniently ignoring.
- throwhehehe 5y agoThe common thread here is how Beijing is afraid from organized ethnic minority movements, religious movements and/or societies from the civil society that could have their own independent ideas. They are not that different from other Leninist inspired governments. Cuba does that. Vietnam does that. The Soviet Union certainly did that. These governments always lose their minds with the idea of people organizing themselves and the controlling party having no control whatsoever about these groups. I have no idea how the People's Daily plays into that. Maybe the readership is so small and it attracts a certain type of personality that Zhongnanhai thinks it is a good idea to report on them. I've read that the major clique in the CCP certainly wasn't happy about students calling themselves Maoists and supporting workers striking. I don't know much about China to say about that nor if the People's Daily has many people reading it.
- msegal 5y agoMotorola is also, now, a Chinese phone maker. Does it suffer from these same vulnerabilities?
- dylan604 5y agowell, for the 4 people left using a Moto, maybe??
- zibzab 5y agoI would love to see a similar analysis for Nokia phones (before they moved development from China to EU).
- MomoXenosaga 5y agoFew months ago I read Xiaomi is now bigger than Apple. The cynic in me says this is just part of American anti China warfare. And Lithuania is, how should I put it nicely, an American lapdog. Disclosure: yes this was typed on a Poco.
- neonate 5y agohttp://web.archive.org/web/20210922185730/https://www.reuters.com/business/media-telecom/lithuania-says-throw-away-chinese-phones-due-censorship-concerns-2021-09-21/ http://web.archive.org/web/20210922185730/https://www.reuter... https://archive.is/YgfUs https://archive.is/YgfUs
- dang 5y agopdf of the report being reported on: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysis_env3.pdf https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
- Aissen 5y agoAnyone know why OnePlus is mentioned ? The only reference seem to be a stupid CVE; I'm sure they have much worse bugs.
- yumraj 5y ago> The capability in Xiaomi's Mi 10T 5G phone software had been turned off for the "European Union region", but can be turned on remotely at any time, the Defence Ministry's National Cyber Security Centre said in the report. While a lot of comments are rightly focusing on the censorship aspect of it, IMHO, the most concerning part of this is that this intrusive capability, while disabled for the EU region can be remotely enabled at any time. This implies that Xiaomi, and most likely all Chinese phone vendors and by extension CCP, has backdoors in all these devices. This re-enabling is probably just the tip of the iceberg, wonder what all they can do via these backdoors?
- thefounder 5y ago>> This implies that Xiaomi, and most likely all Chinese phone vendors and by extension CCP, has backdoors in all these devices. They don't need backdoors. They are the "administrator" of your phone just like Apple is on iOS and MacOS or Microsoft on Windows boxes.You are just a guest. It just happens that the chinese admins(aka vendors) don't mind being nasty and clumsy at the same time. All the manufacturers/vendors are controlled by their government(more or less). That being said I don't buy chinese phones or software unless I have no choice but I don't trust Apple to shield my data from various governments either. It's just a matter of lesser evil.
- han2432 5y agoI think you will have a hard time proving beyond speculation that Apple or Microsoft has backdoors to their OS. Would be curious to see any sources though. I actually think that is the difference here, Chinese phones and possibly other devices have backdoors, but Apple/Microsoft likely do not.
- kelnos 5y agoI think the parent is being more expansive in what they call a "backdoor", and I tend to agree. Does Apple have the ability to remove an app or some bit of content off your phone (ostensibly to remove malware)? I believe they do? That feels like a backdoor to me. And I assume Google (and/or the phone's manufacturer) has the same ability on Android. No idea about Microsoft on Windows.
- qualudeheart 5y agoAnyone living in Lithuania or near it can probably get a lot of phones for cheap soon. You can distribute them to seniors and small children.
- sbakzbsmx 5y agoWhy should I care if the CCP have the theoretical ability to censor what I watch, when Twitter, FB and friends actively do? It seems I should be more concerned about the proximate threat.
- mensetmanusman 5y agoThis reminds me of those IoT lightbulbs that Amazon sells that will not function if you block them from connecting to Chinese servers.
- someperson 5y agoPrevious discussion: https://news.ycombinator.com/item?id=28613703 https://news.ycombinator.com/item?id=28613703
- sloshnmosh 5y agoFun fact.. The first 4 smartphones I ever owned all came with preinstalled malware or malware was added after a “security update”
- laravel92 5y agohttps://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysis_env3.pdf https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi... Whole report is worth a read, but page 22 is where this "censorship" is discussed. Given this is HN I think some of you would be interested in the technical specifics in order to give a proper, informed opinion here. The censorship involves blocking certain personalized ads within some of the core Xiao Mi apps by filtering political keywords. The keywords are all in mandarin, so ads that would be blocked would be Chinese ads. The list of keywords seems to be controversial political statements or news organization based on the report, including a pro china newspaper. The code is only run in China regions, but is stored on all these phones. Technically a standard software update could modify the code to remove that block. I understand concerns about censorship are high, but logically I don't see the concern here; that is if you're not in mainland China. If you're in mainland China the wrong personalized ad can get you into trouble so this very elementary ad censorship is necessary, but this is about the EU region. It's bold to assume they'd allow this to be run in other regions after the user updated the apps, there's just no reason too, nor is there anything particularly invasive or malicious going on here that is different from other smart phones, based on the technical report.
- Ex-Nihilo 5y agoWonder if this is related in any way to sunsetting 3G and telecom companies restricting network access going forward via whitelists.
- Ice_cream_suit 5y agoHow about Iphones made in China ?
- felixding 5y agoThe PDF only has a few keywords of the blacklist. Does anyone have a full list? It'd be interesting to see what they actually censor.
- dgregd 5y agoHow this is different from what Apple is going to do with that on-device image hash algos? The other big story on HN last few days is that a Google Drive account was blocked [1] because of a "terrorist" content. Why should I replace one set of censorship algos with another set of algos? At least Xiaomi limits their censorship algos only to Chinese users. [1] https://news.ycombinator.com/item?id=28621412 https://news.ycombinator.com/item?id=28621412
- arj_vandelay 5y agoI am sure there are better ways to handle censorship concerns