top of page
Search
  • Writer's pictureTech Glass

Beware Xiaomi Users, even in Private mode !!

Warning Over Chinese Mobile Giant Xiaomi Recording Millions Of People’s ‘Private’ Web And Phone Use.


“It’s a backdoor with phone functionality,” quips Gabi Cirlig about his new Xiaomi phone. He’s only half-joking.

Cirlig is speaking with Forbes after discovering that his Redmi Note 8 smartphone was watching much of what he was doing on the phone. That data was then being sent to remote servers hosted by another Chinese tech giant, Alibaba, which were ostensibly rented by Xiaomi. 


When he looked around the Web on the device’s default Xiaomi browser, it recorded all the websites he visited, including search engine queries whether with Google or the privacy-focused DuckDuckGo, and every item viewed on a news feed feature of the Xiaomi software. That tracking appeared to be happening even if he used the supposedly private “incognito” mode.

The device was also recording what folders he opened and to which screens he swiped, including the status bar and the settings page. All of the data was being packaged up and sent to remote servers in Singapore and Russia, though the Web domains they hosted were registered in Beijing.


Meanwhile, at Forbes’ request, cybersecurity researcher Andrew Tierney investigated further. He also found browsers shipped by Xiaomi on Google Play—Mi Browser Pro and the Mint Browser—were collecting the same data. Together, they have more than 15 million downloads, according to Google Play statistics.

Many more millions are likely to be affected by what Cirlig described as a serious privacy issue, though Xiaomi denied there was a problem. Valued at $50 billion, Xiaomi is one of the top four smartphone makers in the world by market share, behind Apple, Samsung and Huawei. Xiaomi’s big sell is cheap devices that have many of the same qualities as higher-end smartphones. But for customers, that low cost could come with a hefty price: their privacy.


Cirlig thinks that the problems affect many more models than the one he tested. He downloaded firmware for other Xiaomi phones—including the Xiaomi MI 10, Xiaomi Redmi K20 and Xiaomi Mi MIX 3 devices. He then confirmed they had the same browser code, leading him to suspect they had the same privacy issues.

And there appear to be issues with how Xiaomi is transferring the data to its servers. Though the Chinese company claimed the data was being encrypted when transferred in an attempt to protect user privacy, Cirlig found he was able to quickly see just what was being taken from his device by decoding a chunk of information that was hidden with a form of easily crackable encoding, known as base64. It took Cirlig just a few seconds to change the garbled data into readable chunks of information.

“My main concern for privacy is that the data sent to their servers can be very easily correlated with a specific user,” warned Cirlig.


Xiaomi’s response

In response to the findings, Xiaomi said, “The research claims are untrue,” and “Privacy and security is of top concern,” adding that it “strictly follows and is fully compliant with local laws and regulations on user data privacy matters.” But a spokesperson confirmed it was collecting browsing data, claiming the information was anonymized so wasn’t tied to any identity. They said that users had consented to such tracking. 

But, as pointed out by Cirlig and Tierney, it wasn’t just the website or Web search that was sent to the server. Xiaomi was also collecting data about the phone, including unique numbers for identifying the specific device and Android version. Cirlig said such “metadata” could “easily be correlated with an actual human behind the screen.”

Xiaomi’s spokesperson also denied that browsing data was being recorded under incognito mode. Both Cirlig and Tierney, however, found in their independent tests that their web habits were sent off to remote servers regardless of what mode the browser was set to, providing both photos and videos as proof.

When Forbes provided Xiaomi with a video made by Cirlig showing how his Google search for “porn” and a visit to the site PornHub were sent to remote servers, even when in incognito mode, the company spokesperson continued to deny that the information was being recorded. “This video shows the collection of anonymous browsing data, which is one of the most common solutions adopted by internet companies to improve the overall browser product experience through analyzing non-personally identifiable information,” they added.

Both Cirlig and Tierney said Xiaomi’s behavior was more invasive than other browsers like Google Chrome or Apple Safari. “It’s a lot worse than any of the mainstream browsers I have seen,” Tierney said. “Many of them take analytics, but it's about usage and crashing. Taking browser behavior, including URLs, without explicit consent and in private browsing mode, is about as bad as it gets.”


Cirlig also suspected that his app use was being monitored by Xiaomi, as every time he opened an app, a chunk of information would be sent to a remote server. Another researcher who’d tested Xiaomi devices, though was under an NDA to discuss the matter openly, said he’d seen the manufacturer’s phone collect such data. Xiaomi didn’t respond to questions on that issue.


‘Behavioral Analytics’

Xiaomi appears to have another reason for collecting the data: to better understand its users’ behavior. It’s using the services of a behavioral analytics company called Sensors Analytics. The Chinese startup, also known as Sensors Data, has raised $60 million since its founding in 2015, most recently taking $44 million in a round led by New York private equity firm Warburg Pincus, which also featured funding from Sequoia Capital China. As described in Pitchbook, a tracker of company funding, Sensors Analytics is a “provider of an in-depth user behavior analysis platform and professional consulting services.” Its tools help its clients in “exploring the hidden stories behind the indicators in exploring the key behaviors of different businesses.”

Both Cirlig and Tierney found their Xiaomi apps were sending data to domains that appeared to reference Sensors Analytics, including the repeated use of SA. When clicking on one of the domains, the page contained one sentence: “Sensors Analytics is ready to receive your data!”  There was an API called SensorDataAPI—an API (application programming interface) being the software that allows third parties access to app data. Xiaomi is also listed as a customer on Sensors Data’s website.


The founder and CEO of Sensors Data, Sang Wenfeng, has a long history in tracking users. At Chinese internet giant Baidu he built a big data platform for Baidu user logs, according to his company bio.

Xiaomi’s spokesperson confirmed the relationship with the startup: “While Sensors Analytics provides a data analysis solution for Xiaomi, the collected anonymous data are stored on Xiaomi's own servers and will not be shared with Sensors Analytics, or any other third-party companies.”

It’s the second time in two months that a huge Chinese tech company has been seen watching over users’ phone habits. A security app with a “private” browser made by Cheetah Mobile, a public company listed on the New York Stock Exchange, was seen collecting information on Web use, Wi-Fi access point names and more granular data like how a user scrolled on visited Web pages. Cheetah argued it needed to collect the information to protect users and improve their experience.

Late in his research, Cirlig also discovered that Xiaomi’s music player app on his phone was collecting information on his listening habits: what songs were played and when.

One message was clear to the researcher: when you’re listening, Xiaomi is listening, too.

UPDATE: Xiaomi posted a blog in which it delineated how and when it collects visited URLs visited by its users. Read it in full here.


Source : Forbes

3 views0 comments

Comments


Apple iPhone Event under 9 Minutes : iPhone 12, iPhone 12 Pro and iPhone 12 Mini details | TechGlass
08:25

Apple iPhone Event under 9 Minutes : iPhone 12, iPhone 12 Pro and iPhone 12 Mini details | TechGlass

Apple today announced the new iPhone 12, featuring a 6.1-inch OLED display. The iPhone 12 is one of four models unveiled today as part of the new fall iPhone lineup. iPhone 12 will go on sale for $799, and the smaller iPhone 12 mini starts at $699. iPhone 12 will be available to order starting this Friday, October 16. All new iPhones support 5G and feature a new industrial design with flat edges and thinner bezels. The phone looks a lot like an iPhone 5 but with a full-screen face. The iPhone 12 comes in five color finishes: black, white, red, green and blue. Whereas the iPhone 12 Pro features a stainless steel frame, the cheaper iPhone 12 continues to use aluminium case materials. Source : Apple/Verge =================================== Check out our other videos: 7 Top iOS14 features from Android : https://youtu.be/u8GWLnM427A How to get iOS 14 NOW before its official release : https://youtu.be/DqKEDX938gs FREE : How to watch YouTube without Ads for FREE : https://youtu.be/mehfU1tsKLI Top 6 Reasons to use Google Meet : https://youtu.be/p278-MTEKA4 Zoom Video Conferencing : Should you Zoom In or Zoom Out : https://youtu.be/nVPrl8NgDoY Google Smart Debit Card : https://youtu.be/HjTEhC06dYQ DIY Surgical Mask under 2 minutes : https://youtu.be/tHTW1dL_Twk iPhone SE launch : https://youtu.be/b8ZBNbymsDk YouTube Short - TikTok alternative : https://youtu.be/uxxvUpVVas8 OnePlus8 Colors : https://youtu.be/P8RhIRwOsFg How to book OLA and Uber directly from Google Maps : https://youtu.be/gseqGb59Kvo Presenting OLA Select : https://youtu.be/H1zixovCvgw
How to get iOS 14 NOW before its official release | TechGlass
02:21

How to get iOS 14 NOW before its official release | TechGlass

Apple released lots of features as part of iOS14, but the official release of iOS14 is going to happen later this year in September if all goes well with rest of 2020 !! How about getting the iOS14 right on your phone, right now ? Yes, you can, here is how you can install iOS14 Beta on you phone in just 2 minutes. Go ahead and get that iOS14 feeling you have been waiting for !! Please note : Beta builds are not as stable as the actual releases, please make sure you take backup of your phone before installing beta software on the phone. Also, we recommend not to install beta profile on your primary phone. You will be solely responsible for any issue/problem/damage to your phone. =============================== Check out our other videos: FREE : How to watch YouTube without Ads for FREE : https://youtu.be/mehfU1tsKLI Top 6 Reasons to use Google Meet : https://youtu.be/p278-MTEKA4 Zoom Video Conferencing : Should you Zoom In or Zoom Out : https://youtu.be/nVPrl8NgDoY Google Smart Debit Card : https://youtu.be/HjTEhC06dYQ DIY Surgical Mask under 2 minutes : https://youtu.be/tHTW1dL_Twk iPhone SE launch : https://youtu.be/b8ZBNbymsDk YouTube Short - TikTok alternative : https://youtu.be/uxxvUpVVas8 OnePlus8 Colors : https://youtu.be/P8RhIRwOsFg How to book OLA and Uber directly from Google Maps : https://youtu.be/gseqGb59Kvo Presenting OLA Select : https://youtu.be/H1zixovCvgw ================ Follow us on Facebook : https://m.facebook.com/TechGlasss Twitter : https://www.twitter.com/techglass1 Instagram : https://www.instagram.com/thetechglass
Top 6 reasons to use Google Meet | TechGlass
02:43

Top 6 reasons to use Google Meet | TechGlass

Skip the Zoom drama and Meet a better way to video chat. Living alone, the only way I see my friends and family right now is video chatting apps, and there certainly are plenty to choose from these days. Zoom has been the in-vogue video app of the last several weeks, but since that Google Meet is free for everyone this summer, you should absolutely move your chats over to Meet instead. While Google Meet was built for enterprise as a way to host weekly staff meetings and host company-wide briefings, it has several advantages for the everyday chat with your parents or that weekly coffee gossip your mom has with her friends. The only reason not to give Google Meet a shot right now is actually that many of us actually can't create video meetings yet. Google said in its announcement that the ability for non-G Suite users to use Google Meet for more than joining someone else's meeting is going to be gradually rolling out over the next few weeks. ================================ Check out our other videos: Zoom Video Conferencing : Should you Zoom In or Zoom Out : https://youtu.be/nVPrl8NgDoY Google Smart Debit Card : https://youtu.be/HjTEhC06dYQ DIY Surgical Mask under 2 minutes : https://youtu.be/tHTW1dL_Twk iPhone SE launch : https://youtu.be/b8ZBNbymsDk YouTube Short - TikTok alternative : https://youtu.be/uxxvUpVVas8 OnePlus8 Colors : https://youtu.be/P8RhIRwOsFg How to book OLA and Uber directly from Google Maps : https://youtu.be/gseqGb59Kvo
bottom of page