Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Xiaomi produces one of the best bang for your bucks hardware in the market. Their software is crap though. Ads in the system apps, ui customization that arguably looks worse than stock android, and now blanket tracking like this, though it was always pinging their tracking servers frequently. My pihole logs pretty much full with blocked xiaomi requests until I flashed the phone.

Best thing to do when you got an android phone, especially from a chinese manufacturer, is to flash LineageOS on it.



Problem is lately many banking app required you to use non-root phone, at least in my country. There used to be workaround, but it is not work anymore.

I have Redmi phone and I hates it as soon as I found that there is ads in their rom. It's so disappointing. I mean, other Chinese brand have their own crapware yes, but ads?

I then flash my phone to pure Pixel rom and never been happier, until the bank app incident happened. So I have to use their original rom for now until I get a new phone.

No matter how rave the Mi phone review be, or how it is great 'bang for the bucks' brand, I will never touch their phone again.


Actually, I installed LineageOS but skip installing root binary (it's an optional step when flashing LineageOS) as I don't need root anymore. Without root I can still use my banking app because Google safetynet is passing on my phone.


I use LinageOS myself but I would never use a smartphone for anything related to personal finance.

Without an extensive research project there is no telling what's going on under the hood imho.


Most banking apps have extensive telemetry enabled themselves. Even keyboards are trying to phone home constantly


There are ways to get around safetynet, though it's a cat-and-mouse game of "detect the root".


Interesting. I'll check out some more information about it.


Wow, didn't realize android got that bad recently. Makes me not want to leave the iPhone ecosystem.

The only benefit Android had was the control. You take that away and make it a walled garden, its just an iPhone...but worse


You still have more control compared to iPhone where you cannot change your default SMS messaging app, or even your default browser. And you have no choice in browser engine either. And it's hardly a walled garden when I can sideload any app on any Android phone. Xiaomi even has their own store that's not Google Play.


More control of apps, but less control over snooping


The assumption is that bad guys have a much harder time swapping out the SMS app for a trojan.


The assumption is that the apps you choose on iOS just won’t be default. You can still have an SMS or mail app that invades your privacy by uploading everything to a remote server, it just wont be given the GUI conveniences of a default app — a big competitive edge.

But it will be difficult to clamp down on leaking user security and privacy when Apple itself has unencrypted backups, so they can’t pressure other companies to proactively protect user data at rest.

I’ve stopped using higher quality non Apple apps because even something like a calendar app or todo app warrants a special private cloud that slurps up your data with a legitimate argument for why they should have everything.


I like overall quality of iOS but I still prefer Android though, you can do all sort of weird things iOS never allow. Just next time I'll choose whatever phones that gives me vanilla Android(as much as possible) Pure android is clean and work great, until vendor try to 'enhance' their phone with their apps and stuff.


Yap, if i could use my banking apps with lineageos, i would install it in a heartbeat!


Ha! As a Chinese myself, when I buying a new phone, the first thing I do is to Google whether or not the phone can load custom ROM.

Buying a phone that allows custom ROM is really beneficial. Not just it gives you more fre<Censored>edom and choose, it can also expand the lifespan of the device and thus save you a bit of money.

A side note: Fairphone looked quite nice, but that €450 price tag pushed me out far far away :(


Is that a recent thing? My Xiaomi Mi A1 ran Android One that gets official updates to this day, as far as I could tell it was pretty stock and the data collection in their "Mi Services" could be disabled in the settings UI, so not unlike pretty much any cheap manufacturer.


Mi A1 is probably an exception as it's part of Android One program. The rest of xiaomi lineups are using their miui rom which contains ads and tracking mentioned in the article.


LineageOS (and a few other Android distros) are the only mobile OSes I trust and use. Not any different with laptops and desktops BTW: I don't trust any preinstalled OS and not any distro for which I can't browse the source.


WRT “bang for the buck”: you have to take the whole picture into account, not just cpu speed/battery life plus price. Taken as a whole, it has a negative bang for the buck

Also curious: can you trust the hardware even if you do flash lineageOS? Honestly curious


That's depend your threat model, isn't it? All Android phones rely on black box baseband blobs from the hardware manufacturers. If there is an exploit hidden there, I believe they won't use it just for blanket data collection like this, but only use it for targeted attacks on high value targets (politicians, journalists, magacorp execs, etc). Hopefully they won't bother to use that kind of low level exploits on normal plebs like me. I'm not even sure if iPhones are safe enough when your threat model requires trusting the low level hardware. The only way to avoid it is by using a phone with fully trusted stacks like pine phone or librem 5.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: