Xiaomi phones allegedly allow backdoor to private user data

Main Image
  • Like
  • Comment
  • Share

A recent cybersecurity report highlights the backdoors in Xiaomi phones, through which private user data is being ferried to Alibaba cloud servers. The man behind the discovery is Gabriel Cirlig, a veteran web security researcher. He shared his worrisome finding with the Forbes.

Let’s see what it’s all about and how Xiaomi responded.

The backdoor

Best Snapdragon 665 phones
Redmi Note 8

“A backdoor with phone functionality,” is what Gabriel Cirlig called the exploit, while talking to Forbes.

Although he snooped in his personal Redmi Note 8 at first, the same issue was later identified within other Xiaomi phones like Mi 10, Redmi K20, and Mi MIX 3.

He noticed the following data being recorded and sent to 3rd party cloud servers:

  • His Google searches (even incognito) and other web activity on Xiaomi browser
  • Every item viewed on the Xiaomi news feed
  • His interaction with MIUI launcher, settings and file manager.

These were being sent to remote servers in Singapore and Russia, though the Web domains they hosted were registered in Beijing. Not just that, Xiaomi apps were also sending data to domains that appeared to reference Sensor Analytics (more on that later).

Furthermore, another cybersecurity researcher named Andrew Tierney also corroborated Cirlig’s findings. He identified both Mi Browser Pro and the Mint Browser as the culprits. These are popular apps with a combined downloads of about 15 million on the Google Play Store.

Cirlig and Tierney mentioned – how Xiaomi was collating “data about the phone, including unique numbers for identifying the specific device and Android version something which could easily be correlated with an actual human behind the screen”.

ALSO READ: Apple iPhone 12 series expected prices

Xiaomi’s response

Xiaomi refutes the allegations saying that “The research claims are untrue”, “Privacy and security are of top concern” and that they “are fully compliant with local laws and regulations on user data privacy matters.”

It underlines the fact that its users had agreed to such tracking.

When users open the app for the very first time, they are displayed a big pop-up window seeking permission for data collection. This is something most smartphone users must be aware of as its a ubiquitous thing. Every app does it.

As for Sensor Analytics, Xiaomi says the firm “provides a data analysis solution for Xiaomi,” and the collected anonymous data is “stored on Xiaomi’s own servers and will not be shared with Sensor Analytics, or any other third-party companies.”

ALSO READ: MIUI 12 Features and Eligible Devices List

A closing note of caution

While Xiaomi claims the data sent to cloud servers as encrypted, Cirlig says he could easily crack the same in a matter of few seconds. Hmm!

In Xiaomi’s defense, every company collects and harvests data. It’s at least upfront about it. Their business model is less focussed on hardware margins and more on revenue from data and ads.

But then there is the point which Cirlig raises:

“My main concern for privacy is that the data sent to their servers can be very easily correlated with a specific user.”

He piles on the warning when he warns millions of other users could also be affected. And every one of those users might not be cool with their private data being recorded and shared.

MIUI user agreement

Vasan G.S.Vasan G.S.
An inquisitive mind who spends a big chunk of the day keenly tracking every emerging detail and is responsible for quickly passing on important developments to Smartprix followers. He loves to stay in his bubble scripting his destiny involving amazing technology and people with good character, passion, and brilliance.

Related Articles

ImageReliance Jio AX6000 Universal Wi-Fi 6 Router Launched In India: Check Specs And Price Here

Reliance Jio has launched a Wi-Fi 6 Universal router. The Jio AX6000 router offers up to 6 Gbps download speeds, provides wide coverage, supports over 100 connections, and enables lag-free streaming or gaming for multiple household members. For the specifications, the router seems affordable. Check out more details about the Jio AX6000 Wi-Fi 6 router’s …

ImageXiaomi Redmi Note 10 Series to get Super AMOLED 120Hz display

Redmi Note 10 series is scheduled to launch on March 4 in India and Xiaomi continues piece by piece unveiling to build up the hype to the launch. The latest bit from Xiaomi India Head assures the Note 10 series will sport a Super AMOLED display. Xiaomi earlier promised to present the Redmi Note 10 …

ImageXiaomi Redmi Note 10S First Impression

Over the years, Xiaomi has offered numerous value champions under its Redmi banner. The brand has been consistently raising the bar for both value and features which has ultimately helped it sell millions of Redmi series phones and become the number one smartphone brand in the country.In 2021, Xiaomi’s Redmi vertical has already delivered …

ImageUsers Allege Xioami To Install “Mintnav” Browser Hijacker On Phones

Chinese smartphone manufacturer Xiaomi has allegedly installed malware on users’ phones that hijacks their web browser and sets itself as the default search engine. The information comes in from several platforms, such as X and Reddit, where users report that a site named “Mintnav” is taking over their Google Home page, interrupting their browsing experience.  …

ImageJio Finally Clears the Air on Voice and SMS-only Plans After Major User Backlash

TL; DR For weeks, Jio users have been expressing their frustration online, questioning why the company’s newly launched voice and SMS-only prepaid plans didn’t allow them to add data when needed. Confusion spread like wildfire, with reports suggesting that Jio had outright blocked any possibility of using data boosters with these plans.  Now, after mounting …

Discuss

Be the first to leave a comment.