LightBlog

mercredi 20 mai 2020

[Update 3: Clearer Toggle Language] Researchers accuse Xiaomi web browsers of collecting browsing data – even in Incognito mode

Update 3 (05/21/2020 @ 01:48 AM ET): Xiaomi has updated its browser settings to be clearer in their purpose, removing previous confusion.

Update 2 (05/03/2020 @ 10:14 AM ET): In its blog post update, Xiaomi has mentioned that its browsers will be updated with an option to allow users to opt-out of tracking in incognito mode.

Update 1 (05/01/2020 @ 03:36 PM EST): Xiaomi has published a blog post in response to these allegations. Scroll down for the update. The original story, as published on May 1st, 2020, at 06:18 AM EST, is as follows.

Xiaomi smartphones are unanimously agreed to be one of the best value purchases available in the market at any point in time. Packing some insane hardware at some very lucrative price points, especially at the lower end of the smartphone market, these phones make an offer that a lot of people just can’t refuse. Xiaomi has also been receptive to the needs of the developer community, with decisions such as allowing bootloader unlocking without sacrificing the manufacturer’s warranty — a combination that a lot of other popular OEMs discard, as well as vastly improving upon their kernel source releases. These reasons make them one of the most popular devices in our forums, and they have rightfully earned that spot of popularity.

However, recent reports from security researchers point towards a worrying privacy issue observed on Xiaomi’s web browsers. Forbes’ cybersecurity contributor and associate editor Thomas Brewster, along with cybersecurity researchers Gabriel Cirlig and Andrew Tierney recently concluded in a report that Xiaomi’s various web browsers were sending data to remote servers. They allege that the data being sent included a history of all websites visited, including the URLs, all search engine queries, and all the items viewed on Xiaomi’s news feed, along with device metadata. What’s even worrying about this data collection allegation is that this data is being collected even if you seemingly browse with “incognito mode” enabled.

This data collection seemingly occurs on the pre-installed stock browser on MIUI, as well as Mi Browser Pro and Mint Browser, both of which are available for download through the Google Play Store. Together, these browsers have over 15 million downloads on the Play Store, while the stock browser is preloaded on all Xiaomi devices. The devices tested include the Xiaomi Redmi Note 8, Xiaomi Mi A1, Xiaomi Mi 10, Xiaomi Redmi K20, and the Xiaomi Mi Mix 3. There wasn’t a distinction between Xiaomi’s Android One or MIUI devices, as the collection code was found in the default browser anyway. As such, this issue does not appear to be MIUI-centric but depends on whether you use any of these three browsers on your device, irrespective of the underlying OS. Other browsers, like Google Chrome and Apple Safari collect far less data, restricting themselves to usage and crash analytics.

Xiaomi responded by seemingly confirming that the browsing data it was collecting was fully compliant with local laws and regulations on user data privacy matters. The collected information was user-consented and anonymized. However, the company denied the claims in the research.

The research claims are untrue. Privacy and security is of top concern.

This video shows the collection of anonymous browsing data, which is one of the most common solutions adopted by internet companies to improve the overall browser product experience through analyzing non-personally identifiable information.

The researchers, however, found this claim of anonymity to be dubious. The data that Xiaomi was sending was admittedly “encrypted”, but it was encoded in base64, which can easily be decoded. Since the browsing data can be decoded in a rather trivial manner, and since the collected data also contained device metadata, this browsing data could seemingly be correlated to the actions by individual users without significant effort.

Further, the researchers found that the Xiaomi browsers were pinging domains related to Sensors Analytics, a Chinese startup also known as Sensors Data, known for providing behavioral analytics services. The browsers also contained an API called SensorDataAPI. Xiaomi is also listed as a customer on the Sensors Data website.

Xiaomi has responded to the report from Forbes with denial on several aspects:

While Sensors Analytics provides a data analysis solution for Xiaomi, the collected anonymous data are stored on Xiaomi’s own servers and will not be shared with Sensors Analytics, or any other third-party companies.

The researchers responded against Xiaomi’s denial with further proof of their data collection practice.

With the information available at hand, there does appear to be a worrying privacy issue in the way these browsers function. We’ve reached out to Xiaomi for further comment on these claims.

Source: Forbes

Update 1: Xiaomi Responds in Blog Post

In an official blog post on Mi.com, Xiaomi strongly denied the allegations that they were violating user privacy.

“Xiaomi was disappointed to read the recent article from Forbes. We feel they have misunderstood what we communicated regarding our data privacy principles and policy. Our user’s privacy and internet security is of top priority at Xiaomi; we are confident that we strictly follow and are fully compliant with local laws and regulations. We have reached out to Forbes to offer clarity on this unfortunate misinterpretation.”

The company confirms that they collect “aggregated usage statistics data,” which includes “system information, preferences, user interface feature usage, responsiveness, performance, memory usage, and crash reports.” They state that this information “cannot alone be used to identify any individual.” They confirm that URLs are collected, but that this is done to “identify web pages which load slowly” so they can figure out “how to best improve overall browsing performance.”

Next, the company states that individual browsing data history is synced, but that this is only done when “the user is signed on Mi Account…and the data sync function is set to ‘On’ under Settings.” They deny that browsing data, apart from the aforementioned aggregated usage statistics data, is being synced when the user has enabled incognito mode.

Xiaomi then published screenshots of code snippets from one of their browser apps (they did not specify which browser, though) that they claim demonstrate their points. The first code snippet, according to Xiaomi, shows a decompiled method for “how [they] create randomly generated unique tokens to append to aggregate usage statistics.” They state that “these tokens do not correspond to any individuals.” The next code snippet is seemingly from the browser’s source code and shows a method for “how the Mi Browser works under incognito mode, where no user browsing data will be synced.” The third code snippet demonstrates that the aggregated usage statistics that Xiaomi collects are “stored on Xiaomi’s domain” and aren’t passed to Sensor Analytics. Finally, the fourth image “shows that usage statistic data is transferred with HTTPS protocol of TLS 1.2 encryption.”

To cap it all off, Xiaomi then cites 4 certifications their software has received from TrustArc and British Standard Institution (BSI). These certifications include ISO27001:2013, ISO27018:2014, ISO29151:2017, and TRUSTe.

In response to this blog post, cybersecurity researcher Andrew Tierney took to Twitter to refute Xiaomi’s claims. He states that he and several others re-confirmed the findings across multiple devices—that there “is no doubt that the Mint Browser sends search terms and URLS whilst in Incognito mode.” He states that the code that Xiaomi published does not demonstrate that their “randomly generated unique tokens” can’t be correlated to individuals. The researchers note that the UUID seems to persist across browsing sessions and only changes when the browser is re-installed. Whether Xiaomi only stores the data on their own servers or elsewhere was not a point of contention for the researcher, too. In addition, the researcher states that Xiaomi wasn’t accused of sending the data to remote servers through insecure methods—Mr. Tierney notes that the issue at hand is the data itself that is being sent.

We’re glad to see Xiaomi address these allegations directly, but the explanation does not seem to satisfy the researchers at this point. We will keep an eye on this story for further developments.


Update 2: Xiaomi to offer opt-out option in next browser update

Xiaomi has updated its blog post to announce that the next update to Mint Browser and Mi Browser will include an option in incognito mode to switch off the “aggregated” data collection. The software updates will be submitted to Google Play Store for approval today itself and should be available to users pretty soon.

It remains to be seen whether this data collection will remain enabled by default within the incognito mode, or not. We hope it isn’t. Still, having an option to opt-out works to address some privacy concerns.


Update 3: Xiaomi is updating its Mi Browser and Mint Browser to clarify its incognito data collection toggle

While Xiaomi did address the privacy concerns with a new settings toggle, what actually happened was that the language used for the toggle was misleading, achieving the opposite of what was written. As Android Authority points out, the “enhanced incognito mode” toggle said: “Aggregated data stats won’t be uploaded when incognito mode is on”, which led users to believe that flipping the toggle on would make this statement true. But this was not the case. The wording reflected the current state of the toggle, and was not a true/false statement that you change by flipping the switch.

Old behavior

Now, Xiaomi has updated Mi Browser and Mint Browser to have better language on this toggle. The toggle is now called “Help us improve Mi/Mint Browser“, and the accompanying text says “Turn on to share usage stats with us when incognito mode is on“, with the text remaining the same when you flip the switch. This is much more clear to the purpose and the active state of the setting.

New behavior

In both the versions, the toggle needs to be in the off state if you wish to not have your data collected in incognito mode. It’s just the text that is changing to better reflect the state. The new update to both the browsers is being pushed to the Google Play Store.

The post [Update 3: Clearer Toggle Language] Researchers accuse Xiaomi web browsers of collecting browsing data – even in Incognito mode appeared first on xda-developers.



from xda-developers https://ift.tt/2KQ8aZD
via IFTTT

OnePlus, Realme, Black Shark, and Meizu join Xiaomi, OPPO, and Vivo’s file transfer alliance

Back in August last year, three Chinese OEMs — Xiaomi, OPPO, and Vivo — formed an alliance for the development of a new P2P file transfer protocol to simplify cross-device file transfers. The solution aimed to offer an AirDrop like experience in the Android ecosystem by allowing devices from different manufacturers to seamlessly share files between them. After months of development, it was finally rolled out earlier this year in February and now, a few more manufacturers are jumping on the bandwagon.

According to recent posts on Chinese social media platform Weibo, OnePlus, Realme, Meizu, and Black Shark have now joined the P2P file transfer alliance. Thanks to this, cross-device file transfer support will soon be coming to devices from these manufacturers, allowing users to easily share files without the need for any third-party applications. The move is expected to benefit over 400 million users around the world.

P2P file transfer Xiaomi Vivo OPPO OnePlus Meizu Realme Black Shark (1) P2P file transfer Xiaomi Vivo OPPO OnePlus Meizu Realme Black Shark (1)

For the unaware, the file transfer protocol supports a variety of file formats and it even lets users share entire folders with each other. The protocol supports file transfer speeds in the order of 20MBps over a stable connection, which is significantly better than file transfers over Bluetooth.

As of now, OnePlus, Realme, and Meizu haven’t revealed exactly when the feature will be released on their respective Android skins. However, as a recent report from BusinessWire points out, Black Shark’s new JoyUI 11 already includes support for the P2P file transfer protocol. The company recently rolled out JoyUI 11 for the Black Shark 2 and Black Shark 2 Pro, which means that these devices should already feature support for the file transfer protocol, along with the company’s latest Black Shark 3 series.


Source: Weibo (1,2,3,4)

The post OnePlus, Realme, Black Shark, and Meizu join Xiaomi, OPPO, and Vivo’s file transfer alliance appeared first on xda-developers.



from xda-developers https://ift.tt/2ZoR9y8
via IFTTT

OnePlus, Realme, Black Shark, and Meizu join Xiaomi, OPPO, and Vivo’s file transfer alliance

Back in August last year, three Chinese OEMs — Xiaomi, OPPO, and Vivo — formed an alliance for the development of a new P2P file transfer protocol to simplify cross-device file transfers. The solution aimed to offer an AirDrop like experience in the Android ecosystem by allowing devices from different manufacturers to seamlessly share files between them. After months of development, it was finally rolled out earlier this year in February and now, a few more manufacturers are jumping on the bandwagon.

According to recent posts on Chinese social media platform Weibo, OnePlus, Realme, Meizu, and Black Shark have now joined the P2P file transfer alliance. Thanks to this, cross-device file transfer support will soon be coming to devices from these manufacturers, allowing users to easily share files without the need for any third-party applications. The move is expected to benefit over 400 million users around the world.

P2P file transfer Xiaomi Vivo OPPO OnePlus Meizu Realme Black Shark (1) P2P file transfer Xiaomi Vivo OPPO OnePlus Meizu Realme Black Shark (1)

For the unaware, the file transfer protocol supports a variety of file formats and it even lets users share entire folders with each other. The protocol supports file transfer speeds in the order of 20MBps over a stable connection, which is significantly better than file transfers over Bluetooth.

As of now, OnePlus, Realme, and Meizu haven’t revealed exactly when the feature will be released on their respective Android skins. However, as a recent report from BusinessWire points out, Black Shark’s new JoyUI 11 already includes support for the P2P file transfer protocol. The company recently rolled out JoyUI 11 for the Black Shark 2 and Black Shark 2 Pro, which means that these devices should already feature support for the file transfer protocol, along with the company’s latest Black Shark 3 series.


Source: Weibo (1,2,3,4)

The post OnePlus, Realme, Black Shark, and Meizu join Xiaomi, OPPO, and Vivo’s file transfer alliance appeared first on xda-developers.



from xda-developers https://ift.tt/2ZoR9y8
via IFTTT

Samsung Galaxy Buds+ go on sale in a new Aura Blue color in the U.S.

At the Galaxy Unpacked event earlier this year, Samsung unveiled a new pair of truly wireless (TWS) earbuds alongside its flagship Galaxy S20 series. The new earbuds, called the Galaxy Buds+, were a minor upgrade over the original Galaxy Buds, featuring larger batteries in the earbuds as well as the charging case, support for multi-device connection, and a new dual driver system. Initially, the Galaxy Buds+ were released in three color variants — Cosmic Black, Cosmic Blue, and Black — but Samsung soon added a red color option to the lineup. Along with these four color options, Samsung also launched a special variant as part of the limited editing Samsung Galaxy Z Flip bundle designed by the American fashion designer, Thom Browne.

Samsung Galaxy Buds+ Samsung Galaxy Buds+

Late last month, we discovered yet another Deep Blue color variant of the Galaxy Buds+ in version 1.7.47-22 of the Samsung SmartThings app. But, at the time, we had no information about its release and we believed that the company would launch them alongside the Galaxy Note 20 series later this year in August. However, Samsung has now released the new Deep Blue color variant, officially called Aura Blue, in the U.S. and you can get it on Best Buy for $149.99 by following the link below. Do note that, other than the color, the new Aura Blue Galaxy Buds+ are exactly the same as previously launched variants.

Buy the Aura Blue Galaxy Buds+ from Best Buy ($149.99)

The post Samsung Galaxy Buds+ go on sale in a new Aura Blue color in the U.S. appeared first on xda-developers.



from xda-developers https://ift.tt/3e4h5Dw
via IFTTT

OnePlus removed from McLaren’s partners page, hinting there won’t be another McLaren Edition

OnePlus has been doing special editions of its phones for a few years now. The OnePlus 5T was available in the Star Wars: The Last Jedi Edition, and the OnePlus 6 was available in a Marvel Avengers Edition. Both of these phones were available in limited quantities and in select regions only. The company expanded the scope of these special editions with the launch of the OnePlus 6T McLaren Edition. This variant not only came with a new and distinct CMF (color-material-finish), but it also bumped up the RAM to 10GB and the charging technology to Warp Charge 30. The McLaren Edition made a return with the OnePlus 7T Pro, once again bumping up the RAM and opting for the signature CMF. However, this run appears to have come to an end, as recent developments indicate that there may not be another McLaren edition in the works.

A keen-eyed Redditor noticed that OnePlus was no longer listed as a Formula 1 partner for McLaren for the 2020 F1 season. We checked through Wayback machine (internet archive) and can spot that OnePlus continued to remain listed until March 29, 2020, at least. So, it is safe to presume that the company was delisted as a partner within the last month or so.

OnePlus 7T Pro McLaren Edition

What does this mean? This means that there is unlikely to be another McLaren Edition phone coming from OnePlus. The next McLaren iteration was expected to be on the presumed OnePlus 8T, but we can rule this out from happening based on how things stand right now.

OnePlus CMF Concepts

That’s not to say that there won’t be a special edition for the OnePlus 8T series, at all. OnePlus could always collaborate with a new partner and market a different CMF with different features as a special edition. Some have taken this news to also mean that there won’t be a “T” version at all this year — we do not have any evidence of this statement being true or false, either way.

We’ve reached out to OnePlus for comment on this delisting. We’ll update our article when we get more information.

The post OnePlus removed from McLaren’s partners page, hinting there won’t be another McLaren Edition appeared first on xda-developers.



from xda-developers https://ift.tt/2AMa4ZD
via IFTTT

OnePlus removed from McLaren’s partners page, hinting there won’t be another McLaren Edition

OnePlus has been doing special editions of its phones for a few years now. The OnePlus 5T was available in the Star Wars: The Last Jedi Edition, and the OnePlus 6 was available in a Marvel Avengers Edition. Both of these phones were available in limited quantities and in select regions only. The company expanded the scope of these special editions with the launch of the OnePlus 6T McLaren Edition. This variant not only came with a new and distinct CMF (color-material-finish), but it also bumped up the RAM to 10GB and the charging technology to Warp Charge 30. The McLaren Edition made a return with the OnePlus 7T Pro, once again bumping up the RAM and opting for the signature CMF. However, this run appears to have come to an end, as recent developments indicate that there may not be another McLaren edition in the works.

A keen-eyed Redditor noticed that OnePlus was no longer listed as a Formula 1 partner for McLaren for the 2020 F1 season. We checked through Wayback machine (internet archive) and can spot that OnePlus continued to remain listed until March 29, 2020, at least. So, it is safe to presume that the company was delisted as a partner within the last month or so.

OnePlus 7T Pro McLaren Edition

What does this mean? This means that there is unlikely to be another McLaren Edition phone coming from OnePlus. The next McLaren iteration was expected to be on the presumed OnePlus 8T, but we can rule this out from happening based on how things stand right now.

OnePlus CMF Concepts

That’s not to say that there won’t be a special edition for the OnePlus 8T series, at all. OnePlus could always collaborate with a new partner and market a different CMF with different features as a special edition. Some have taken this news to also mean that there won’t be a “T” version at all this year — we do not have any evidence of this statement being true or false, either way.

We’ve reached out to OnePlus for comment on this delisting. We’ll update our article when we get more information.

The post OnePlus removed from McLaren’s partners page, hinting there won’t be another McLaren Edition appeared first on xda-developers.



from xda-developers https://ift.tt/2AMa4ZD
via IFTTT

Nova Launcher 6.2.13 beta adds new adaptive icon shapes inspired by Android 11

Google launched the first Android 11 Developer Preview earlier this year in February, which was followed by Preview 2, Preview 3, and recently, Preview 4. Even though the company did not highlight any developer features in the latest release, we discovered a couple of changes and new features when we tried it out on the Google Pixel 3a XL and Google Pixel 4. These included things like a new select button in the recent apps overview, resizable picture-in-picture windows, new icon shapes in Pixel Themes, and much more. While there’s still a long way to go before any of these features are officially available in a stable Android 11 release, you can now experience the new icon shapes with the latest beta release of Nova Launcher.

Nova Launcher 6.2.13 Nova Launcher 6.2.13 Nova Launcher 6.2.13

Nova Launcher v6.2.13 is now available for download and it brings the new adaptive Flower and Hexagon icon shapes that were introduced in the Android 11 Developer Preview 4. To try out these new adaptive icon shapes for yourself, you can download the latest beta release of Nova Launcher from the link below.

Once you have the update installed on your device, you’ll need to navigate to the Icon style option within the Look & Feel section in the Nova Launcher Settings. As you can see in the attached screenshot, Nova Launcher now offers a total of 12 icon shapes, including Round, Squircle, Rounded square, Flower, Square, Teardrop, Pentagon, Heptagon, Octagon, and three different Hexagons. Along with the new adaptive icon shapes, the update brings a couple of bug fixes and optimizations for the launcher. Here’s the complete changelog for Nova Launcher v6.2.13 beta:

  • New Adaptive Icon Shapes:
    • Flower from Android 11 Preview DP4
    • “Hexagon” from Android 11 Preview DP$
    • Pentagon, actual hexagons, and heptagon
    • Bug fixes and optimizations

Download Nova Launcher v6.2.13 beta

The post Nova Launcher 6.2.13 beta adds new adaptive icon shapes inspired by Android 11 appeared first on xda-developers.



from xda-developers https://ift.tt/2zSDDby
via IFTTT