abusesaffiliationarrow-downarrow-leftarrow-rightarrow-upattack-typeburgerchevron-downchevron-leftchevron-rightchevron-upClock iconclosedeletedevelopment-povertydiscriminationdollardownloademailenvironmentexternal-linkfacebookfiltergenderglobegroupshealthC4067174-3DD9-4B9E-AD64-284FDAAE6338@1xinformation-outlineinformationinstagraminvestment-trade-globalisationissueslabourlanguagesShapeCombined Shapeline, chart, up, arrow, graphLinkedInlocationmap-pinminusnewsorganisationotheroverviewpluspreviewArtboard 185profilerefreshIconnewssearchsecurityPathStock downStock steadyStock uptagticktooltiptwitteruniversalityweb
Article

15 Sep 2016

Author:
Kristijan Lucic, Android Headlines

Xiaomi Officially Responds To Recent Backdoor Accusations

See all tags

Xiaomi is one of the largest smartphone manufacturers in the world…Xiaomi releases quite a few devices a year, and various reports in the past accused the company of pre-installing adware, spyware and all sorts of other malicious software on their devices…

…[A] report [claims] that Xiaomi can install any app on their devices without you knowing it. This information came from Thijs Broenink, a Computer Science student from Netherlands. He basically figured out that Xiaomi’s AnalyticsCore.apk constantly runs in the background, and reappears even if you decide to delete it. This app, according to Broenink, checks for updates from Xiaomi every 24 hours, and sends all kinds of information to Xiaomi’s servers …

…[A]ccording to Xiaomi’s statement, this app functions more or less as Mr. Broenink described, but in addition to sending usage reports…the app also pulls updates from the server if they’re available. Now, Xiaomi also said that MIUI (Xiaomi’s user interface pre-installed on every single one of their devices) check the signature of the AnalyticsCore app before installation in order to make sure that the update is official, otherwise it won’t install it. So, all in all, the AnalyticsCore app does support the auto-update feature, though Xiaomi claims that this only improves user experience, nothing else, and it seems like this ‘issue’ was blown way out of proportion.