Jump to content

Security firm discovers several major flaws in MIUI

The Sloth

what happened? 

 

"The first problem relates to the Mi-Mover app, which allows you to transfer apps and some settings from any Android device (running 4.2 or higher) to a Xiaomi phone. This is a pretty common feature, even on Nexus and Pixel phones. However, if both devices are running MIUI, Mi-Mover will copy all system data to the new phone. This includes confidential information, like saved payment information, overriding Android's built-in sandbox protection in the process. Some applications are unaffected, like ones check the device or require a PIN at launch, but many popular apps like Twitter and Airbnb don't check the device. So if someone had access to a Xiaomi phone, they could copy all of a user's information without much effort" 

 

"Another flaw was found in how MIUI handles device-administrator apps. As you may know, many security/anti-theft apps (like Android Device Manager) can use Android's administrator permission to wipe the device. Uninstalling these apps usually requires the user's password, but eScan discovered that no prompt was given when deleting an administrator app. Theoretically, someone could steal a Xiaomi phone and quickly delete any anti-theft apps before the owner had the chance to use them." 

 

 

Xiaomi response 

 

598c877f7cc28_ScreenShot2017-08-10at10_16_59AM.thumb.png.adb1a28d40dd02043d05ebc196ca8382.png

 

TLDR-  Xiomi Mi-Mover app can be easily used to copy user data, like saved payment information, overriding Android's built-in sandbox protection in the process, another issue was how someone with a stolen xiimi phone could uninstall device administrator giving them acess because of how MIUI handles device-administrator apps, so a thief can delete a anti theft app after obtaining the stolen phone before owner can activate any antitheft measure. 

 

"Uninstalling these apps usually requires the user's password, but eScan discovered that no prompt was given when deleting an administrator app." 

 

what do you guys think? i think a simple software update can fix the issues but not sure if that will happen. 

 

-http://www.androidpolice.com/2017/08/10/security-firm-discovers-several-major-flaws-miui/ 

Link to comment
Share on other sites

Link to post
Share on other sites

Stock Android Lyfe

Make sure to quote me or tag me when responding to me, or I might not know you replied! Examples:

 

Do this:

Quote

And make sure you do it by hitting the quote button at the bottom left of my post, and not the one inside the editor!

Or this:

@DocSwag

 

Buy whatever product is best for you, not what product is "best" for the market.

 

Interested in computer architecture? Still in middle or high school? P.M. me!

 

I love computer hardware and feel free to ask me anything about that (or phones). I especially like SSDs. But please do not ask me anything about Networking, programming, command line stuff, or any relatively hard software stuff. I know next to nothing about that.

 

Compooters:

Spoiler

Desktop:

Spoiler

CPU: i7 6700k, CPU Cooler: be quiet! Dark Rock Pro 3, Motherboard: MSI Z170a KRAIT GAMING, RAM: G.Skill Ripjaws 4 Series 4x4gb DDR4-2666 MHz, Storage: SanDisk SSD Plus 240gb + OCZ Vertex 180 480 GB + Western Digital Caviar Blue 1 TB 7200 RPM, Video Card: EVGA GTX 970 SSC, Case: Fractal Design Define S, Power Supply: Seasonic Focus+ Gold 650w Yay, Keyboard: Logitech G710+, Mouse: Logitech G502 Proteus Spectrum, Headphones: B&O H9i, Monitor: LG 29um67 (2560x1080 75hz freesync)

Home Server:

Spoiler

CPU: Pentium G4400, CPU Cooler: Stock, Motherboard: MSI h110l Pro Mini AC, RAM: Hyper X Fury DDR4 1x8gb 2133 MHz, Storage: PNY CS1311 120gb SSD + two Segate 4tb HDDs in RAID 1, Video Card: Does Intel Integrated Graphics count?, Case: Fractal Design Node 304, Power Supply: Seasonic 360w 80+ Gold, Keyboard+Mouse+Monitor: Does it matter?

Laptop (I use it for school):

Spoiler

Surface book 2 13" with an i7 8650u, 8gb RAM, 256 GB storage, and a GTX 1050

And if you're curious (or a stalker) I have a Just Black Pixel 2 XL 64gb

 

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, Kumaresh said:

If they could demonstrate such security loopholes live on a locked phone, that would give cause for alarm..... And just when I purchased a new Mi Max 2......

Such a good phone.

 

I'm lusting over that huge screen

Link to comment
Share on other sites

Link to post
Share on other sites

Not trying to hate on something (Xiaomi smartphones) i never used, and that i personally dont plan to use, but the company answer is so trivial and uninspiring...

 

Like said above, a demonstration would be nice to see.

Link to comment
Share on other sites

Link to post
Share on other sites

I have a redmi 4 pro, doesn't affect me much but I hope it will get patched soon.

Link to comment
Share on other sites

Link to post
Share on other sites

Security issues in a proprietary OEM utility? Say it ain't so.

Link to comment
Share on other sites

Link to post
Share on other sites

17 hours ago, nerdslayer1 said:

what do you guys think? i think a simple software update can fix the issues but not sure if that will happen. 

Reading Xiaomi's response, I would say:

1) it won't happen

2) it's not needed

 

At least regarding MI Mover, which is what Xiamoi response was about. It's working as intended, the original complain is the equivalent of saying that there is a flaw in any OS because having administrator rights give you administrator rights - imagine if someone logged in as administrator to your device! :P 

 

The second claim is the only potential problem here, but unfortunately we don't have any response from the company about them. I don't particularly care because I don't install that type of apps anyway, but those who do certainly don't want for anyone to uninstall them. Although, again, if they require unlocking the phone as administrator, then what else can you do (other than having them as uninstallable "system apps", as is common in Android OEM bloatware)?.

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×