{"id":295,"date":"2018-03-24T18:31:54","date_gmt":"2018-03-24T18:31:54","guid":{"rendered":"http:\/\/thomas.goirand.fr\/blog\/?p=295"},"modified":"2018-03-24T22:33:29","modified_gmt":"2018-03-24T22:33:29","slug":"about-the-privacy-of-the-unlocking-procedure-for-xiaomis-mi-5s-plus","status":"publish","type":"post","link":"http:\/\/thomas.goirand.fr\/blog\/?p=295","title":{"rendered":"Privacy breaches when unlocking a Xiaomi&#8217;s Mi 5s plus"},"content":{"rendered":"<p>My little girl decided the old OnePlus One of my wife had to take a swim in the toilets. So we had to buy a new phone. Since I know how bad standard ROMs are, I looked-up in the LineageOS list of compatible OS, and found out that the Xiaomi&#8217;s Mi 5s plus was not too bad, and we bought one. The phone itself looks quite nice: a 64 bits fast processor, a huge amount of RAM, nice screen, etc. Then I tried the procedure for unlocking&#8230; because I care about privacy, and I knew the Chinese Xiaomi ROM is full of spyware (the phone was purchased in China). Though what I didn&#8217;t know is that the unlock procedure (needed before changing the ROM) is itself is full of privacy breaches. Let me give you the details.<\/p>\n<p>First, you got to register on Xiaomi&#8217;s website, and request for the permission to unlock the device. That&#8217;s already bad enough: why should I ask for the permission to use the device I own as I am pleased to? Anyway, I did that. The procedure includes receiving an SMS. Again, more bad: why should I give-up such a privacy thing as my phone number? Anyway, I did it, and received the code to activate my website account. Then I started the unlock program in a virtualbox Windows XP VM (yeah right&#8230; I wasn&#8217;t expecting something better anyway&#8230;), and then, the program tells me that I need to add my Xiaomi&#8217;s account in the phone. Of course, it then sends a web request to Xiaomi&#8217;s server (it refused to work unless I connected the phone to WiFi). I&#8217;m already not happy with all of this, but that&#8217;s not it. After all of these privacy breaches, the unlock APP tells me that I need to wait 72 hours to get my phone to account association to be activated. Since I wont be available in the middle of the week, for me, that means waiting until next week-end to do that. Silly&#8230;<\/p>\n<p>Let&#8217;s recap. During this unlock procedure, I had to give-up:<\/p>\n<ul>\n<li>My phone number (due to the SMS).<\/li>\n<li>My phone ID (probably the EMEI was sent).<\/li>\n<li>My email address (truth is: I could have given them a temporary email address).<\/li>\n<li>Hours of my time understanding and run the stupid procedure, and I can&#8217;t even finish it in a single day.<\/li>\n<li>My policy of not using Windows. I also consider that using Windows is a privacy breach, though here I have a way to roll-back the Virtualbox image, and I only use it for this kind of bad software, so privacy wise, it&#8217;s kind of fine, because I&#8217;m used of this trick. The real issue here is that, to unlock freedom on that phone, one must use a proprietary OS.<\/li>\n<\/ul>\n<p>So my advice: if you want an unlocked Android device, do not choose Xiaomi, unless you&#8217;re ok to give up the above. It&#8217;s probably fine to pay a little bit more and reward the maker of a phone if the unlock experience isn&#8217;t that bad.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>My little girl decided the old OnePlus One of my wife had to take a swim in the toilets. So we had to buy a new phone. Since I know how bad standard ROMs are, I looked-up in the LineageOS list of compatible OS, and found out that the Xiaomi&#8217;s Mi 5s plus was not [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"http:\/\/thomas.goirand.fr\/blog\/index.php?rest_route=\/wp\/v2\/posts\/295"}],"collection":[{"href":"http:\/\/thomas.goirand.fr\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/thomas.goirand.fr\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/thomas.goirand.fr\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/thomas.goirand.fr\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=295"}],"version-history":[{"count":6,"href":"http:\/\/thomas.goirand.fr\/blog\/index.php?rest_route=\/wp\/v2\/posts\/295\/revisions"}],"predecessor-version":[{"id":301,"href":"http:\/\/thomas.goirand.fr\/blog\/index.php?rest_route=\/wp\/v2\/posts\/295\/revisions\/301"}],"wp:attachment":[{"href":"http:\/\/thomas.goirand.fr\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=295"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/thomas.goirand.fr\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=295"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/thomas.goirand.fr\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=295"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}