Xiaomi Apologises For Unauthorised Personal Data Transmission

Chinese smartphone manufacturer Xiaomi has apologised for what it describes as a “loophole” in its cloud messaging service that sends a phone, SIM and contact information to a server in China without user consent.

Security firm F-Secure tested a Xiaomi RedMi 1S smartphone fresh out of the box and without any account setup or cloud service connection. A SIM card was inserted into the device, which was then connected to a Wi-Fi network and GPS functions were allowed.

Researchers added a new contact to the phone book, sent and received an SMS and MMS message and made and received a phone call. They detected that the phone sent operator information, the device’s IMEI number and phone number to a server known as ‘api.account.xiaomi.com’, along with the phone number entered into the phone book and the content of the SMS message sent.

Xiaomi data transfer

The researchers then logged into the ‘Mi Cloud’ service and repeated the same steps, witnessing that this time, the ISMI details that identify the SIM card were also sent to the same server.

Xiaomi vice president Hugo Barra says this behaviour was triggered by the MIUI cloud messaging service which attempts to deliver texts over a mobile data connection to save money. MIUI is switched on by default and the reason for the data transfer was so an SMS could be sent if the intended recipient was offline.

In a Google+ post, the former vice president for product management for Android at Google, says an over-the-air update has been issued to affected smartphones and promises the messaging service will no longer be enabled by default.

“As we believe it is our top priority to protect user data and privacy, we have decided to make MIUI Cloud Messaging an opt-in service and no longer automatically activate users,” he says. “We apologize for any concern caused to our users and Mi fans.”

Xiaomi will hope that the revelation does not damage its reputation abroad given it currently enjoying great success in its homeland. The company currently commands 27 percent of the Chinese smartphone market, according to Kantar Worldpanel ComTech, ahead of Samsung on 21.1 percent.

What do you know about IT in China? Take our quiz!

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

6 hours ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

8 hours ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

9 hours ago

VW, Rivian Launch Joint Venture, As Investment Rises To $5.8 Billion

Volkswagen and Rivian officially launch their joint venture, as German car giant ups investment to…

10 hours ago

AMD Axes 4 Percent Of Staff, Amid AI Chip Focus

Merry Christmas staff. AMD hands marching orders to 1,000 employees in the led up to…

13 hours ago

Tesla Recalls 2,431 Cybertrucks Over Propulsion Issue

Recall number six in 2024 for Tesla Cybertruck, and this time the fault cannot be…

14 hours ago