Tired of ads? Enjoy an ad-free experience by signing up.
Terence Lee · · 2 min read

How Xiaomi installs apps without telling you

Mi Note is the giant Xiaomi phone you can’t have (REVIEW)

Xiaomi started making Android-based phones in 2011.

A lot of invisible things happen on our smartphones. But somewhere, someone cares enough to probe deeper.

Security blog The Hacker News reported how computer scientist Thijs Broenink found out that smartphone maker Xiaomi can silently install apps on its phones without user interaction.

He discovered a pre-installed app, called AnalyticsCore.apk, which gets updates in the background and reappears after you delete it.

The app checks for new updates once a day. “While making these requests, the app sends device identification information with it, including phone’s IMEI, Model, MAC address, Nonce, Package name as well as signature,” the article reports.

Xiaomi claims the self-upgrade feature was meant to ensure a better user experience.

Thijs questions if this process is secure. He claims no validation took place to ensure the correct app was installed, and that the app updates happened over a non-secure HTTP connection.

As a result, Thijs posits that the process exposes users to malicious and invisible app installs, either from Xiaomi or other sources, as well as man-in-the-middle attacks.

Xiaomi has responded to these claims. “AnalyticsCore is a built-in MIUI system component that is used by MIUI components for the purpose of data analysis to help improve user experience, such as MIUI Error Analytics,” a spokesperson tells Tech in Asia. MIUI is the customized version of Android used in all Xiaomi phones.

Xiaomi added that the self-upgrade feature was meant to ensure a “better user experience.”

In addition, “as a security measure, MIUI checks the signature of the Analytics APK file during installation or upgrade to ensure that only the APK file with the official and correct signature will be installed.”

Because of that, it’s unlikely other apps can be installed on the phone through that method.

Addressing the HTTP connection issue, Xiaomi says that the more secure HTTPS connection has been enabled since April with MIUI version 7.3.

However, this would mean a loophole existed before that.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

TIA Writer

Terence Lee

I like analyzing and digging into the real goings-on in the tech industry. Holds these crypto: BTC, Eth, Matic