Xiaomi and data privacy—how secure are Chinese smartphones? (2024)

In a survey conducted by German tech portal “Elektronik Informationen,“ 84 percent of Xiaomi users reported uninstalling an app due to security concerns. This was the highest percentage among all manufacturers, indicating a “high perception of potential privacy risks“ among Xiaomi users.

Xiaomi and data privacy—how secure are Chinese smartphones? (1)

Data privacy and the Xiaomi browser (2020)

In 2020, the company gained public attention following a Forbes article that highlighted privacy concerns raised by Android expert Gabi Cirlig.

The article suggested that the Xiaomi browser, “Mi Browser,“ not only transmitted data to the Chinese conglomerate Alibaba without user consent but also tracked search queries, folder accesses, and viewed news articles, even in incognito mode.

The data was allegedly sent to servers in China and Russia, with weak encryption that allowed Cirlig to trace the user data transmitted by the Xiaomi device. Xiaomi spokespersons disputed Cirlig’s portrayal, stating that the data was anonymized and encrypted, and users had consented to the transmission.

Are Xiaomi smartphones secure?

Xiaomi smartphones are highly popular, ranking third in new smartphone sales in Germany with a market share of 13.7 percent (as of Q3/2023).

Xiaomi devices are commonly included in bundles with various network providers and are increasingly prevalent in the business sector, including T-mobile’s corporate mobile offerings.

Current status of data privacy and Xiaomi phones

As of the end of 2023, Xiaomi smartphones are considered secure. The company has made significant progress in enhancing the security of its devices over the years. Xiaomi regularly releases security updates and patches to address potential vulnerabilities.

Additionally, Xiaomi has developed its security suite, “MIUI Security,“ providing extra protection against malware and other threats. However, it is advisable to follow basic security practices, such as downloading apps from trusted sources and enabling device locks.

Xiaomi and data privacy—how secure are Chinese smartphones? (2)

Criticism of Xiaomi’s data privacy in 2021

The company faced criticism, not only for security concerns but also for shortcomings in sustainability and the production of eco-friendly phones.

In 2021, Xiaomi’s data privacy came under scrutiny following an investigation by the Lithuanian National Cyber Security Centre (NCSC). The Xiaomi smartphone Mi 10T 5G was found to have several issues related to data privacy (more details below).

Xiaomi payment mechanism vulnerability

In August 2022, Check Point identified a vulnerability in Xiaomi’s payment mechanism.

Xiaomi and data privacy—how secure are Chinese smartphones? (3)

The flaw affected Xiaomi devices with a MediaTek processor, allowing attackers to overwrite the current application with an outdated one to manipulate or disable payment transactions, including the widely used “WeChat Pay“ in China. Following Check Point’s notification, Xiaomi addressed the security flaw within the same month.

Is the corporate data on your employees’ mobile devices secure? Do your colleagues use private devices on the job? Our data security white paper clarifies the key questions. Click here for the free download.

What data does Xiaomi collect?

In 2021, the NCSC found that the Mi 10T, through the pre-installed “Mi” browser, transmitted data to the Chinese analytics startup “Sensors Data“ and Google Analytics. The server was located in Singapore. Additionally, the phone number was sent to Singapore via an invisible, encrypted SMS when the Xiaomi cloud was activated.

Accusation of censorship against Xiaomi

The NCSC also suspected that the Xiaomi smartphone could block content from certain groups, as a list of active groups from the political and religious spectrum was discovered in a configuration file named “MiAdBlackListConfig,“ used by multiple system applications. However, other analysts suggested that this was an ad-filtering feature.

Data security and Xiaomi smartphones

One year later, in 2022, the German Federal Office for Information Security (BSI) conducted its own tests following the NCSC investigations.

The BSI performed an in-depth examination of Chinese mobile phones, with a particular focus on the Xiaomi Mi 10T 5G, for potential security vulnerabilities and built-in censorship features.

How do you prevent problematic apps and services from accessing your sensitive company data? Our white paper clarifies the key questions. Click here for the free download.

Is my data secure with Xiaomi?

The BSI investigation found no abnormalities. In Germany, there were no identified filter lists or other anomalies.

Consumer advocates still urge caution: Stating that users should assume that Chinese smartphones transfer user data to Chinese servers, bringing the data within reach of Chinese government agencies.

Users should be especially skeptical if system apps request unnecessary permissions, such as a compass app suddenly requesting access to the World Wide Web.

Ban on Huawei and ZTE in the US

For data privacy reasons, some Chinese technology manufacturers, including Huawei and ZTE, were banned from the US market. The US Federal Communications Commission (FCC) deemed the national security threat posed by these companies so severe that the import of their products was prohibited—an unprecedented move in US history.

Xiaomi and data privacy—how secure are Chinese smartphones? (4)

Background: Individual state legislators are free to instruct national intelligence services and companies to collect information, as there is a lack of internationally binding regulations on this matter. This allows companies to be fundamentally compelled by their governments to engage in intelligence activities.

Xiaomi smartphones and data privacy for companies

In the corporate context, the potential espionage of economically significant data is relevant, as well as the data privacy of Xiaomi smartphones. Company smartphones should meet the highest security standards, whether companies opt for conventional purchases, popular smartphone leasing, or smartphone rental. If you’re interested in Xiaomi business phones, feel free to reach out.

Regardless of whether mobile devices come from Chinese manufacturers like Xiaomi, Oppo, or Huawei, or from Samsung and Apple: IT compliance, mobile security, and mobile threat defense should be considered from the outset.

Xiaomi and data privacy—how secure are Chinese smartphones? (2024)

FAQs

Are Xiaomi phones safe for privacy? ›

As of the end of 2023, Xiaomi smartphones are considered secure. The company has made significant progress in enhancing the security of its devices over the years. Xiaomi regularly releases security updates and patches to address potential vulnerabilities.

Are Chinese phones safe for privacy? ›

Using Chinese-made Android cell phones is a huge risk, given the security threats they pose. If you don't live in China and aren't using an Android device purchased there, you have less reason to be worried.

Can I trust Xiaomi with my data? ›

We promise to ensure the security of your personal information. In order to prevent unauthorized access, disclosure or other similar risks, we have implemented all physical, electronic and management measures and processes required by law to protect the information we collect from your mobile device and Xiaomi website.

Does Xiaomi send data to China? ›

The breach was attributed to Xiaomi devices sending data back to servers in China. The Taiwanese researcher's claims involved a zero-day vulnerability in Xiaomi's website, which supposedly allowed unauthorized access to Xiaomi's user account data.

Are Xiaomi phones safe for banking? ›

Researchers from Check Point Research (CPR) have discovered vulnerabilities in the payment system built into Xiaomi smartphones that could allow forging of payment packages or disabling the payment system directly, from an unprivileged Android application.

Are Xiaomi phones encrypted? ›

The secure storage in MIUI adopts AES-256 for encryption and decryption. The secure storage keys are derived from the hardware unique key (HUK) and are invariably stored in the device's TEE.

Which phone has highest privacy? ›

What Are the Best Smartphones for Security and Privacy?
  1. 4Freedom Mobile. At the core of 4Freedom Mobile's offerings is its dedication to privacy and security. ...
  2. Google Pixel Series (Google) ...
  3. Samsung Galaxy Series (Samsung) ...
  4. BlackBerry Key Series. ...
  5. Fairphone.
Apr 16, 2024

Does China have data privacy? ›

The Personal Information Protection Law (PIPL), which went into effect in November 2021, gives Chinese data subjects new rights as it seeks to prevent the misuse of personal data. Two months earlier, the Data Security Law (DSL) came into force.

Are there any cell phones that protect privacy? ›

The Blackphone PRIVY 2.0 is the guardian angel of smartphones, offering an unbreakable fortress for your privacy and security from the moment you lay hands on it. Powered by a custom version of the Android OS, this phone boasts encrypted phone calls, video chats, and text messages as its default settings.

Can Xiaomi track my phone? ›

You can access and view the location of your devices via the Find Device function. Go to the Find Device page, and choose the device you want to locate. You can click the Find Location/Relocate button to see its current location. Once the device is located successfully, you can see its current location on the map.

Does Xiaomi have antivirus? ›

MIUI is a built-in security app installed on most Xiaomi devices that provides MI mobile security features like Antivirus Scanner, App Lock, Cleaner, Battery Saver, Network Firewall, Anti-theft, and Privacy Protection.

Why do people choose Xiaomi? ›

Low Price – Great Specifications

So, Xiaomi gives foremost importance to the pricing of its devices. Even its latest flagship smartphone Xiaomi Mi5 with premium features just costs under $400 (INR 25,000). Because its always better to sell a $100 product to 1000 people than a $1000 product to 100 people.

What is the rank of Xiaomi in China? ›

The annual shipments of these brands were 44.5 million, 43.9 million and 43.6 million units, respectively. Xiaomi held fifth place in the annual market with a 13% market share. Huawei, ranking sixth, saw its full-year market share jump from 8% in 2022 to 12% in 2023, with a year-on-year increase of 48%.

What is the difference between Xiaomi global and China phone? ›

The global version offers broader language support, pre-installed Google services, and wider band coverage. On the other hand, the China version may be more tailored to the Chinese market and requires additional steps to install Google apps.

Why is Xiaomi so successful in China? ›

"We want to sell as low as possible, instead of at a premium price." Creating premium smartphones and selling them at low price points is what made Xiaomi find success throughout China, and the same strategy would later be its secret to winning over India's consumers.

Can Xiaomi phones be tracked? ›

If your device is missing

Go to https://i.mi.com and turn on Lost mode for this device in "Find device". Other people won't be able to access your device once Lost mode is on. In case they flash the device, all data on it will be erased. You'll be able to reactivate the device when you find it.

Does Xiaomi have private space? ›

MIUI provides users with a series of private space functions such as private text messages, private photo albums, private folders and private notes.

Does Xiaomi have hidden apps? ›

Method 1: Hide Apps on Redmi Using Hide Apps Feature

Step 2: Enable the Button after the app name to Hide that App. Hooray! With these simple two steps, you have successfully hidden the Android App on a Redmi device.

Top Articles
Latest Posts
Article information

Author: Edmund Hettinger DC

Last Updated:

Views: 6585

Rating: 4.8 / 5 (78 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Edmund Hettinger DC

Birthday: 1994-08-17

Address: 2033 Gerhold Pine, Port Jocelyn, VA 12101-5654

Phone: +8524399971620

Job: Central Manufacturing Supervisor

Hobby: Jogging, Metalworking, Tai chi, Shopping, Puzzles, Rock climbing, Crocheting

Introduction: My name is Edmund Hettinger DC, I am a adventurous, colorful, gifted, determined, precious, open, colorful person who loves writing and wants to share my knowledge and understanding with you.