Expert claims hacking Xiaomi server, firm calls it hoax

Image
Press Trust of India New Delhi
Last Updated : Oct 30 2014 | 7:21 PM IST
A Taiwanese cyber security expert has claimed to have compromised server of China based smartphone maker Xiaomi but the company called it a hoax.
"Chen Huang is an independent Taiwanese Security Expert. Session Abstract: In this session Taiwanese Researcher will demonstrate how Xiaomi Phones have been sending device data and personal data of Xiaomi Phone user to Chinese Servers," said the website of Ground Zero Summit.
"The Researcher will also release Server Logs, Mi Account username, Emails and passwords of millions of Xiaomi users which have been obtained using a Zero Day flaw in the Xiaomi Servers," the webpage added.
Xiaomi is now world's third largest smartphone maker after Samsung and Apple, as per the latest IDC report.
When contacted, Xiaomi' Head of India Operations Manu Jain said: "We have verified that the zero-day data breach allegation made by security researcher Chen Huang and the Ground Zero Summit organising committee reported by The Hacker News on October 30, 2014 is a hoax."
Jain said that the zero-day vulnerability reported by the cyber security researcher Chen Huang is a deliberate falsehood and Xiaomi is taking the necessary legal action against the parties involved.
Jain in his reply admitted that the company's user account file was leaked in May this year.
"To date, throughout Xiaomi's history, there has only been one incident in which a two-year-old user account file was leaked in May 2014," Jain said.
He said that leaked information was from user accounts registered before August 2012 in an old version of the Xiaomi user forum website.
Meanwhile, organisers of the summit, which is to be held here next month, said that they have put Cheng's session on hold till the time Xiaomi completes its investigations.
"Xiaomi representatives contacted and requested us regarding the session. We have decided to withhold session till the time Xiaomi investigates data breach and accusations and works with the researcher to fix it," Indian Infosec Consortium CEO Jiten Jain said.
The summit's website shows former chief of Indian Army and Minister of State for Development of North Eastern Region General VK Singh, Home Ministry Joint Secretary Nirmaljeet Singh Kalsi, Enforcement Directorate Special Director Karnail Singh and NTRO Director of Cyber Security Operations Alok Vijayant will be among key speakers.
Xiaomi entered the Indian market in July through tie-up with e-Commerce major Flipkart. It is estimated that the firm has sold over 1.5 million devices so far.
Earlier, Indian Air Force had issued an advisory asking its personnel and their families to desist from using Chinese 'Xiaomi Redmi 1s' phones as they are believed to be transferring data to their servers in China and could be a security risk.
However, Xiaomi said the company collects data only with the user's permission to offer specific services like cloud and will set up a server in India next year.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Oct 30 2014 | 7:21 PM IST

Next Story