The National Communications Commission (NCC) is planning to establish a certification system for mobile phone security following reports that Chinese smartphone vendor Xiaomi automatically sends personal information to its servers in Bejing without first securing the consent of users.
A story published in a blog post of Finnish security company F-Secure Corp indicated that Xiaomi smatphones’ built-in text-messaging application, MIUI, can send users’ information to the company’s servers in Beijing without their approval.
Because of the loophole, the report said that the Chinese vendor can access users’ mobile phone number, the international mobile equipment identity (IMEI) code as well as the SIM card number.
The international mobile subscriber identity code would be exposed too if the user signs on to Xiaomi’s cloud service, the report said.
Similar to Apple Inc’s iMessage service, MIUI allows users to send text messages through the Internet rather than through telecoms’ networks.
The story was subsequently picked up by Taiwanese media outlets, with Xiaomi users in Taiwan reportedly topping 400,000. The Beijing-based smartphone vendor first denied the reports, but later apologized for the unauthorized data collection.
It added that the messaging system would only be activated on an “opt-in” basis and personal information would be encrypted and would not be stored on its servers.
The commission said it told the Chinese company to inspect all types of phones — not only the two mentioned in the F-Secure blog — that it sells in Taiwan and determine if they have the same issue.
“We have notified them that they should provide a written explanation of how they plan to address the issue,” said Lo Chin-hsien (羅金賢), director of the commission’s Resources and Technologies Department. “We will ask them to come in and answer questions if necessary.”
The commission is to meet with other mobile phone manufacturers soon to discuss how they address information security issues, Lo said.
He added that the Executive Yuan has determined that the applications built into mobile phones will be tested by the commission, while applications downloaded via mobile phones will be supervised by the Industrial Development Bureau.
While the commission has a certification system for mobile phone interfaces, batteries and other specifications, it does not have one yet for information security.
It is aiming to establish an information security mechanism by the end of next year, he said.
“Currently, there is no country in the world that demands that mobile phone manufacturers have national certifications for information security. We can only encourage mobile phone manufacturers to take such certification when it becomes available,” he said.
Lo said the mechanism would not only target mobile phones produced in China, but it would apply to other manufacturers as well.
AGGRESSION: China’s latest intrusions set a new benchmark for its ‘gray zone’ tactics and possibly a new pattern that it would attempt to normalize, a researcher said China’s latest military exercises represent a new challenge to Taiwan’s legal authority to demarcate its borders in the Taiwan Strait, a defense expert said, adding that the fleets in the latest exercises were likely the most powerful the People’s Liberation Army (PLA) ever assembled. The PLA conducted military exercises from Sunday last week to 6am on Friday, which encompassed large swathes of the western Pacific, including the Taiwan Strait and waters off the Philippines and Guam, National Policy Foundation associate research fellow Chieh Chung (揭仲) said on Friday. The Ministry of National Defense said that it detected 70 warship and 162 aircraft
DOMESTIC MARKET: To protect the livelihoods of local egg farmers, the government adopted a new method for releasing imported eggs, the agriculture minister said More than 54 million imported eggs will be disposed, as their expiration date has passed, Minister of Agriculture Chen Chi-chung (陳吉仲) said yesterday. Chen made the remarks at a news conference in Taipei, explaining the flow of imported eggs following recent controversies regarding the products. The ministry introduced a special egg import program to address a nationwide egg shortage earlier this year. However, controversies have risen in recent weeks. These included an accusation that the government helped some egg importing companies over others, eggs imported from Brazil that had an incorrect expiration date, and egg shipments from Brazil that were found
PACIFIC OCEAN: Defense experts have warned that the ‘Shandong,’ China’s second largest aircraft carrier, poses a serious threat to eastern Taiwan’s defenses The drills conducted by the Chinese aircraft carrier Shandong in the Western Pacific last week were more aimed at showcasing China’s military capabilities to the US rather than toward Taiwan, a Taiwanese defense expert said yesterday. Lin Yin-yu (林穎佑), an assistant professor at Tamkang University’s Graduate Institute of International Affairs and Strategic Studies, said the drills which involved dozens of warplanes sought to test China’s anti-access and area denial capabilities should the US and its allies attempt to interfere in a cross-strait conflict. Lin said that the latest Chinese drills coincided with a joint maritime exercise conducted by the US, South Korea
Thousands of bottles of Sriracha have been returned or destroyed after the discovery of excessive sulfur dioxide, a bleaching agent, the Food and Drug Administration (FDA) announced on Tuesday. About 12,600 bottles totaling 9,991.8kg of the hot sauce imported from the US by Emporium Corp (河洛企業) were flagged at the border for containing illegal levels of sulfur dioxide, the FDA said in its regular border inspection announcement. Inspectors discovered 0.5g per kilogram of the common bleaching agent and preservative, higher than the 0.03g permitted, it said. As it is the first time within six months the product has been flagged, Sriracha products from