Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not proof, but my Xiaomi A3 (Android One) European version has a couple of China Mobile packages and what I suspect is China Telecom.

It also has com.wapi.wapicertmanage, WAPI as in World Association of Professional Investigators! No idea what it does but from the name, it sounds it's security related.

Do these belong on an Android One phone? Do these fit with the impression that most people seem to have about Android One?



The WAPI you're looking for is https://en.wikipedia.org/wiki/WLAN_Authentication_and_Privac.... Which, AFAICT, would allow the phone to connect to some Chinese wi-fi APs that were manufactured+configured to use the WAPI encryption standards.

You know how sometimes, cell ISPs ban certain baseband firmwares from connecting to their network, such that you have to upgrade your phone's firmware before it can connect? Now what happens if you live in some college dorm that has only WAPI-configured wi-fi APs? Guess your phone's a brick until you can find wi-fi somewhere else!

In other words, this is kind of a crucial package for a phone you're going to be using in China.

(But also, it's government-mandated that phones released in China have WAPI support.)


Thanks, that makes much more sense. I only looked at the domain name matching the package name. I'd still like to remove it but it feels much less worrying.


Hmm, looks like whatever that WAPI package is, it's not just on Xiaomi devices, I see it mentioned as bloatware on a OnePlus 7 Pro[1]

1: https://forum.xda-developers.com/oneplus-7-pro/how-to/debloa...


I don't know whether it's actually Chinese (OnePlus is by the way), not that it matters anyway. It has no business being on my phone and doesn't match with what most people seem to think Android One is.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: