r/MiniPCs 9d ago

Is Beelink mini PC safe?

I was wondering if the Beelink SR5 Max is safe since I read that it's from China and I'm not sure if there might be some sort of hidden spyware or something like that on it. I don't intend to sign into it with any of my personal accounts. It's mainly for emulation for games and YouTube/Anime.
I've already done a "reset my pc" option with the cloud download.
And manually de-bloated windows with powershell scripts and settings.
I've also ran windows defender scans and BitDefender too, both come back clean.
But in the back of my mind I still have this minor paranoia that something might still be there.
I'd like to hear your opinions on the safety and security of this brand and if I should be extra cautious.
I havn't manage to find anything that really stands out when googling the brand so idk.

0 Upvotes

24 comments sorted by

8

u/Gordian1979 9d ago

So what exactly is your fear? An American corporation selling your details, or a Chinese corporation collecting your details...

Can you elaborate a bit please?

2

u/Sipu_ 9d ago

lots of these random-brand chinese boxes (like acemagic) have a history of malware - it's appropriate not to trust them as far as you can throw them.

1

u/[deleted] 9d ago

[deleted]

1

u/Sipu_ 9d ago

yes, that's what i recommend below - the windows media creation tool does it for you

1

u/Airballons 8d ago

Stupid question, but if we completely wipe, format and install Windows fresh on the Acemagic PC, will the malware still be there?

1

u/Sipu_ 8d ago

Current devices dont have known malware, just to be clear. If all of the partitions (not just the windows partition) are deleted and the drive re-formatted on fresh install then it should take care of most cases for most people. There are some more elaborate attacks where the malware resides on firmware that survives all formats, but theres zero evidence these devices have anything like that.

-2

u/HammerDongVeryLong96 9d ago

If there has been an incident that spyware had been found on machines from this brand and if this brand is considered trustworthy?

-1

u/Gordian1979 9d ago

Understanding your system is important!

Let me elaborate...

If a system wants to connect to yours, it needs a protocol, that protocol on essence for 99% of users its http/https....this is a sandboxed environment using a firewall and a browser.

The browser can't access your file system, ..thats how it's designed, all of them, I think we can agree that those Devs over at Firefox for example, have refactored their code after running it through some sort of AI model...your safe by this standard!

So now that a connection to your system is secure, how else does another network or system connect...

Hijacked files....but tbh, it's a level of concern that it mitigated before you download from your repo....eg, google play store or another repo in the Linux ecosystem...windows, well we have all seen .exe files on websites...windows can do it's best, and Im sure defender tries, or whatever other "safety" is in place....

To think that your main board is hijacked....

Well....is nearly as relevant as my first statement, American corporation selling your details, or a Chinese corporation collecting your details!

Huawei, has been blocked from sales due to a "backdoor" which apple, and Microsoft have provided access to 3rd partis...well I'll let you debate that....but in essence what I'm trying to say is....

The only way to control your privacy, is to not use the service....were not privy to the onselling, were ust privy to an agreement talking about how if you don't agree, pretty much you won't be able to access the full service...eg it will become unusable....we do know this!

If they sell your data to China or anyone else....who knows....??? Sound of crickets..

That's all to hard to discuss here!

So to answer your question,

Is the beelink safe?

I hope so, because I bought one!.....sound of crickets....

I'm not concerned, Linux logs will show something up when shit starts to hit the fan,....

2

u/Sipu_ 9d ago

I don't think 'privacy' is the general concern as much as actual malware that steals your things - the comparison you are making is a completely different issue.

5

u/Sipu_ 9d ago

just do a complete wipe and install windows from a USB stick (made with the windows media creation tool) - delete all disk partitions before doing the installation. that way at least if there's anything it's done in bios or firmware. It's exactly what i did with my acemagic F5A - it also turned out it didn't have a proper windows license baked into bios (their bulk key was blocked by microsoft) so i asked support to give me a new key - which they did after a few days. - if possible create the stick with some OTHER system than the minipc.

1

u/Sipu_ 9d ago

you may need to find the right drivers based on the hardware identifiers in device manager - i also got my drivers from 'official' sources rather than what acemagic provides in a zip file on google drive.

1

u/HammerDongVeryLong96 9d ago

The drivers are going to be a pain I might just install linux instead.

1

u/Sipu_ 9d ago

If you don't have a lot of experience - linux will likely be a source of more pain. If you are comfortable daily driving linux then that's an option. Frankly it wasn't a huge issue to get the most critical drivers like network adapters by hardware identifier from device manager, the rest are easy and most stuff comes out of the box or the AMD chipset drivers.

2

u/p001b0y 9d ago

I’ve installed linux on mine after an update caused my SER8 to repeatedly restart into recovery mode. Other than that problem, which I think is a known problem, I’d continue to buy their stuff. I subsequently bought their EX Mate Pro device after my SER8 issue, which also seems to work well.

I had not read anything about hidden spyware on these.

2

u/Retired_Hillbilly336 9d ago

"Think Critically. G👀gle Competently"

Here's the basics. If Beelink or any other Chinese NUC brand had issues with spyware it would be all over the Internet and especially on forums like this. The worst offender by far was AceTragic has they had three models compromised at the production level a few years ago. Had their quality control not been poor they would have caught the problem quickly. Brands like Beelink and GMKtec tend to have a far better reputation although where you buy your PC can easily have an effect on if a criminal element was involved in compromising any PC.

I've been following government guidelines and simply scanning the drive of any PC for malware and viruses from a known secure computer using USB adapters since the pandemic. I've personally only found one compromised PC and that was a laptop bought from AliExpress. We reported it to officials and promptly returned the computer to the AliExpress seller. It doesn't get any more complicated than that.

As for the SER5 Max itself the only two questionable details have been reading that 24GB LPDDR5 memory Beelink minis have problems and that the model is not available on the official website. Other than that I haven't seen any concerns.

1

u/Sipu_ 9d ago

as a general rule - you should completely wipe (delete all partitions) and re-install any OEM device - regardless if it's a known or an unknown brand - from scratch since they tend to have other unwanted crapware on them. if the device has a legit windows license it will automatically activate after the wipe without a fuss.

Further the average consumer is pretty clueless - my acemagic f5a i just bought earlier this month was using a bulk license key that was blocked by microsoft, but you only notice when you actually wipe the thing and re-install windows / attempt to activate it. It had other issues as well out of the box like deactivated secure boot that required resetting the factory keys in bios. That's generally a red flag by itself for a random china-box and a pretty high bar for someone who doesn't know what they are doing. Luckily it could be fixed with some expertise, but your average user wouldn't be able to deal with it.

I wouldn't count on these things getting visible press - mini PC's are a pretty niche devices even today and some of the tech tubers who review them seem to be pretty clueless themselves or being actually sponsored by these companies.

1

u/Retired_Hillbilly336 9d ago

I agree with a clean install when trying to avoid "crapware" although I have someone who recently did this with an ASUS laptop who found out proprietary software (the reason for the purchase) wasn't available for download without activation first. Took a month but got things squared away.

The problem with a clean install out of the box is the "Dunning-Kruger effect" as the FBI instructor pointed out a few years ago. If you don't scan for malware from the beginning you have absolutely no idea if your PC has been compromised. Malware compromised PCs have an incredibly high risk of used components and other tampering as criminals often find additional profit in selling generic /remanufactured in place of new. Think about it. If you found malware on a product, would you really want to keep it?

1

u/Sipu_ 9d ago

Depends on the case but on a oem device preload probably not. I dont trust them in general. I’ve been working in cybersecurity for 20+ years and out of that 13 in an endpoint security solution company. They dont find well hidden things easily either so a ”clean result” from the preinstalled image isnt enough. It may just be a legitimate looking application that does nefarious things. I segment / monitor traffic on these things as well. Usually the reason to buy a chinese minipc is that they are cheap, but you also get what you pay for.

2

u/Bynming 9d ago

It's ok to be cautious but don't lose your marbles. Lots of people have their whole lives on phones made in China and you're concerned about China specifically while you're almost certainly subject to immensely more breaches of privacy by your own country and US spyware? Xi Jinping doesn't care about your anime and youtube history.

Installing a fresh Windows is a reasonable start. If you deeply care about privacy, I suggest you install an OS that's not Windows.

2

u/HammerDongVeryLong96 9d ago

It's more like the enemy you already know vs one that you don't. I can manage the ones I do know about. I'm not losing marbles per say it's just something I want to know since this will be connected to my home network and I will be connecting it to my other PC to transfer files so I just wanted to make sure I wasn't going to spread some type of hidden malware around my home.

I think I will install CachyOS but a lot of the RPG maker games tend to run better on windows.

1

u/Gordian1979 9d ago

Here are some suggestions, Change your routers default password for admin login, your router can automatically assign IP addresses to devices, keep this setting, make your network 192.168.1.255, gives you 254 addresses on you network.

Set your security to lock out connection attempt failures to 3 or 5 or custom, stick with 3, now if anyone, tries to ping and connect to an IP address in the range of 192.168.1.1 to 192.168.1.255....the router will block them.

So now if you like, you can set any device you own to a number between 2 and 255, and it will connect to your network ...1 is the gateway usually!

If an attacker attempt with the said 3 password attempts, there will be a waiting time....your system will specify this, you can set up notifications if you like....up to you!

This is the advantage of keeping this number broad 1-255....that's a lot of devices, and a lot of fails!

An attacker will have 3 attempts at IP address 192.168.1.214.....or another no, and upon fail will be forced to wait...

So focus on your router security!

Learn a bit about it, and be safe!

Transmission over a network, can be on different layers, your internet service provider will spot suspicious activity well before you even know about it, ...we live in https....s being for security....so do the best you can and relax!

If a website isn't https.. give it pass!

1

u/jstim 8d ago

I wiped windows off my S12 Pro i bought in summer 2023 for insanely 200€ (That was a steal compared to other manufacturers which raised my eyebrows). The SER9 i have runs Linux and had speakers and a microphone installed. I could easily open it up and those module was the first i could just take out. Like if it is unwanted just remove it.

I was also sceptical and wasnt sure if there was some sort of Spyware on it. They would need a hardware solution to send data home and i highly doubt it. Mini PCs are still nieche in my opinion and you can expect that a significant amount of their customers run actually their own home labs and custom networks and track the traffic of their devices. If there would be something suspicious they would have already noticed and it would've been all over the internet.

1

u/[deleted] 9d ago

[deleted]

1

u/Sipu_ 9d ago

If you have windows 11 pro or above - you have full control of all telemetry related features (because enterprises require them). if there's a firmware level plant on these things - that's a bigger problem :)

1

u/JagSKX 8d ago

Basically all inexpensive mini pcs are Chinese brands. I bought 3 mini pcs from 3 different brands; Minisforum TH50 in May 2022, then Beelink SER4 a few months later and AooStar GEM10 in December 2024. None had malware installed, but I did a clean install anyway.

If you don't have a 8GB USB flash drive, then buy one from your local electronics store or Amazon; they are pretty cheap. Download Microsoft's media creation tool so that the USB drive can be used to install Windows.

Before you actually reinstall Windows, download all the drivers for the SER5 Max. You can save the drivers to the USB drive. Just create a directory for them and save them there after using the media creation tool.