Notices


Reply
Thread Tools
onethreealpha's Avatar
Posts: 434 | Thanked: 990 times | Joined on May 2010 @ Australia
#11
Originally Posted by danramos View Post
Just because you're paranoid doesn't mean they're not out to get you.
I'm not paranoid........... who said I am?
__________________
Always remember you're unique, just like everyone else.
 

The Following User Says Thank You to onethreealpha For This Useful Post:
jd4200's Avatar
Posts: 451 | Thanked: 424 times | Joined on Apr 2010 @ England
#12
Originally Posted by festivalnut View Post
what about the anti-theft app that was sending data to a russian email address? and the maintainer was nowhere to be seen when people found out and wanted to ask a few questions about that...
Wow, I had my suspicions about that app. do you have a link to a source on the claims?
 
Saturn's Avatar
Posts: 1,648 | Thanked: 2,122 times | Joined on Mar 2007 @ UNKLE's Never Never Land
#13
Originally Posted by festivalnut View Post
what about the anti-theft app that was sending data to a russian email address? and the maintainer was nowhere to be seen when people found out and wanted to ask a few questions about that...
From what I know, imhere was using an account owned by the developer in a Polish mail server to forward massages from all mobiles.

Nobody confirmed ever a misuse of the data. The developer disappeared leaving a broken and closed source version in devel that many had problem unistalling.
 

The Following User Says Thank You to Saturn For This Useful Post:
Posts: 1,341 | Thanked: 708 times | Joined on Feb 2010
#14
Since N900 uses deb-packages and not GPG-signed rpm-packages, and people, even and because even developers install software just by wget'ing it and 'dpkg -i'ing it without any way checking the authenticity of the package
and
because there is tools like DNS-spoof and Mallory,
I think almost all N900 users are backdoored long ago.

Sadly, I think, all Linux-users also.
There is an interest, it is cost-effective for the 3 letter agencies and there is examples.

It would be quite huge job to check there is no well hidden Thompson Trojan's in Linux (and Maemo) -code.

Anyway, after these "few" beers :-), I think everything Google knows, knows also these infamous three letter agencies. Information is power and it is never deleted. It is hard to find services or people who wouldn't be connected to Google somehow nowadays and it is practically impossible to stay anonymous in Internet.
 
Guest | Posts: n/a | Thanked: 0 times | Joined on
#15
Originally Posted by HellFlyer View Post
Hence, OPEN source RULEZ ...
The FBI thinks so too...

edit: zimon beat me to it by like 12 minutes.

There are other backdoors supposedly out there, I've always wondered about one that was surrounding the Unix BIND libraries - there seemed to be something around that area that was once questioned, then disappeared back in the early 2000's.

Last edited by gerbick; 2010-12-19 at 01:42.
 
danramos's Avatar
Posts: 4,672 | Thanked: 5,455 times | Joined on Jul 2008 @ Springfield, MA, USA
#16
OPEN YOUR EYES, PEOPLE!
__________________
Nokia's slogan shouldn't be the pedo-palmgrabbing image with the slogan, "Connecting People"... It should be one hand open pleadingly with another hand giving the middle finger and the more apt slogan, "Potential Unrealized." --DR
 

The Following User Says Thank You to danramos For This Useful Post:
Scottlfa's Avatar
Posts: 124 | Thanked: 38 times | Joined on Feb 2010 @ Gaffney, South Carolina, USA
#17
I would think if enough demand is there we could do what the others won't or can't ... make a firewall app. Then of course you can be as closed off as you want and would know when the snitch runs for another company with your personal information.

That's the true beauty of the N900
__________________
Need more apps for the N900?
Qole's Easy Debian lets you choose from some 25,000 precompiled packages running safely on top of Maemo!
 

The Following User Says Thank You to Scottlfa For This Useful Post:
Posts: 671 | Thanked: 1,630 times | Joined on Aug 2010
#18
Originally Posted by Scottlfa View Post
I would think if enough demand is there we could do what the others won't or can't ... make a firewall app. Then of course you can be as closed off as you want and would know when the snitch runs for another company with your personal information.

That's the true beauty of the N900
Nailed it there.

<Rather than pointlessly b1tch, moan and complain that
the n900 is compromised and not worth the effort>
An app could be created to address the issue.

I would guess that this could never be done completely
on an iPhone or an Android because backdoor comms
are probably invisible to apps inside their prisoncells.

The n900 could have just such an app to blockade
or at least inform the owner of any nasties being broadcast.

I thought wireshark would be able to show anything being sent,
perhaps there would be an easier way though,
since you would not necessarily need to listen to
anything other than outgoing messages.
For the truly paranoid it might be necessary to do some kind of
traffic monitoring on the inputs to the GSM hardware
to make sure there is nothing extra being generated
beyond what the system network actually generates.
Wish my broken unit was healed so I could check on this..
__________________
Three n900s: One for stable working platform,
One for development testing Chopping Onions
One for saltwater immersion power testing resurrected ! parts scavenging

My Mods for Wonko's Advanced Clock Plugin:
ISO8601 clock mod and Momental_IST clock mod

Printing your Email with the N900
 
Posts: 1,341 | Thanked: 708 times | Joined on Feb 2010
#19
The start would be if developers would start to GPG-sign their packages with debsig.

Then at least there would be some traces where the backdoor or other type of Trojan horse came from.

It is a fact, people has and will be installing deb-packages also out of apt-repositories.

And we could have something else in /etc/dpkg/dpkg.cfg
# Do not enable debsig-verify by default; since the distribution is not using
# embedded signatures, debsig-verify would reject all packages.
no-debsig
Meego will hopefully fix this problem with rpm-package system, which usually has signed packages granted.

Last edited by zimon; 2010-12-21 at 18:33. Reason: Added a link how rpm package signing is initially set up for automatic signing.
 

The Following User Says Thank You to zimon For This Useful Post:
Reply


 
Forum Jump


All times are GMT. The time now is 10:07.