Active Topics

 


Reply
Thread Tools
Posts: 50 | Thanked: 17 times | Joined on Apr 2014
#1
I want to start post about increasing secure of Sailfish OS for end-users.

Many geeks are using on their phones Cyanogenmod, becouse it is provide feature to delete android permitions of installed apps.

Is any way to delete permitions of Android apps in Sailfish OS? Is more interesting proprietary applications, but I do not want to allow applications to do everything in the system that they have requested(try to remember story about Skype, apparmor, and reading /etc/shadow).

If way is, is it usable for everyday usage?

Also, many geeks encrypte SMS, contacts, emails on their Android and iOS phones. Can I have same feature on Sailfish OS?
If you will lost your phone, bad guys can read your files, change passwords in your accounts (if it save on your losted device), and have fun with your torments.

Last edited by sHaggY_caT; 2015-06-30 at 13:37.
 

The Following User Says Thank You to sHaggY_caT For This Useful Post:
Community Council | Posts: 4,920 | Thanked: 12,867 times | Joined on May 2012 @ Southerrn Finland
#2
Originally Posted by sHaggY_caT View Post
If you will lost your phone, bad guys can read your files, change passwords in your accounts (if it save on your losted device), and have fun with your torments.
That is why you generally want to have the lock code enabled on your device.

Lock code will prevent the easy attacks; booting the device, flashing another boot image, connecting to device with USB.
What it doesn't protect is attacking the device via boundary scan or physical chip attacks. (However it will indeed stop the casual hackers)
 

The Following User Says Thank You to juiceme For This Useful Post:
Posts: 50 | Thanked: 17 times | Joined on Apr 2014
#3
I have a login PIN code. I want to save my private files. If I lost smartphone, anybody can try to remove PIN. If he win, he can read my files.
 
Community Council | Posts: 4,920 | Thanked: 12,867 times | Joined on May 2012 @ Southerrn Finland
#4
Originally Posted by sHaggY_caT View Post
I have a login PIN code. I want to save my private files. If I lost smartphone, anybody can try to remove PIN. If he win, he can read my files.
By "login PIN" do you mean the device lock code?
It is not easy to remove that.
I'd say it is pretty difficult indeed... How do you propose going around it?
 
Posts: 50 | Thanked: 17 times | Joined on Apr 2014
#5
But the service center can be, is not it?

And after deleting PIN, user can get from service center smartphone with files and accounts (with saved passwords) of old owner.
 
Community Council | Posts: 4,920 | Thanked: 12,867 times | Joined on May 2012 @ Southerrn Finland
#6
Originally Posted by sHaggY_caT View Post
But the service center can be, is not it?

And after deleting PIN, user can get from service center smartphone with files and accounts (with saved passwords) of old owner.
I don't think so. AFAIK what is possible at service is to cold-reflash it so that all content is wiped, but it is not possible just to remove locking so that content is readable.

This is why it is called "Lock code"
 
Posts: 50 | Thanked: 17 times | Joined on Apr 2014
#7
Oh... It is good news

May be also is solution for android apps?

Last edited by sHaggY_caT; 2015-06-30 at 17:21.
 
Posts: 188 | Thanked: 308 times | Joined on Jan 2013 @ UK
#8
Originally Posted by juiceme View Post
I don't think so. AFAIK what is possible at service is to cold-reflash it so that all content is wiped, but it is not possible just to remove locking so that content is readable.

This is why it is called "Lock code"
This is true, as I dound to my cost when I borked my lock code with limited retries.
 
Posts: 1,548 | Thanked: 7,510 times | Joined on Apr 2010 @ Czech Republic
#9
Originally Posted by juiceme View Post
By "login PIN" do you mean the device lock code?
It is not easy to remove that.
I'd say it is pretty difficult indeed... How do you propose going around it?
But all the data is still there, unencrypted. And I would not want to place my bets that there is no mechanism for going around the lock (UART, JTAG, etc.). You might also have sensitive data on the uSD card.

The only way to be sure no one can get to your (or to any third party data you might have) is to use full disk encryption. Then the stolen/lost device is basically just holding a lot of random data.
__________________
modRana: a flexible GPS navigation system
Mieru: a flexible manga and comic book reader
Universal Components - a solution for native looking yet component set independent QML appliactions (QtQuick Controls 2 & Silica supported as backends)
 

The Following 4 Users Say Thank You to MartinK For This Useful Post:
Posts: 50 | Thanked: 17 times | Joined on Apr 2014
#10
May be, we need a new topic for android permitions removing feature?
I think, it is also very important and affected privacy very much.
 
Reply

Tags
android apps, encryption, secure


 
Forum Jump


All times are GMT. The time now is 22:04.