Reply
Thread Tools
tiempjuuh's Avatar
Posts: 202 | Thanked: 165 times | Joined on Jul 2012 @ Apeldoorn, Netherlands
#1
Nokia: "Yes, of course we decrypt your SSL sessions. But don't worry, we won't look at it"

http://gigaom.com/2013/01/10/nokia-y...orry-about-it/
__________________
Nokia N900 hw rev. 2204
Nokia N9 16GB black hw rev. 1507
Jolla + LETOH
 

The Following 6 Users Say Thank You to tiempjuuh For This Useful Post:
Posts: 1,523 | Thanked: 1,997 times | Joined on Jul 2011 @ not your mom's FOSS basement
#2
Opera Mini, Opera (Mobile) with Turbo enabled, and also some enterprise proxies that pose as the endpoint and install their own root certificate on workstations all do similar stuff.
 

The Following 2 Users Say Thank You to don_falcone For This Useful Post:
tiempjuuh's Avatar
Posts: 202 | Thanked: 165 times | Joined on Jul 2012 @ Apeldoorn, Netherlands
#3
True.

10chars
__________________
Nokia N900 hw rev. 2204
Nokia N9 16GB black hw rev. 1507
Jolla + LETOH
 
Posts: 2,076 | Thanked: 3,268 times | Joined on Feb 2011
#4
Haven't used Asha but can't imagine the user is not informed of that. Compressing encrypted data just doesn't work. Seems like a non-issue.
 

The Following User Says Thank You to szopin For This Useful Post:
peterleinchen's Avatar
Posts: 4,117 | Thanked: 8,901 times | Joined on Aug 2010 @ Ruhrgebiet, Germany
#5
That does not surprise me!

But still unbelievable. Especially this no-information-policy.
Similar workflow is the Nokia messaging service. Simple and easy for standard non-techy user, but "untrustworthy". I never ever used that feature, but set up my mail accounts manually/directly.

But fear is this is just the beginning.
1984 is already gone
__________________
SIM-Switcher, automated SIM switching with a Double (Dual) SIM adapter
--
Thank you all for voting me into the Community Council 2014-2016!

Please consider your membership / supporting Maemo e.V. and help to spread this by following/copying this link to your TMO signature:
[MC eV] Maemo Community eV membership application, http://talk.maemo.org/showthread.php?t=94257

editsignature, http://talk.maemo.org/profile.php?do=editsignature
 
Posts: 207 | Thanked: 552 times | Joined on Jul 2011
#6
I quite liked the Ashas until I read that.
 
automagic68's Avatar
Posts: 415 | Thanked: 161 times | Joined on Apr 2010 @ San Francisco, CA
#7
Are you guys accusing Nokia of data mining like Google?
__________________
Have a GREAT day!
 
Posts: 771 | Thanked: 393 times | Joined on Feb 2012
#8
of course nokia needs to do that to archieve compressed image loading.
no magic in it
__________________
5800XMN8808N9
 
woody14619's Avatar
Posts: 1,455 | Thanked: 3,309 times | Joined on Dec 2009 @ Rochester, NY
#9
I'm sure this is disclosed in the documentation somewhere. Opera Mini, for example, discloses this in the 27 pages of legal "agreement" you say OK to on first run. Anytime you have bandwidth savings, good odds it comes at the price of some level of security.

One silly question: If you trust a phone manufacturer to not put back doors and spyware into their closed-source browser and/or base OS... Why would you suddenly not trust them running a web server that does compression and middle-man decryption needed to do that well?

There are far more examples of manufacturers putting in back doors and data dump capabilities into their software than spying on service streams.
__________________
Maemo Council Member: May 2012 - November 2012
Hildon Foundation founding member.
Hildon Foundation Board of Directors: March 2013 - Jan 15, 2014
 

The Following 6 Users Say Thank You to woody14619 For This Useful Post:
Moderator | Posts: 6,215 | Thanked: 6,400 times | Joined on Nov 2011
#10
2 things:

- Unlike Opera, Nokia's privacy policy or terms of service does NOT mention this

- Opera only compress http traffic and do not touch https traffic other than transmitting it from your phone to the destination but Nokia decrypt https traffic too on their servers which means any compromising of Nokia's servers is a threat for those using it...

If it was transparent, nobody would say a thing but Nokia did realize they screwed up as usual and even before the above article posted a reply on the original blog. The above is what I gathered from the original blog but haven't verified it myself...
 

The Following 5 Users Say Thank You to thedead1440 For This Useful Post:
Reply


 
Forum Jump


All times are GMT. The time now is 17:17.