[Q] Android Security Issues - HTC Aria Q&A, Help & Troubleshooting

i was watching G4 earlier and they said that Android saves all of our passwords in plain text and anybody can easily access these. How threatened should we feel if we are using the custom roms such as CM7? They said that they have release 2.3.4???? not sure if thats the correct version but i believe thats what they said.

Cm7 is 2.3.4 and I'm no expert but if someone was trying to hack my phone I'd just turn off wifi or the phone.
Sent from my Liberty using XDA App

superman6143 said:
i was watching G4 earlier and they said that Android saves all of our passwords in plain text and anybody can easily access these. How threatened should we feel if we are using the custom roms such as CM7? They said that they have release 2.3.4???? not sure if thats the correct version but i believe thats what they said.
Click to expand...
Click to collapse
They are reporting it inaccurately (sensationalism) or you just remembered it wrong. Either way, the actual issue is not that big of a deal. Here's a more accurate article about the problem: http://blogs.computerworld.com/18308/google_android_security_flaw
Your password is not at risk. To avoid having to resend the password itself every time your phone communicates to Google's servers (which would be a security risk), the server generates a token (a bunch of random letters and numbers basically) that your phone will send instead of the real password. The token is only valid for a number of days, so if it is compromised, there's no permanent damage being done. The issue is that this token is sometimes sent unencrypted when you are connected to a wifi network, which means it could be intercepted by someone else connected to that wifi network. However this is something Google can and will correct on their side -- i.e., no one needs to apply any software update or patch to their phone to fix the issue, as mentioned in the article I linked to.
By the way, if you log into Facebook while on public wifi on a laptop, you will be putting yourself in the exact same risk. Facebook does exactly the same thing, but the only difference is Facebook doesn't care to fix the issue.

Google addressed the issue server side and all is well again.....
sauce:
http://www.engadget.com/2011/05/18/google-confirms-android-security-issue-server-side-fix-rolling/

martiantakeover said:
Cm7 is 2.3.4 and I'm no expert but if someone was trying to hack my phone I'd just turn off wifi or the phone.
Sent from my Liberty using XDA App
Click to expand...
Click to collapse
Actually Cm7 is 2.3 -2.3.3 while Cm7.1 is 2.3.4.

Thanks for clearing that up I don't ever use a public wifi anyways so I wouldn't be at much risk
Sent from my Liberty using XDA App

Related

[Q] Remove password when using exchange sync

After a bit of trouble I got the new JI6 update installed on my vibrant. One of the "lovely" changes included was apparently "better" exchange support. By better I guess they mean that I now have to put up with a rather annoying and completely unwanted need to include a password to access my phone after it has been asleep for a bit. I quite simply do not want this. Yes I understand its for security etc, but no I do not want this simply because I need to connect to an exchange server. Does anyone know a way around using this feature?
Would it be possible to use the mail app from stock? If so, how?
Sent from my SGH-T959 using XDA App
T.Els said:
One of the "lovely" changes included was apparently "better" exchange support. By better I guess they mean that I now have to put up with a rather annoying and completely unwanted need to include a password to access my phone after it has been asleep for a bit.
Click to expand...
Click to collapse
I know this isn't what you want to hear, but just to make things clear -- The improvement was the fact that the email client more fully supports the ActiveSync protocol. The password requirement wasn't supported before, and is now. And the actual requirement comes from your Exchange provider. Ask them if they'll let you use Exchange without a password. Odds are they'll say no. But still, if they agree -- they can remove the requirement for you.
If it is not possible to disable the password all together is there a way to change it? I have been finding it very annoying to have to enter a password every 15 minutes or so, so if it can't be disabled, is it possible to change it to something else (ie 1111)? Would installing an earlier version of the email.apk work? If so, where could I find that?
Thanks...

[Q] Removing Keyguard Password Policy due to Exchange

I am attaching the Mail.apk that comes with the Thunderbolt and begging someone who is up to the challenge to mod it and allow the removal of the device admin so I don't have to put in a password every 15 min. I hav.e searched and every patched Mail.apk for the desire doesn't work. I totally need this as I am sure that others will too. Your work will be legendary.
That would be so awesome.
On a side note...Why does Sense only let you sync 3 days with MS exchange? I have always synced 7 or 30 days with my other android phones.....Mytouch 3g, G2, and my Nexus 1
I don't think that it has to do with the Mail.apk as I can synk up tp thirty days. I just have to deal with the password issue. So in the mean time I am using touchdown.
Search market for lockpicker app. It bypasses the exchange policy that makes you enter your password. It's a sense thing. And this app was made for it.
Sent from ADR6400L using Tapatalk
denonlake said:
Search market for lockpicker app. It bypasses the exchange policy that makes you enter your password. It's a sense thing. And this app was made for it.
Sent from ADR6400L using Tapatalk
Click to expand...
Click to collapse
Says it does not work with Froyo
The people in security at your work will hate you for this. It's there for a reason. You lose your phone and work data escapes... you can be jailed and fined (depending on the data)
I work for a company that has to be hippa compliant and mass HI-TECH compliant. We don't even allow android devices to connect because of things like the lack of device encryption.
Help please...
I accidentally deleted Mail.apk using titanium backup (idiot). I tried to install the attached mail.apk from the first post but it didn't install. Can someone please send me an apk that can be installed.
Thank you!
ktrinidad said:
I accidentally deleted Mail.apk using titanium backup (idiot). I tried to install the attached mail.apk from the first post but it didn't install. Can someone please send me an apk that can be installed.
Thank you!
Click to expand...
Click to collapse
That is the APK from the stock rom and I did the same thing as you. But I was able to flash to a recovery that I just had made. I posted that Mail.apk directly from the stock rom and it wouldn't install for me either. The plot thickens...
cps68500 said:
The people in security at your work will hate you for this. It's there for a reason. You lose your phone and work data escapes... you can be jailed and fined (depending on the data)
I work for a company that has to be hippa compliant and mass HI-TECH compliant. We don't even allow android devices to connect because of things like the lack of device encryption.
Click to expand...
Click to collapse
Ironically, some idiot in you IT department is in an airport right now, with a laptop containing all your details for your govt contracts...and he just lost it
cps68500 said:
The people in security at your work will hate you for this. It's there for a reason. You lose your phone and work data escapes... you can be jailed and fined (depending on the data)
I work for a company that has to be hippa compliant and mass HI-TECH compliant. We don't even allow android devices to connect because of things like the lack of device encryption.
Click to expand...
Click to collapse
It's far worse than what my employer's IT implemented...
Our Exchange policies haven't changed (I know many people at work who are setup to receive email + calendar from our corporate exchange server, nothing changed).
I only have to enter a pin ever ~30mins. Then I upgrade my Cappy to froyo and setup the exchange account again. NOW I have to re-enter it every time my screen blanks (timeout), even for 1 second.
This is froyo mail app folks, not my employer's Exchange settings. they didn't change, my email client did.
I want it back the old way. Not to mention calendar only synchs ~5% of my meetings now. crappy appy on my Cappy!

XWLA4 roms incompatible with amazon market?

Anyone able to login to the amazon market app on xwla4? No matter which one it won't accept login and password .
Sent from my SGH-I777 using xda premium
Works on mine, just signed in, I haven't found any issues reported yet.
http://forum.xda-developers.com/showthread.php?t=1502426
Many of the new roms are being stripped down, I assume breaking things so just ask them to either include the files or ask for what is being removed/modified.
Also having issues with the latest version of google music as well :-/
Everythings perfect with shishirROM
Sent from my GT-I9100 using XDA App
Honestly I have had this problem on LILROM also (also was playing around with Rebel) and they both do it. I triple checked this before posting so someone didnt think I was just being dumb and it was a password problem but I can login fine to Amazon using the same Email/password on my laptop and on Shostock/ICScrewed fine. It was my understanding that the Amazon market is limited to US users so far and not international which was why I was curious -- its really a deal breaker for me because I have a ton of paid apps that are shared across my phone and several Kindle Fires. Hopefully someone figures this out and thanks for taking the time to respond btw...
defnow said:
Everythings perfect with shishirROM
Sent from my GT-I9100 using XDA App
Click to expand...
Click to collapse
Thanks I will give it a try but having tried LIL/Nonamed and Rebel already I suspect something is going on here that is either in relation to this base or how its being hellraised? I am not a developer but work in IT so if there is any information I can provide that might help correct this please let me know.
I will post back with some results on this later I need to wait for my GF to go to bed so she does not think I am ignoring her texts.
No issue here. Using lilrom, flashed before it was named, if that makes any difference.
Sent from my SGH-I777 using XDA App
i was on shishir rom also and didnt have any issues with amazon appstore.
Please don't blame ROMs for issues with logging into cloud services unless a problem like this exists for more than a day or two.
Login problems are frequently problems on the service provider side - for example, the Market wigged out on me this morning, but 20 minutes later it was OK.
If you install lots of roms check amazons site under your apps and devices. You may have used up the allowed amount of devices, just delete some and try to login from your mobile again.
Entropy512 said:
Please don't blame ROMs for issues with logging into cloud services unless a problem like this exists for more than a day or two.
Login problems are frequently problems on the service provider side - for example, the Market wigged out on me this morning, but 20 minutes later it was OK.
Click to expand...
Click to collapse
Out of curiosity..If it was a problem with the market it wouldn't allow you to log in from computer either?
Nyk0n. said:
If you install lots of roms check amazons site under your apps and devices. You may have used up the allowed amount of devices, just delete some and try to login from your mobile again.
Click to expand...
Click to collapse
This. Ran into it a couple weeks ago. I think the limit is 20 devices. Every new login on a different ROM appears to count, from what I saw...though I didn't dig in detail, just deleted some aria and cappy instances.
Sent from my SGH-I777 using XDA App
jasvncnt1 said:
Out of curiosity..If it was a problem with the market it wouldn't allow you to log in from computer either?
Click to expand...
Click to collapse
No, completely different interface - for example, it's common for the Android Market to be inaccessible or wacky when accessed by devices but for the web frontent to be fine.
Entropy512 said:
No, completely different interface - for example, it's common for the Android Market to be inaccessible or wacky when accessed by devices but for the web frontent to be fine.
Click to expand...
Click to collapse
Got ya, thanks for the clarification.

Stolen Prime

Hey all, I need some help.
I left my Prime in the seat back pocket of an airplane and when i immediately went bak on the plane to get it it was gone! I unlocked the bootloader so devicetracker.asus.com isn't helping me at all. I didn't have any other tracking software on my prime.
Any ideas? I have the Serial number and a Device ID from having it sync'd to my work email. HELP! Am I SOL?!
IM bummed for you
Sent from the Beer in your goblet
Why don't you sign into the google play store, push mobile lookout to your tablet, and see if you can auto track it that way. I'm not sure if you have to setup the app first which would make this procedure pointless, but worth a shot.
Good idea. Call me stupid, how do i do that?
playingeetar247 said:
Good idea. Call me stupid, how do i do that?
Click to expand...
Click to collapse
Lookout sign in, and press INSTALL. Better hope it has an active WIFI signal else it won't install until it does.
Give this a try. It works fine with my phone, and It's perfect for your case:
https://play.google.com/store/apps/details?id=com.lookout.labs.planb&feature=search_result
Hope you find it!
chugger93 said:
Lookout sign in, and press INSTALL. Better hope it has an active WIFI signal else it won't install until it does.
Click to expand...
Click to collapse
You know, thats a very good idea, but i think you need to setup lookout on your prime the first time you install to set up tracking, last time i checked that is, I think that goes for all apps,
I think a developer would make killing if they managed to create an app that can do what you suggested
Edit: Never mind, thanks victorvasconcelos ^^^
Hope someone figures something out for you OP, because thats a damn shame, good luck
Some advice as an aircraft mechanic.
You're not getting it back.
Android Lost is another great app for this type of situation. You can push it to your Prime via tha Play store website and then use the Android Lost web interface to hide the app from your Lapp draweraking it harder to notice and uninstall.
Also from the Android Lost web interface you can force the device to take photos using either camera which will then be emailed to an address of your choice. It can also track the device via GPS and you can lock and password protect the device remotely. Of course all of this requires an active data connection, but it is pretty useful.
https://play.google.com/store/apps/...t#?t=W251bGwsMSwxLDMsImNvbS5hbmRyb2lkbG9zdCJd
None of those will work if the person who nabbed it has wiped it or changed the google account on it.
I hope you get it back, but as one that left a palm pilot in a seat from a 13hr flight from Japan, I do not see good luck in your future for this.
Lookout won't work even if you install it through PC. You would still have to once downloaded run it and sign up/activate it all. There's no other way since you didn't prepare your tablet for the worse case scenario. Consider it gone
Sent from my PC36100 using XDA
Lookout has an app called Plan B. Install it from the Play Store from your PC, and it will auto activate when it finally downloads. It will attempt to locate itself and send you the coordinates to your GMail account. Of course Wifi has to be active, and connected to a network, and the precision of the location is dependant on how good your GPS is, or how many WiFi networks it can see.
As for the Asus Device Locator, boot unlocker does not disable this, only a non-Asus Rom will. I am running a rooted .21 stock ROM on my unlocked Prime, and I can locate my device on the Asus site. If you have stock ROM and the device locater will not connect, its possible the WiFi is off and/or the Prime has no data connection to any Wifi network. The nice thing about the locator is that if it is found, you can activate the "ringer", which on the prime just makes it emit a loud sound. Handy if you are in the area of the device. I have not tested remote wipe nor lock device.
maybe a stupid question but.....
I don't think you mentioned this and this may be a stupid question but Have you gone to the airport or airline to see if someone turned it in to lost and found?
copc said:
None of those will work if the person who nabbed it has wiped it or changed the google account on it.
I hope you get it back, but as one that left a palm pilot in a seat from a 13hr flight from Japan, I do not see good luck in your future for this.
Click to expand...
Click to collapse
Possible, but lets assume that their an android noob for now, what i'd be concerned about is whether they have a charger or not, as you'll probably have to wait until they get round to charging it before you can do something, OP should take that into account if hes not getting a reply
Question, do you have a credit card saved on your playtore or anything, if so did you set up keylock?
nonpaq said:
Lookout has an app called Plan B. Install it from the Play Store from your PC, and it will auto activate when it finally downloads. It will attempt to locate itself and send you the coordinates to your GMail account. Of course Wifi has to be active, and connected to a network, and the precision of the location is dependant on how good your GPS is, or how many WiFi networks it can see.
Click to expand...
Click to collapse
Plan B was already linked on 1st page, as for Plan B I have personally tried it after READING it on the 1st page. My Prime is in a office GPS is on connected to our wifi and multiple wifi's around. Plan B installed but no e-mails after 10min so far. I think it relies too much on GPS for location, as it seems to be designed more for phones with cell coverage.
"After you install it, Plan B will start locating your phone using cell towers and GPS. On some phones, Plan B can switch GPS on automatically. Your location will keep updating for 10 minutes."
So you can try Plan B but don;t count on it as I am sitting next to my prime with Plan B on it and I have no idea where it is?
Also as I stated before if the gmail account has been removed or changed, you are not getting any software pushed from the play store onto your tablet.
---------- Post added at 02:40 PM ---------- Previous post was at 02:32 PM ----------
banderos101 said:
Possible, but lets assume that their an android noob for now, what i'd be concerned about is whether they have a charger or not, as you'll probably have to wait until they get round to charging it before you can do something, OP should take that into account if hes not getting a reply
Question, do you have a credit card saved on your playtore or anything, if so did you set up keylock?
Click to expand...
Click to collapse
I disagree, always prepare for the worst.
Forget the account begin removed, Tablet taken stuck in workers locker, driven home then turned on, Chance of an open wifi not good.
Plan B does not seem to work well on prime from my experience so far.
If the person who nabbed it is stupid enough to take it hook it up to their own home wifi and start messing with it before wiping it, they deserve to get caught.
I hope for the best, but I do not see it working out that easy. It would have been easier if it were a phone or if the software was on there from the start.
Good luck and keep us posted.
I would stick with Asus Device Locator as long as you were running a stock ROM. A wipe can't change the serial number. If the unit is off, has Wifi off, or is in an area with no wifi, none of these other apps are going to work anyway.
The sad news is that without Wifi, the Prime could never report is location even if a locator app was on it running.
The good thing about the asus devicetracker is that even if they remove your Google account or factory reset the device you can still track it.
Sent from my Transformer Prime TF201 using XDA Premium HD app
[/COLOR]
almightywhacko said:
Android Lost is another great app for this type of situation. You can push it to your Prime via tha Play store website and then use the Android Lost web interface to hide the app from your Lapp draweraking it harder to notice and uninstall.
Also from the Android Lost web interface you can force the device to take photos using either camera which will then be emailed to an address of your choice. It can also track the device via GPS and you can lock and password protect the device remotely. Of course all of this requires an active data connection, but it is pretty useful.
https://play.google.com/store/apps/...t#?t=W251bGwsMSwxLDMsImNvbS5hbmRyb2lkbG9zdCJd
Click to expand...
Click to collapse
Step 2: Register your phone
Simply start the program. Thats it! If you don't have your phone nearby, you may remotely start the app by sending an SMS with the text "androidlost register" to your mobile.
From their website, looks like you need to have had it pre-installed, or a sms capable setup.
Shame, i really want this guy to find his prime, dramas killing me ..........huh, oh, i mean, sorry for your loss
Gd luck
OP: You might to change the subject to 'lost prime' instead of 'stolen prime'.
Must feel terrible to realize you left your prime on the airplane. Almost as terrible as stealing a tablet only to realize it isn't an ipad.

[Q] Blocked URLs/Domains?

I have a Moto Droid X2 using GB 2.3.5 and Eclipse 2.2.1 ROM with Verizon Wireless in the USA. For the life of me I cannot figure this one out...
When I receive emails from EastBay.com or HomeRunMonkey.com they generally display correctly on my X2. However they also sends advertisement emails and both use a 3rd-party company, mybuys.com. Whenever I receive emails that are advertisements, the images are blocked. I checked Google and MyVerizon and nothing is showing as being blocked. So, if I try to click the link in the email that says if you cannot see the images, click here, my native browser opens but it errors out as if I have no active internet connection. I've even tried Opera Browser and the URL still fails. If I try to open the same email message on my PC using Gmail or on my HP TouchPad, the email displays correctly and the URL also works in all browsers. The best I can determine is Verizon Wireless is blocking this company. I'm guessing this because if I tether my TouchPad to my X2 using FoxFi then the same negative results occur - I cannot see the images in the email or browse to the URL in any browser.
Can someone with a Droid X2 on VZW please try the URLs below and let me know if it works?
http://w.p.mybuys.com/mfs/EASTBAY/201207022309/4662402/46624026764.html
http://w.p.mybuys.com/mfs/HOMERUNMONKEY/201207032150/4664783/46647836937.html
I have no idea what else I can try other than calling VZW but I'm apprehensive to do so in fear they tell me to go to a store and when I get there they see my Rooted and Eclipse ROM'd X2 and refuse to help me.
Any suggestions at all are most welcome.
Thanks!
P.S. I did make sure in Gmail the sender is always set to display images, also added their email address to my address book, made sure there were no filters, etc., but I seriously doubt Gmail is the issue.
So I just forwarded the email to my work account and on my work laptop everything displays correctly but if I view the same work email on my Droid X2, I still cannot see any images. I have to conclude either something on the phone itself is the issue or it is VZW blocking access to the site that supplies the external images.
That url doesn't work for me using eclipse and dolphin hd.
Sent from my DROID X2 using xda app-developers app
smallzfsu said:
That url doesn't work for me using eclipse and dolphin hd.
Sent from my DROID X2 using xda app-developers app
Click to expand...
Click to collapse
Thanks for checking and just to confirm, you too are on VZW? I'm in Southern NJ, what region are you?
I haven't had that particular problem but I do use my phone to make a hotspot and watch hulu and just the internet from my phone seems to be blocking the commercials cause it works fine on my home connection. I'll let you know if I find a setting to fix it but so far its not looking like something I did
Strubie42 said:
I haven't had that particular problem but I do use my phone to make a hotspot and watch hulu and just the internet from my phone seems to be blocking the commercials cause it works fine on my home connection. I'll let you know if I find a setting to fix it but so far its not looking like something I did
Click to expand...
Click to collapse
Ok, so did the URLs in my OP work or not work for you? Are you on stock or a particular ROM? I've looked for settings too but came up empty. Thanks for checking...
ktklein72 said:
Ok, so did the URLs in my OP work or not work for you? Are you on stock or a particular ROM? I've looked for settings too but came up empty. Thanks for checking...
Click to expand...
Click to collapse
Yes both links worked for me at least I think they did. Opened up to some sports apparel?
Strubie42 said:
Yes both links worked for me at least I think they did. Opened up to some sports apparel?
Click to expand...
Click to collapse
Ok, sorry to be a PitA - they opened on your phone in the native browser? Yes, both sites are sporting goods and sporting apparel. And just to confirm, are you on Verizon Wireless and are you rooted/custom ROM or totally stock? I'm trying to see if the Eclipse ROM in any was has bearing on this and want to rule it out if possible. Thanks.
UGH! My VZW Blocking theory is starting to crumble...
I just tested those links on a Droid X (I know it's not an X2) and the emails from my gmail account and the website links all worked perfectly. That Droid X is on VZW, same region as me, but is unrooted and on the stock ROM. I'm now wondering if Eclipse might be the issue. I guess I need to get Nitro involved for some help...
ktklein72 said:
Ok, sorry to be a PitA - they opened on your phone in the native browser? Yes, both sites are sporting goods and sporting apparel. And just to confirm, are you on Verizon Wireless and are you rooted/custom ROM or totally stock? I'm trying to see if the Eclipse ROM in any was has bearing on this and want to rule it out if possible. Thanks.
Click to expand...
Click to collapse
I would agree that eclipse is the problem. I was on stock cause I couldn't get the download for cm9 alpha 4 to work. I went to eclipse about an hour ago and tried those links again and they immediately go to failed load page. Before they did just open in my native browser
Strubie42 said:
I would agree that eclipse is the problem. I was on stock cause I couldn't get the download for cm9 alpha 4 to work. I went to eclipse about an hour ago and tried those links again and they immediately go to failed load page. Before they did just open in my native browser
Click to expand...
Click to collapse
I was starting to lean that way too and just sent Nitro a message asking for help. Maybe he can isolate the issue and fix it. Thanks for confirming - most appreciated.
ktklein72 said:
I was starting to lean that way too and just sent Nitro a message asking for help. Maybe he can isolate the issue and fix it. Thanks for confirming - most appreciated.
Click to expand...
Click to collapse
No problem homie
first time I ever heard any one complaining their adverts are blocked, lol.
So, you are upset because (you are assuming) the rom is blocking spam/advertsing?
If I could block every single ad I would, I cant get enough of ad-block.
Gl hope you get what you want working working though.
I know it sounds crazy and generally I agree with you but in this case they are legit ads that I read to keep up on deals for my son who plays baseball. It just so happens I discovered something in the ROM was preventing me from accessing the URLs.
Sent from my Eclipsed DROID X2 using Tapatalk 2.2 b2
what was it?
please post up what ya found!
I emailed nitro to look into it. But so far ive determined with help from others is Verizon is not blocking anything and a stock droud x or x2 CAN access the URLs but the Eclipse ROM for the X2 cannot. Whatever is the root cause I do not know so that is why I emailed nitro. I even determined that while my hp Touchpad CAN see the images in gmail and access the URLs from any browser the minute I Tether it to my X2 images in gmail wont load and the urls fail in any browser. The x2 fails whether 3g or wifi.
Sent from my Eclipsed DROID X2 using Tapatalk 2.2 b2
After flashing Eclipse 2.3 the "broken URL" issue I originally discovered and reported now appears to be resolved.
Sent from my Eclipsed DROID X2 using Tapatalk 2.2.4
ktklein72 said:
After flashing Eclipse 2.3 the "broken URL" issue I originally discovered and reported now appears to be resolved.
Sent from my Eclipsed DROID X2 using Tapatalk 2.2.4
Click to expand...
Click to collapse
just a thought but is it possible that they were blocked based on entries in the host file?
2.3 changelog said:
Fixed website resolving issue
Click to expand...
Click to collapse
nevermind.

Categories

Resources