Hi all, I just started flashing custom roms and kernels and really enjoying the learning process. XDA and its members have been a huge help and awesome resource. It occurred to that it might be possible for the developer of a custom rom to hide spyware in their rom, is that true?
Also, does it happen or does the community on XDA keep people honest? Like if I flash one of the popular roms like AOKP, PacMan, CM, etc, are there enough people (smarter and better technically equipped than me) who would spot it and out the developer/rom?
I just want to know that what I am doing is reasonably safe in terms of spyware. I know there are other risks with flashing custom roms and kernels, but I haven't read anything about spyware.
Thanks!
Related
hi crew,
I couldn't seem to find the answer or a logical breakdown on this topic and so I wanted hear from the folks here at xda. I'm relatively new and just learned about this website last year while I was searching for things to do with my HD2. I used to flash all kinds of stuffs on my phone and really enjoy it. However, I moved on to the Sensation, touchpad, kindle fire, and Dell 7.
except for the touchpad (cm7), I'm keeping everything else stock and unrooted. This year alone there were several incidents with security on android platform .. Skype, malicious apps on market and forums, and I believe there was also ISSues with custom roms for folks in China. I guess my question is .. How easy is it to include a malicious coding into a custom Rom? If a developer/chef can modify just about every aspect of this platform then I'm guessing it won't break much sweat for them to include these spying coding into a custom Rom?
don't get me wrong because I truly believe that 99.999% of developers on this forum is dedicated and passionate about giving us the ultimate user experience. But if you look at the math, it only takes 1 out of every 100,000 and that's enough to create fear in many of us. Is there a way for users (common users) like myself to determine if there is something else coded in a custom Rom? Would it help at all to protect our privacy with an AV?
of course, one answer to my question is to avoid custom Rom! But yet, with the recent news about carrier iq even with stock you are still being monitored. Since I'm not a developer and have very limited knowledge about this area, I just wanted ask the questions here to hear inputs, suggestions, and opinions from more experienced users (and perhaps developers if any). Thanks!
.
Thread moved to Q&A due to it being a question. Would advise you to read forum rules and post in correct section.
Failure to comply with forum rules will result in an infraction and/or ban depending on severity of rule break.
qdochemistry said:
How easy is it to include a malicious coding into a custom Rom? If a developer/chef can modify just about every aspect of this platform then I'm guessing it won't break much sweat for them to include these spying coding into a custom Rom?
Click to expand...
Click to collapse
Very easy.
qdochemistry said:
Is there a way for users (common users) like myself to determine if there is something else coded in a custom Rom? Would it help at all to protect our privacy with an AV?
Click to expand...
Click to collapse
It depends. You could use an antivirus, but they mainly just scan your apps, media, and settings; so if the malicious 'thing' is directly built into the rom, it will not be detected. If it was an app (or in one), then there is a chance it would be detected.
Thanks .. that was indeed my thoughts but since I don't know much about coding or "cooking" and so figured I'd would ask. XDA is a great community but it is a scary thought having to think that our privacy with custom roms is entirely relying on the "honor code" of developers. I have not read about anything isolated incidents with infected ROMs, and much less would something like that happen here at XDA. I hope I am correct with the assumption that ROMs being released here are somehow being cross-checked by someone .. but I guess that would be a great amount of effort as too many ROMs are being released everyday on this site.
Again, there are many reputable developers in this community but just thought that I'd ask since it would only take one to ruin the effort of a million ... if anyone got thoughts or opinions feel free to comment.
Thanks for replying
I think that's a very valid concern. I am using a custom rom right now so this is also my concern.
I hope I am correct with the assumption that ROMs being released here are somehow being cross-checked by someone .. but I guess that would be a great amount of effort as too many ROMs are being released everyday on this site.
Click to expand...
Click to collapse
Well, I don't think there is anyone / any party responsible for checking the released ROMs given that the amount of work required...So what I do is to avoid dealing anything sensitive with the phone (even I was using Stock ROM). All this kind of stuff I will do it with my desktop where I feel I have more control.
lol .. same here .. on devices with ported ROMs I am quite careful as to what I do with it .. and on stock devices i do keep the number of apps to the minimal. But it's just sad being that way .. or may be i'm just paranoid!
So I have a GN and now Im running the Bigxie rom, its blazzing fast, and solid as it shoulfd be However I find it odd, that we buy a phone for 600usd and then to put it working as it should be, needs to by developers,developing roms and Kernels and then needs to by us flashing it...
Shouldnt be Google or Android department, developing roms or whatever to take the most of the device... I understand that they release the code and the stock rom and then its up to everyone to develop, but shouldnt their stock roms be the most advanced and fast has custom roms like yours?
Ive got 3 devices, N1, GN and GTab 10.1 and in all 3 devices I run customs roms to take the most of them....Its strange, the way I see it, it should be them, when they release somenthing the rom, should be the best of the best, with kernel up to the best in speeds..bla bla bla....
I dont know...just my thought,....maybe Andoid department should choose some developers to be affiliated with them and develop customs roms...
Once again, thanks to everyone who develops customs roms and keep up the good work
I'm wondering what prevents our devices from running custom roms such as cyanogen, aokp, etc?
I don't think that there is necessarily anything that prevents us from running custom ROMs, I think it's more of a lack of developers.
At least that's what i'm guessing (I know there are certain people here that mod the existing firmware and stuff, but creating a completely new ROM is usually not a one-man show... at least most of the time).
oh I'm fully aware of the difficulties and time needed..I just wasn't sure if it was lack of dev interest or what tho
My question is plain and simple. I mean, I do know the benefits of rooting like backing up apps, removing bloatware, over/underclocking and so on. But in my own experience rooting the device and putting a custom rom in it automatically made the device less stable and more battery hungry (for some weird reason) plus added many many bugs which made me question why did I do it in the first place. So I'm asking do you feel any improvement whatsoever while using any custom rom? Or do you use custom rom just because you can?
It has thousans of reasons.. For simple example while every unrooted users rumor "when will come jely bean? I'm tired of waiting!!" Etc.. i run 4.1.1 jely bean on my SGS3 for 3 months.. its enough.
If you like always research for better and better mobile experience, you have to root your phone. Or simply just say yes for your brand's supply.
Sent from my GT-I9300 using xda premium
lolkoz said:
My question is plain and simple. I mean, I do know the benefits of rooting like backing up apps, removing bloatware, over/underclocking and so on. But in my own experience rooting the device and putting a custom rom in it automatically made the device less stable and more battery hungry (for some weird reason) plus added many many bugs which made me question why did I do it in the first place. So I'm asking do you feel any improvement whatsoever while using any custom rom? Or do you use custom rom just because you can?
Click to expand...
Click to collapse
since everbody is aware that customization can happen better with a custom rom over and above the stock one.
and regarding improvement, well it all depends on what sort of customization u need and accordingly the Custom rom and kernel u choose. which do vary from person to person.
and nobody use custom rom because they can but because they need the same to customize the phone accordingly to there need.
lolkoz said:
My question is plain and simple. I mean, I do know the benefits of rooting like backing up apps, removing bloatware, over/underclocking and so on. But in my own experience rooting the device and putting a custom rom in it automatically made the device less stable and more battery hungry (for some weird reason) plus added many many bugs which made me question why did I do it in the first place. So I'm asking do you feel any improvement whatsoever while using any custom rom? Or do you use custom rom just because you can?
Click to expand...
Click to collapse
From my experience with my HTC Desire on which I tried a lot of different ROMs you can either:
1) Flash a stable ROM, benefit is that most of the time its faster than stock & includes additional features and is 99% stable. In addition ROMs are improved all the time and new features added that you might not get on your stock ROM or only very late
2) Flash a ROM that is currently under development and not stable, e.g. earlier ICS ROMs for the HTC Desire had features missing and were not very stable
In my case I started with stable ROMs as I need my phone as daily driver, after I got more experienced I switched to (2) and tried the not so stable ROMs as I always like to try new things etc. and you will get all those new features and improvements (sometimes on the cost of stability and or speed).
Basically up to you what you want to do.
For my Galaxy S III I will also start with a rooted stock ROM as currently I do not see that much benefits in the custom ROMs yet (please correct me if I am wrong).
The answer is also plain and simple. Rooting is to unlock your phone for more customisation and some extra features.
Why we need more customisation and extra features? Because we get bored easily and because we can.
Sent from my GT-I9300 using xda app-developers app
There is a really good article you can read here.
You just get so much more with root. Without root i would have been stock with stock rom on my htc desire and my xoom. The brilliant roms that are on here have provided me with so much more and given me an amazing experience with android.
Hello.
I'm on a Galaxy S5 (klte) on T-Mobile (g900t). There are a ton of custom ROMs with great features and amazing devs providing great support. However, I've come to find myself jonesing to make my own ROM, for personal use. I've seen some guides online and I'm fairly certain I can do it.
Here's where I would need help: I'd like to make a Frankenstein-like ROM. Take bits and pieces of several ROMs and make some new and only for personal use.
Obviously, I would ask permission to use various parts of a devs ROM before started this endeavor but I would like to know if this has been done by others as I'm sure I'm not breaking any new ground.
Sent from my G900T from nowhere.