themerapp.com & heartbleed - Themer General Discussion

My browser (an a heardbleed detecting plugin called chromebleed) keeps warning me about the themerapp.com website being vulnerable to the Heartbleed SSL bug, might want to look into it

davidcampbell said:
My browser (an a heardbleed detecting plugin called chromebleed) keeps warning me about the themerapp.com website being vulnerable to the Heartbleed SSL bug, might want to look into it
Click to expand...
Click to collapse
Hi, this thread should help clarify this warning you are receiving: http://forum.xda-developers.com/showthread.php?t=2736772

Unrelated, the error I am referring to is an openssl bug called heartbleed, which was exposed in openssl, which the website server is still vulnerable to and needs to be patched, unrelated to the app.
More I formation here http://blogs.sophos.com/2014/04/11/...hat-is-it-and-what-does-it-mean-for-security/
Or Google heartbleed for more info
I've never used themer and do not intend to, I'm just letting you know about a bug on your website.

davidcampbell said:
Unrelated, the error I am referring to is an openssl bug called heartbleed, which was exposed in openssl, which the website server is still vulnerable to and needs to be patched, unrelated to the app.
More I formation here http://blogs.sophos.com/2014/04/11/...hat-is-it-and-what-does-it-mean-for-security/
Or Google heartbleed for more info
I've never used themer and do not intend to, I'm just letting you know about a bug on your website.
Click to expand...
Click to collapse
Apologies for that, I thought that the two had something in common, will let our team know now.
Thanks for the info!

Related

[Q] How did they find I was using a rooted device?

Hi All,
I have my device SGS2 synchronized with our corporate network. Our corp uses Zenprise for MDM solution which has me running this ****ty app zenprise for employees always running on my device.
Also, when I configured the inbuilt email app - it asked me all sort of privileges and became an admin for my device.
now the question - when I rooted my device, somehow corporate admins knew about it and I got an email from them that it has been detected that I am running rooted device and I should remove the root or take it to the service station.
How do they find THIS out? Is it zenprice MDM that reports rooted device or is it Exchange Security policies???
Now this time - after a flash I did install the zenprise MDM but I have not configured email . I simply used Touchdown and now I dont have to use PIN on my device lock and I doubt how many exchange SPs are enforced anyways. But I really do not know if I should try rooting again.
So, is it the exchange or is it the MDM which detected if the device is rooted? Any ideas?
Check out the web page for Zenprice: http://www.zenprise.com/solutions/android-management
It says "Block jailbroken or rooted devices".
And,
"Maintain hardware inventory, including asset details; report on device statistics"
"Report on service details such as roaming, location, user inactivity, and expenses"
If you own the device, you should hit them up about monitoring this information about your private phone, if it's not in your corporate mobile usage policy.
awojtas said:
Check out the web page for Zenprice: http://www.zenprise.com/solutions/android-management
It says "Block jailbroken or rooted devices".
And,
"Maintain hardware inventory, including asset details; report on device statistics"
"Report on service details such as roaming, location, user inactivity, and expenses"
If you own the device, you should hit them up about monitoring this information about your private phone, if it's not in your corporate mobile usage policy.
Click to expand...
Click to collapse
I know this is an old post but I wanted to add to it.
I'm an MDM administrator and I run Zenprise for MDM. Yes it is the Zenprise agent that detects whether or not a device is rooted. While the device belongs to you, you are connecting it to company resources which requires certain levels of security. In this case they block rooted devices. They can also record your screen and more. By connecting your phone to your company resources you are agreeing to their security policy. Ignorance of the policy is your fault and not theirs.
Hope this helps those of you who hate Zenprise. Being on the other side of it, I love it.
Well, but Zenprise is not differentiating between rooted and unlocked AT ALL. Unless Im misunderstanding something, this is a huge flaw in their detection mechanism which then leads to a false vilification of Android phones. In my case, I purchased a Samsung SIII aka S3 GTi9300 World Phone, so I can travel abroad and use different SIMS, so it is unlocked but NOT ROOTED. I installed the Zenprise aka Citrix Connect for Samsung app, and when it tries to login it quickly fails and reports back that "Connection failed due to a security policy". The Zenprise admins say my device is rooted, and it is not, so they dismiss it and say that well it doesnt matter from a Zenprise perspective it sees unlocked and rooted phones the same. This is so backwards I dont even know where to start. Nevermind Zenprise seems to be Apple-centric (just about every device it manages is an Apple, Androids seem despised), but getting support to care or do something about this difference in phone status (unlocked vs. rooted) is like asking a brick wall to care.
What can be done about this, what is the right setting to get Zenprise to accept a legitimate phone, or how can it be tricked into doing so. Thanks.
There's an app module called XPrivacy for the Xposed Framework, it could possibly help you guys hide your rooted and unlocked status as it is designed to feed bogus information for different permissions like for example you can spoof your mac address, imei bla bla yada yada, a little talk and contribution to the dev will possibly get you any missing features too.
P. S We can also set our desired info too for most relevant permissions or allow any specific information, and I agree with one thing privacy is too underestimated now. Orbot app can be used for connecting your device to the Tor Network thereby hiding your Internet presence to the whole world, the only thing you're admin will see is you being connected to a single IP which is random and could be anybody or anything.
Sent from my GT-I9100 using xda app-developers app
---------- Post added at 12:51 AM ---------- Previous post was at 12:37 AM ----------
goinovr said:
I know this is an old post but I wanted to add to it.
I'm an MDM administrator and I run Zenprise for MDM. Yes it is the Zenprise agent that detects whether or not a device is rooted. While the device belongs to you, you are connecting it to company resources which requires certain levels of security. In this case they block rooted devices. They can also record your screen and more. By connecting your phone to your company resources you are agreeing to their security policy. Ignorance of the policy is your fault and not theirs.
Hope this helps those of you who hate Zenprise. Being on the other side of it, I love it.
Click to expand...
Click to collapse
First of all don't easily and directly specify the root of the problem when you guy's are trying to cause the problem if a little modding and changing the apk is too difficult there will always be workarounds to virtually hide everything, lol you guy's wouldn't even understand when a security issue rises.
Sent from my GT-I9100 using xda app-developers app
We do not allow discussions regarding spoofing IMEI on xda so a few posts have been deleted.
E.Cadro said:
We do not allow discussions regarding spoofing IMEI on xda so a few posts have been deleted.
Click to expand...
Click to collapse
Understood, thanks for pointing it out, but anybody who knows a little about Xposed Framework can modify, spoof or do anything related to code level modification.
Sent from my GT-I9100 using xda app-developers app
E.Cadro said:
We do not allow discussions regarding spoofing IMEI on xda so a few posts have been deleted.
Click to expand...
Click to collapse
Yes point taken. Sorry
They check SU binaries. There are serval ways to hide it. Check for hide root on Google play.
Yours,
Amiroslo
Not any more. The new version (Worx) see su even hiden...
Sysadmins & tech support guys know everything. No hiding anything from them (except maybe the lazy ones).
So I've tested around this a good bit. The latest Citrix Worx doesn't only check for su binary. Even when you use hide root on say SuperSu it doesn't work. Even a hide my root won't work. After days of testing and tinkering I found what it does look for. It looks for both su binary AND busybox. So what I did was delete the busybox and all the symlinks to it in xbin. Then used the hide root on SuperSu and it worked. So that seems to be the fix for now. Hope that helps anyone.
Dixit
dixit said:
So I've tested around this a good bit. The latest Citrix Worx doesn't only check for su binary. Even when you use hide root on say SuperSu it doesn't work. Even a hide my root won't work. After days of testing and tinkering I found what it does look for. It looks for both su binary AND busybox. So what I did was delete the busybox and all the symlinks to it in xbin. Then used the hide root on SuperSu and it worked. So that seems to be the fix for now. Hope that helps anyone.
Dixit
Click to expand...
Click to collapse
Do you mind elaborating on this a bit? My company is running the latest version of Citrix Xenmobile (worx) and I'd like to accomplish this so I can use it but also keep root obviously.
cowman4000 said:
Do you mind elaborating on this a bit? My company is running the latest version of Citrix Xenmobile (worx) and I'd like to accomplish this so I can use it but also keep root obviously.
Click to expand...
Click to collapse
I explained it fairly well. You have to delete Busybox, the app itself. Then using file explorer like tool like maybe root explorer you need to go to Xbin and remove all the symlinks that pointed to busybox that may have been left behind. Only delete the ones that pointed to busybox.
Sorry cant be of more help on this as I don't have this device anymore, I have a Note4 which I cannot root so I cant test this further.
Dixit
Love it when old threads like this pop up. These were the good time's on Xda....shame pretty much all my Post's was removed lol.
Good time's... Great people.

App Stolen. Copyright Theft? Malware? Advice Please.

Hello,
Just looking for some advice.
I developed an app a few months ago, which has been surprisingly popular and seems to have got a bit of a reputation since I put it on the Market.
Today, I found my app, recoloured, renamed, and re-uploaded to the Play Store by some dodgy developer. This is relatively easy to do using most decompile tools nowadays. The developer even had the cheek to leave in a slight bug that I never fixed because it wasn't particularly important. You can actually see it from the screenshot. I'm not willing to download it however because I've noticed added to the permissions is "FULL INTERNET ACCESS" and "RECEIVE SMS" something that is totally unnecessary for my app to function correctly. This raises a few concerns.
His app is obviously based on one of the very early versions of mine because despite his screenshot having an 'add contact' button, the permissions page does not include READ CONTACT LIST. I have a feeling he's simply taken my version 0.1, changed a few colours and added some malicious code and reuploaded it.
I don't know how to proceed. Downloading it maybe unsafe.
Should I report this to Google ? Is this a case of copyright theft?
I am already looking to seek legal advice but I predict this guy doesn't live in my country...
If you're sure... report the issue to Google =/
Not just sure, absolutely positive. Definitely my app, definitely something dodgy.
then report to google right now
Do I do it via inappropriate app or via DMCA?
Yes, you should report to google to prevent other user from downloading that app.
OK,
well I assume that reporting via http://support.google.com/bin/request.py?&product=androidmarket&contact_type=lr_dmca
is the best way as it is copyright theft right? But obviously with the other extra permissions that are totally unnecessary it could be considered Malware too. So i'm not 100% Sure where to go with that.
skezza said:
OK,
well I assume that reporting via http://support.google.com/bin/request.py?&product=androidmarket&contact_type=lr_dmca
is the best way as it is copyright theft right? But obviously with the other extra permissions that are totally unnecessary it could be considered Malware too. So i'm not 100% Sure where to go with that.
Click to expand...
Click to collapse
then do both

[APP][4.0.3+ & GB][XPOSED] UnbelovedHosts

Xposed hosts blocker.
This app blocks host names of advertising, malware, spam, phone-home etc sites. You could import "hosts"-files by given urls.
With this app you have no more to alter the /etc/hosts file on the system partition, which was also a problem on some devices (eg Nexus 7) because changes where reverted after reboot.
Technical:
Name resolution request are answered with "No address associated with the hostname". This is even better than a common hosts file with redirects to 127.0.0.1, because no connection attemp follows. For logging of hostnames is no tcpdump needed!
Browser:
If you want to block content of websites, you have to use a browser app which does not tunnels everything through a proxy! This is because the proxy does also the name resolution. Negative examples I found: Google Chrome does not work.
UPDATE: XDA described how to use Chrome: DNS-based Ad Blockers are broken on latest Chrome versions, so here’s a fix
I'm using Dolphin with Jetpack, which works fine for me. Some more info in post #47. Opera Mobile Classic works also, see post #389
If you want to use Firefox you need Network Preferences Add-on, see hint of @ag43 here: post #297 - OR just open website "about:config" and delete content of "[network.]proxy.http", see hint of @TheClownDE here: post #483
This app will NOT be release in the Play Store because of Google's policy. Other apps like AdAway or AdFree where removed in the past... But you could anyway donate in the Play Store and/or on my website.
Limitiation:
No support of native querying binaries.
Donation:
You support this app!
Some hosts file import/export/sharing options
Logging of not denied host names
Blacklist/Whitelist/Patterns (Regex)
Timed download: 150 minutes after reboot, then every 4 days
Permissions:
RECEIVE_BOOT_COMPLETED: set timer for download
ACCESS_NETWORK_STATE: download only via W-Lan
INTERNET: downloading of files
WAKE_LOCK: don't sleep while dl/import
EXTERNAL_STORAGE: export/import files
This app connects only to the websites you see for downloading hosts files!
Important:
This app needs the Xposed Framework. The framework requires root access for installation. Don't forget to enable the module in Xposed. You can grab it here: Xposed Installer
Website: http://tinyurl.com/qg27xkr
Play Store: <not available>
Xposed Repository: http://tinyurl.com/qgmz3sh
Changelog: http://tinyurl.com/net7rdh
Why this app? Common method modifying /etc/hosts file does not work in all cases
Translation:
You could find here a interface to translate the english strings: http://tinyurl.com/okycacj
A free account of www.oneskyapp.com is required to edit. Additional, please attach your email address or send it via PM
defim said:
Xposed hosts blocker.
Why this app? Common method modifying /etc/hosts file does not work in all cases
Click to expand...
Click to collapse
So, whats the difference between this and AdAway ?
So your adblocker app got ads? I'll need to donate in order to remove the ad?
That sounds funny
theknut said:
So your adblocker app got ads? I'll need to donate in order to remove the ad?
That sounds funny
Click to expand...
Click to collapse
Hehe, if you want is say this way, Yes.
If you look at the screenshot with logfiles, you could see FolderSync, Feed+ and Smart AppLock. They all are pro/donate/premium versions...
And I think it is okay to get more features which are not really needed, but nice
yanleites said:
So, whats the difference between this and AdAway ?
Click to expand...
Click to collapse
Quote of a part of the OP
defim said:
With this app you have no more to alter the /etc/hosts file on the system partition, which was also a problem on some devices (eg Nexus 7) because changes where reverted after reboot.
Technical:
Name resolution request are answered with "No address associated with the hostname". This is even better than a common hosts file with redirects to 127.0.0.1, because no connection attemp follows. For logging of hostnames is no tcpdump needed!
Click to expand...
Click to collapse
How about GB support @defim ?
Opening settings seem to crash the app
Tryin to get into settings gets me a FC. Also weren't the adblocker removed also from xposed few weeks back as the dev said something like it's going against the devs, practically taking a possibility to earn any money for their free apps?
Sent from my LG-D802 using Tapatalk
AssToast said:
Opening settings seem to crash the app
Click to expand...
Click to collapse
Can you catch a error in logcat?
swat4samp said:
How about GB support @defim ?
Click to expand...
Click to collapse
I'll check that later, have to reflash my device for that. At the moment i'm improving some apps and finishing another new...
PAGOT said:
Tryin to get into settings gets me a FC. Also weren't the adblocker removed also from xposed few weeks back as the dev said something like it's going against the devs, practically taking a possibility to earn any money for their free apps?
Sent from my LG-D802 using Tapatalk
Click to expand...
Click to collapse
Have you a logcat of the fc?
In fact this is not a add-blocker, it blocks hostnames. And as you can see on the screenshot at the OP, in my case most of them are tracking sites
Btw, my 1st app had admob included. Was a big §%"$, not got any cent by it because no one touches adds...
Another thoughts: All "free" apps should be removed from Play Store, because nobody gets non-free ones
defim said:
Have you a logcat of the fc?
In fact this is not a add-blocker, it blocks hostnames. And as you can see on the screenshot at the OP, in my case most of them are tracking sites
Btw, my 1st app had admob included. Was a big §%"$, not got any cent by it because no one touches adds...
Click to expand...
Click to collapse
Buddy don't get me wrong I do not wanna start even to argue about it. I was in adds in marketing in my previous job. And my stance is to allow ad blockers as to in my case it's beneficial to the company with the ads as well. I never ever bought anything cuz or from an ad..they loose money if I click basically.... But this is a discussion for somewhere else.
Just wanted to give you a headsup that this might be an issue so you might get ready for some explanations.
Sent from my LG-D802 using Tapatalk
@PAGOT: Thanks, FC fixed. It appeared only in english version because of malformed strings.xml - did not show in with my language settings.
Adblocker: Yea, another place would be better to discuss. As i used modified /etc/hosts before, this app makes depending add/tracker/malwar etc companies no difference.
The app on xposed was removed by the developer itself, because he decided it so
Is there a way to add host sources to the main screen? (so I can update them by pressing them)
I've found a way to add the lists from sources but it doesn't save them so I have to copy the link and updating it this way make it very laborious.
@Blizzard22: Soon
Is rover.ebay blocked? Some host files block that site and it breaks important ebay email links.
If you are blocking anything rover.eBay please remove
Sent from my SGH-I337M using Tapatalk
When the unbelovedhosts module is active you cannot start the official chromecast app. It constantly force closes on starting it.
Looks good no issues yet please could you add the mother of all adblocking host to your list thanks in advance
Sent from my One X using Tapatalk
@defim
I tried the app and its pretty cool! But somehow the website I'm visiting with firefox are not listed in the log, why? Btw.
would be possible to add IPs / hosts directly from the log to the blacklist? Or at least to make it copy & paste-able.
It doesnt work for me. Adaway also stopped working for me sometime ago... Dunno why.

[CLOSED][APP][XPOSED][6.0+] XPrivacyLua - Android privacy manager [UNSUPPORTED]

XPrivacyLua
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Really simple to use privacy manager for Android 6.0 Marshmallow and later (successor of XPrivacy).
Revoking Android permissions from apps often let apps crash or malfunction. XPrivacyLua solves this by feeding apps fake data instead of real data.
Features:
Simple to use
Manage any user or system app
Extensible
Multi-user support
Free and open source
See here for all details, including installation instructions and download link.
Please read the frequently asked questions before asking a question.
This XDA thread is about using the latest version of XPrivacyLua. Off topic comments are allowed as long they are related to XPrivacyLua and are in the general interest of the followers of this thread, but anything not related to privacy is not allowed.
If XPrivacyLua doesn't work and/or when "module not running or updated" is shown, this is almost always caused by an Xposed problem.
Discussions about purchases are not allowed here, please contact me via here instead.
XPrivacyLua is being maintained and community supported, but new features won't be added anymore.
Custom hook definitions will always be part of XPrivacyLua, but there will be community support only. This means that I won't respond to questions about defining custom hooks anymore. See this thread for the reasons.
If you value your privacy, please consider to support this project with a donation or by purchasing pro features.
M66B said:
XPrivacyLua is not a permission manager, but a privacy manager. XPrivacyLua doesn't block things and doesn't revoke permissions, but does replace real data by fake data. This means you can grant Android permissions to an app and still let XPrivacyLua prevent the app from seeing privacy sensitive data. Revoking permissions can result in an app refusing to work and/or to crash. However, replacing real by fake data generally doesn't let an app crash.
Currently restrictions are quite crude because they mostly replace real data by no data. For example restricting the contacts app from getting contacts will result in an empty contact list. In the near future it might be made possible to select the data an app may see, for example just one group of contacts.
Click to expand...
Click to collapse
About feature requests and bug reports:
M66B said:
The goal is to have a tool that can properly protect the privacy of many in the near future. However, it isn't paid work, so I do whatever I like whenever I like it.
You can request features in this XDA forum. I will read them, but I will not respond to them and they might or might not be implemented. If I know for sure something will not be implemented, I will let you know.
You can report any problem you have here. There will be no issue tracker on GitHub.
Click to expand...
Click to collapse
M66B said:
For now I have decided to not implement restrictions that are useful to prevent tracking only. There are simply too many data items that can be used for tracking and it would take too much time to develop restrictions for all these data items.
The basic idea is to restrict only things that 'define' you, so which contacts you have, where you are, which apps you use, etc.
Click to expand...
Click to collapse
Namnodorel said:
Maybe we can widen the definition of things that the core of XPL covers to "What defines you, and what can be used to spie on you"? This would include camera/audio, but not tracking.
Click to expand...
Click to collapse
M66B said:
XPrivacyLua is pretty feature complete and will be maintained and supported and when there is a need new hook definitions will be added to better protect your privacy. For the rest this FAQ applies:
https://github.com/M66B/XPrivacyLua/blob/master/FAQ.md#FAQ4
As said before, development will also depend on Xposed development, which is just minimal unfortunately.
Click to expand...
Click to collapse
XDA thanks and donations are appreciated.
XPrivacyLua is supported with Xposed only. There is no support for VirtualXposed and TaiChi.
Even if old Xprivacy isn't supported on nougat, is it possible to keep it with new Lua too until Lua grow up? Or it is not recommended ?
Thank you
Orphee said:
Even if old Xprivacy isn't supported on nougat, is it possible to keep it with new Lua too until Lua grow up? Or it is not recommended ?
Thank you
Click to expand...
Click to collapse
Noooo! First post and it is asking about using Xprivacy on Nougat? That must be demotivating to the dev! It has been told too many times in the xprivacy thread that it is not recommended to use it on Nougat and above all IT IS NOT SUPPORTED!
Sorry for using capitals but let's hope everyone sees it and this thread stays on new Lua topic.
Greetings.
Wow, I was just scrolling through some stuff, stumbled into your repo for XPrivacy/Lua and couldn't believe what I saw! M66B is developing a new app as a replacement for XPrivacy... Thank you so much, you've totally made my day and pobably quite some time into the future as well! I'll definetely also buy/donate for this version as soon as I get to use it.
Just some technical questions:
Looks like you are going more modular with this new app, and you mentioned something about downloading additional (user-made) hooks. You also said you'd keep it much more simple this time to avoid high maintenance etc. Could these external hooks then allow to get the complexity back? I totally understand your motivation, but in-depth restricting of app permissions was something I really liked about the old XPrivacy, and if some user-made hooks would make that possible I'd use them. But they'd also need the ability to add new UI elements, and not just "This hook is about the method XY, execute this code before/after to block it and this code to enable it" for that to be possible.
Orphee said:
Even if old Xprivacy isn't supported on nougat, is it possible to keep it with new Lua too until Lua grow up? Or it is not recommended ?
Click to expand...
Click to collapse
I have just added a FAQ that answers this question:
https://github.com/M66B/XPrivacyLua/blob/master/FAQ.md
m66b said:
i have just added a faq that answers this question:
https://github.com/m66b/xprivacylua/blob/master/faq.md
Click to expand...
Click to collapse
5vp4096549363413x
Namnodorel said:
Wow, I was just scrolling through some stuff, stumbled into your repo for XPrivacy/Lua and couldn't believe what I saw! M66B is developing a new app as a replacement for XPrivacy... Thank you so much, you've totally made my day and pobably quite some time into the future as well! I'll definetely also buy/donate for this version as soon as I get to use it.
Just some technical questions:
Looks like you are going more modular with this new app, and you mentioned something about downloading additional (user-made) hooks. You also said you'd keep it much more simple this time to avoid high maintenance etc. Could these external hooks then allow to get the complexity back? I totally understand your motivation, but in-depth restricting of app permissions was something I really liked about the old XPrivacy, and if some user-made hooks would make that possible I'd use them. But they'd also need the ability to add new UI elements, and not just "This hook is about the method XY, execute this code before/after to block it and this code to enable it" for that to be possible.
Click to expand...
Click to collapse
For now I will concentrate on fixing bugs and building restrictions, which is of course the most important of all. Restrictions are indeed defined and written in Lua. Currently all restrictions are built-in, but later I might add a manager, so you can manage your own definitions. There might even be a repository, which could even contain definition for things not privacy related.
You can find the current definitions here (hooks.json contains the definitions).
Just donated. More to follow along the way. Thank you!!
blackhawk_LA said:
Noooo! First post and it is asking about using Xprivacy on Nougat? That must be demotivating to the dev! It has been told too many times in the xprivacy thread that it is not recommended to use it on Nougat and above all IT IS NOT SUPPORTED!
Sorry for using capitals but let's hope everyone sees it and this thread stays on new Lua topic.
Greetings.
Click to expand...
Click to collapse
"XPrivacyLua is supported on Android 6 Marshmallow and later" you're either lying or it's a misstatement on the repo.
Also can somehow explain to me (I just switched to Android), what Lua is (if not a programming language)?
OgreTactic said:
"XPrivacyLua is supported on Android 6 Marshmallow and later" you're either lying or it's a misstatement on the repo.
Click to expand...
Click to collapse
I don't see why that is a lie or misstatement, so, could you please explain why you think it is?
Edit: I have changed the wording of the opening post a bit, so it is clearer that "Android 6 Marshmallow and later" applies to XPrivacyLua and not to XPrivacy, assuming this is what you meant.
OgreTactic said:
Also can somehow explain to me (I just switched to Android), what Lua is (if not a programming language)?
Click to expand...
Click to collapse
See this comment.
OgreTactic said:
"XPrivacyLua is supported on Android 6 Marshmallow and later" you're either lying or it's a misstatement on the repo.
Also can somehow explain to me (I just switched to Android), what Lua is (if not a programming language)?
Click to expand...
Click to collapse
Some people...
Glad to see Xposed Module development is still alive!
Thx a lot for building and developing this app.
After I've selected some apps I get an error:
XLua.Main:android.os.DeadObjectException:Transaction failed on small parcel; remote process probably died
Things that I would appreciate in future releases:
- More restriction-types like: Network connection, Telephone number/sim-operator, Serialnumber, installed apps/services, accounts
- Is it possible to hide disabled apps from the list?
- Is it possible to decide when an app will request for example the location to allow or deny the request?
th4_c0r3 said:
Thx a lot for building and developing this app.
After I've selected some apps I get an error:
XLua.Main:android.os.DeadObjectException:Transaction failed on small parcel; remote process probably died
Click to expand...
Click to collapse
Can you please capture a logcat? If not, the problem might be visible in the Xposed log as well.
Edit: where exactly do you see this error?
th4_c0r3 said:
Things that I would appreciate in future releases:
- More restriction-types like: Network connection, Telephone number/sim-operator, Serialnumber, installed apps/services, accounts
- Is it possible to hide disabled apps from the list?
- Is it possible to decide when an app will request for example the location to allow or deny the request?
Click to expand...
Click to collapse
Disabled apps are hidden from the list by default.
First: thanks for the release and minimal UI of this app.
Just one request if it is possible. Would it be possible when you start ironing out the features to include a randomisation to some privacy information. Like my main coordinates for GPS are 33N 112W. If the app could randomise the rest so the app knows my general location but not accurately as 1m?
Edit: a good reason for this is for apps like speedtest.net. it grabs GPS to find a close server. When I restrict, closes server is in NY. I don't mind if it knows I live in AZ, heck, XDA knows I live here, but knowing my exact location is bothering.
M66B said:
Can you please capture a logcat? If not, the problem might be visible in the Xposed log as well.
Edit: where exactly do you see this error?
Click to expand...
Click to collapse
The error occurs every second time I open the app and it's shown in the bottom of the app. In the Xposed log there isn't a XLua-Error.
I've sent you the logcat via email.
M66B said:
For now I will concentrate on fixing bugs and building restrictions, which is of course the most important of all. Restrictions are indeed defined and written in Lua. Currently all restrictions are built-in, but later I might add a manager, so you can manage your own definitions. There might even be a repository, which could even contain definition for things not privacy related.
Click to expand...
Click to collapse
Thank you for your answer, but I'm still kinda missing what I wanted to know: Could hooks potentially add custom UI and/or save data? I'd imagine something like saving a list of contacts and when an app requests the contact list selecting this specific list to be returned.
Namnodorel said:
Thank you for your answer, but I'm still kinda missing what I wanted to know: Could hooks potentially add custom UI and/or save data? I'd imagine something like saving a list of contacts and when an app requests the contact list selecting this specific list to be returned.
Click to expand...
Click to collapse
Yes, that would be possible. When there is a need, I will add APIs that can be used in Lua to save data in a structured way into the XPrivacyLua database, so anyone wanting to develop a new hook definition doesn't have to worry about how to do this. In fact this has already been prepared.
M66B said:
I don't see why that is a lie or misstatement, so, could you please explain why you think it is?
Edit: I have changed the wording of the opening post a bit, so it is clearer that "Android 6 Marshmallow and later" applies to XPrivacyLua and not to XPrivacy, assuming this is what you meant.
See this comment.
Click to expand...
Click to collapse
Oh okay, thanks. So I can't use the current XPrivacy (on the PlayStore) on Nougat S8? I hope I can if not, I'll wait for the XPrivacy L.
It's crazy that Android forces privacy breaching (violation is an accurate word use) "services", processes and apps at it's core. If I were to learn to use Android enough is it possible to prevent it, like it's the case on iPhone, well in appareances because when you jailbreak it you can see all the processes, but it's clearly not in completely forcing this violation of your data, be it just with the permission management that NO apps can require or force on you to run, which to me absolutely crazy that it's the case on Android.
OgreTactic said:
Oh okay, thanks. So I can't use the current XPrivacy (on the PlayStore) on Nougat S8? I hope I can if not, I'll wait for the XPrivacy L.
It's crazy that Android forces privacy breaching (violation is an accurate word use) "services", processes and apps at it's core. If I were to learn to use Android enough is it possible to prevent it, like it's the case on iPhone, well in appareances because when you jailbreak it you can see all the processes, but it's clearly not in completely forcing this violation of your data, be it just with the permission management that NO apps can require or force on you to run, which to me absolutely crazy that it's the case on Android.
Click to expand...
Click to collapse
As M66B said in the Xprivacy Thread:
M66B said:
An absolute privacy fix is turning your device off. XPrivacy is an best effort attempt to fix the most important privacy problems, like exposing your location and contacts.
Click to expand...
Click to collapse
What you could do, at least that's what I do, is to disable services (look for DisableService in PlayStore) and/or restrict as much as possible via the privacy settings (depending on ROM). For example I deny Google services the location rights and only switch them on when needed.
Also there are possibilities to run your phone without any Google services at all. Search for MicroG.
But you have to understand, that using an Android device is going to violate privacy in one form or another. Same goes with Windows and Apple devices...
I don't like it at all but that's just what the world has become. If you want to use Google Services you kinda have to accept that you can't (at least not with simple fixes) protect your whole privacy. It sucks, but that's just what it is...

Question App crashing--developer blaming numerous Pixel users

Midea Air - Apps on Google Play
Midea Air allows you to control your AC from wherever you are
play.google.com
Would some of you Pixel 6 users mind installing and seeing if it crashes on you, please?
Because it's not 100% of users encountering the issue, they blame some Pixel users due to a "classnotfound" error within their application.
Since we've all seen people copy & paste code and other silly things they shouldn't do, which cause crashes, I asked them if they used a root checker:
Yes, and we also have our test team both in China and the U.S. using a couple of problematic models which are reported by users too. But nothing more is found and none of the trails show the problem. And according to the feedback situation, not all users using these phone models are having issues, so we assume it is related to a specific user environment.
Click to expand...
Click to collapse
But they didn't expand on it beyond "yes", unfortunately.
Spoiler: my thoughts & minutia
Other than Play Store app updates and automatic Google-pushed Play/Services updates, all I've done in the past 10-14 days is update Lsposed. I've disabled and rebooted without it, and the issue remains. I've also used a stock boot.img and the app still crashes, which makes me think it's detecting an unlocked bootloader or some similar and unnecessary check(s), and moving forward with its checks which then fails due to Google no longer supporting whatever methods the app is using, and they don't know how to figure it out since it's probably copied & pasted code from many months ago and they're unwilling to suspect that old code is the cause, even though Google normally rolls out subtle security changes like this, very gradually.
Is it really just me and 5-8 other users in the entire world with this issue, or does it crash on some of you as well? I can't imagine it being such bad code that it's only rooted/unlocked bootloaders with the issue. It must be non-rooted and stock Pixel users with the issue as well, and those devices just haven't been pushed the Play Store/Services update yet.
I'd like to know if I'm just getting older and dumber or not, and if I'm truly the cause for the crash, haha. I'm open to being entirely to blame for this, but I don't want to wipe my phone and relock the bootloader for testing quite yet. Thanks for testing and voting in the poll!
Huh? If you've got a "class not found" it seems like it would be pretty easy to determine where the problem lies.
Is it some esoteric Kotlin thing or java.util.boring?
Renate said:
Huh? If you've got a "class not found" it seems like it would be pretty easy to determine where the problem lies.
Is it some esoteric Kotlin thing or java.util.boring?
Click to expand...
Click to collapse
Yeah, I figured something like that should be pretty simple, unless they have zero failures in their own testing. But...is there some new background auto-report for crashes on Android, which ties in to the email address, that I'm unaware of?
I never said anything to them other than email them my phone model, Android build, and posted a google app review (under the same name & email address) with no information other than it crashing. And they repllied, via email, with this:
Due to the uniqueness of this bug, no more code trace can be reported as you received only a line of error indicating "classnotfound". normally there will be at least a few lines more which helps with debugging.
Click to expand...
Click to collapse
Well, there could easily be conditional code for almost anything.
If you can repeatedly bomb this, why don't you get a logcat and see where the problem is?
Code:
$ logcat
The logcat should say what the class is and where it's called from.
Heck, it could even be in JNI code.
I just tested it, opened but due I am not registered and have no compatible AC, I didn't processed further. My cast vote is given, but not sure whether this is helpful, due not sure whether the app crashes when you open it or after login.
Pixel 6, A13, rooted and unlocked bootloader.
Cheers
Tom
oops!
So.... they have test teams in... China? You want to give CHINA control of your air conditioner? And access to data on your phone?
I'm same with tom1807
Yesterday Instagram app started crashing after I got a video message from a friend, I had to clear cache and reinstall it and reboot the phone, its now working fine, it was weird though

Categories

Resources