![]() |
Re: Idea: N900 security update (openssl, browser etc)
Quote:
Not perfect test honestly. |
Re: Idea: N900 security update (openssl, browser etc)
Did anyone ever look at reviving gtkmozembed by hooking it up to embedlite?
|
Re: Idea: N900 security update (openssl, browser etc)
Quote:
|
Re: Idea: N900 security update (openssl, browser etc)
Quote:
Even if rootsh isn't installed, the user may not be safe. The default setup allows it to be installed without root privileges. In my opinion rootsh should be removed from the repositories but this probably wouldn't even be enough. If you ask me, Maemo is very broken in this respect. It's not that hard for an attacker to create some malware, create multiple Garage accounts and then vote it up for promotion to Extras. Actually, they probably don't even need to do that. They can just enable Extras-devel and install anything from that. It's part of the reason why I want to replace Maemo with Debian. |
Re: Idea: N900 security update (openssl, browser etc)
So I've been playing around with web browsers in Easy Debian (jessie). One option that I like is Midori which is available in jessie-backports. It passes all of the Cipher Suites tests from SSL Labs. It fails the Mixed Content Tests but it's not clear what are the implications these failures. I think I'm going to make it my main browser.
Here are some Midori usage tips if anyone is interested:
If anyone has any spare time, it would be nice to update the Midori and libwebkit packages in Extras to the latest versions. |
Re: Idea: N900 security update (openssl, browser etc)
Quote:
Quote:
|
Re: Idea: N900 security update (openssl, browser etc)
Quote:
I tried with webkitgtk-2.4.11 from debian sid. |
Re: Idea: N900 security update (openssl, browser etc)
Any idea how is the security today or is it at the same level as before? Did anyone do anything to these security matters or is there somewhere like the basic safety and security instructions on using N900? I have just been using it and haven't really thought of how to make it more secure. I would like to know: I have cssu-testing (maybe devel).
1. Is there a way to update the certificates of the device/microb? 2. If you have rootsh installed do you need to set a root password (haven't seen instructions for that shared or mentioned too much on this forum)? 3. Is Glenwall firewall valid and are there good instructions somewhere for a basic user what to use while just browsing? 4. Are people still interested these things or should I just wait for Maemo Leste to be a proper solution? 5. I have been using Mobile Hotspot for sharing my wifi to N810. It uses only WEP encryption so is there a better option which people use? 6. I have set up with the stock email app connection to my secure email provider with imap and ssl etc. Is there some problems with that email app and should I use some other (it just works so fine and would not want to change to something not as good)? 7. Is using a browser with easy debbie more secure by default or is it related to a newer browser (netsurf 3.8)? 8. Noticed that in some post it was mentioned that "just update global trust list with mozillas and you are good to go". Seems as a good option compared not doing anything. Is it good option and how to do it, or is there a better option and how to do that? Would really like to know what I should have understood in the beginning when started to use this device. |
Re: Idea: N900 security update (openssl, browser etc)
Concerning #2
rootsh doesn't need a password ... (I wouldn't ...nor device password...there are a good long list of threads and posts titled like : "forgot password , locked out of device , help!?!?" next thing you know you forget it....then you are up a fast flowing body of water without a handheld device to navigate with) concerning all your other many questions ... essentially what you want is someone to do the leg work for you and hunt down answers and forum links to answers... And it may take a lot of time to do just that.. Some here may know one or two... or a couple of quick answers... But... Why not use the the search button to your right? That is how people figure things out here. Asking for answers for the list of questions you have ... before looking and trying the answers provided in forum posts by those who have posted the most recent successes .. is working backwards. I would suggest looking first. That is the whole point of keeping a decade plus of past threads and posts... to research them. If you have a hard time after hunting down your questions... and after finding answers ... whether due to the solutions being outdated ... or no answers at all found... Then definitely ask for help. But with your particular questions... I think you won't find it too difficult to hunt down the requisite posts concerning the topics... They quite common questions ... So there should be plenty of documentation readily available .. via the search function here. |
Re: Idea: N900 security update (openssl, browser etc)
I think that would just not be wise. I have been here now for a year. There are people who have been maybe ten and are still using their device daily. I believe that if they use it daily they have probably sorted out some security stuff. Now if some new person starts to use N900 I don't see a real value for him to need to use lots and lots of time reading different threads in this forum trying to find answers to many questions if there are people who know the answers and could easily give them.
I have tried to search answers but in many threads it goes the same way as in this: a good title making you think that from that thread you will find answers. Well I didin't find answers, just talk about many things what would be good to be done but I don't know what happened. Did someone find solutions? I see making my questions (which I thought first to put on a new thread "Security of N900 in 2019" to make it easier for everyone to have one thread under which to disguss about it but because I would have probably got an answers "do not start a new thread if there is already a similar thread" I searched one which had ended with only questions and ideas in the air without solutions or answers) in this particular thread a very wise thing to do. If someone knows the answers and will answer them in this thread which is left as kind of unfinished state then if there comes a next person searching for answers from this same thread then he will find the answers and the title of the thread is not kind of misleading or a disappointment. If there is a thread or a wikipage of the security of N900 which clearly guides a new N900 user through things explaining these very serious matters well, then my bad. Just say there is one and I will shame. But if there isn't such, there should be. To make a new N900 user to search about this kind of matters from many many different threads which may or may not give answers which may or may not be updated (some may have answers predating cssu, cssu testing or cssu devel solutions). I think that this forum would have more value if there would be a procedure of keeping some wikipages updated that way that always when there comes a new user asking the same guestions you could just say "first read all these pages for new users". Now I have got answers from some or just "read through the forum" sometimes. I just don't think it is a wise thing to do and I think this should change. You have done your part really well endsormeans with your guide for N8x0 which you updated now when there was a dead link. You can always point a person to read it. So should be with security matters if they are not dealt with installing cssu updates (maybe they are but it was left unaswered in this thread, on a mere idea stage). If someone knows these answers I don't know why he would not like to answer. Only proper reason would be that the answers are already there easily found. I claim they aren't and that there are only few here who really knows and who knows which threads are dead ends and which threads have real answers which are still up to date and which are unneccessary or may even make things worse. I think I have right to ask. You have the right not to answer. From my point of view to go through threads which do not give answers is wasted time and not wise thing to do. You may oppose and see a value there. And we may stay thinking about this matter differently and its perfectly ok. I understand people are thired of answering same questions to new users. I'm trying to help to make it stop. "The perfect setup for N900", they are good. If someone would like to make one about N900 security that would be very helpfull to all I think. |
All times are GMT. The time now is 11:18. |
vBulletin® Version 3.8.8