Active Topics

 


Reply
Thread Tools
qwazix's Avatar
Moderator | Posts: 2,622 | Thanked: 5,447 times | Joined on Jan 2010
#1
Ok, aegis can be a PITA. For example right now I wonder why my app is not getting location access even though the manifest seems to be ok.

On the other hand however, I like the idea of controlling the privileges each app has and it seems that aegis has fine grained control. I would love it even more if I could deny some of the credentials at install time, or even more through a settings page. (Long tap an app, see all the requested permissions and turn off the ones you don't like - for example all apps on android ask pretty much for everything, why the heck would a flashlight app need access to contacts??)

Aegis also enables you to create secure dbus calls so that you can make sure no other app exploits your access to vital functions (e.g. calls)

That's a whole different story than disallowing the user (or root) to do things, I don't like THAT obviously.

Anyway is it opensource? Any chance we will see a similar permission system on our desktops soon?
__________________
Proud coding competition 2012 winner: ρcam
My other apps: speedcrunch N9 N900 Jolla –– contactlaunch –– timenow

Nemo UX blog: Grog
My website: qwazix.com
My job: oob
 

The Following 2 Users Say Thank You to qwazix For This Useful Post:
HtheB's Avatar
Moderator | Posts: 3,718 | Thanked: 7,420 times | Joined on Dec 2009 @ Bize Her Yer Trabzon
#2
I don't see the point of AEGIS on our devices, since we didn't needed that on the N900 too....
__________________
www.HtheB.com
Please donate if you think I'm doing a good job.
 
Posts: 124 | Thanked: 75 times | Joined on Nov 2011 @ Edmonton Canada
#3
Originally Posted by HtheB View Post
I don't see the point of AEGIS on our devices, since we didn't needed that on the N900 too....
Keep in mind this was originally going to be a massed produced device for the everyday user...
 

The Following 2 Users Say Thank You to slashd0t For This Useful Post:
Posts: 1,298 | Thanked: 2,277 times | Joined on May 2011
#4
There are comprehensive desktop/server security frameworks. For example RBAC (used in illumos).
 

The Following User Says Thank You to shmerl For This Useful Post:
Posts: 1,313 | Thanked: 2,978 times | Joined on Jun 2011 @ Finland
#5
Originally Posted by qwazix View Post
Anyway is it opensource? Any chance we will see a similar permission system on our desktops soon?
I think it's opensource, at least it's MeeGo counterpart is.

Anyway, agree with your sentiments. Too bad on harmattan the system is implemented to cripple user, not to empower him to control apps.
 

The Following User Says Thank You to ajalkane For This Useful Post:
Posts: 196 | Thanked: 224 times | Joined on Sep 2010 @ Africa
#6
Originally Posted by shmerl View Post
There are comprehensive desktop/server security frameworks. For example RBAC (used in illumos).
Or SELlinux. Or AppArmor. Both should be a 'make config' away on Harmattan (though of course some other components would also need to be built with specific support for them).
 

The Following 2 Users Say Thank You to buchanmilne For This Useful Post:
qwazix's Avatar
Moderator | Posts: 2,622 | Thanked: 5,447 times | Joined on Jan 2010
#7
Originally Posted by HtheB View Post
I don't see the point of AEGIS on our devices, since we didn't needed that on the N900 too....
we didn't need it on the N900 because most of the apps were built by the community and were open. Also the small uaer base makes it pointless dor someone to develop malware for tje N900. On the other hand, if the N900 was in the hands of tens of millions of ignorant hands, it would be trivial for someone to make a nicely named app that sends paid sms in the background.
__________________
Proud coding competition 2012 winner: ρcam
My other apps: speedcrunch N9 N900 Jolla –– contactlaunch –– timenow

Nemo UX blog: Grog
My website: qwazix.com
My job: oob
 

The Following User Says Thank You to qwazix For This Useful Post:
Posts: 479 | Thanked: 1,284 times | Joined on Jan 2012 @ Enschede, The Netherlands
#8
I like just about every security system, as long as I, the owner am in full control. Things like Aegis, TPM, secure boot and whathaveyou are fine, as long as I can override them and/or provide the keys. This implies the option to disable it altogether, but that should never be the only option.

Problem is: these security options are far too complex for "mere user" to comprehend. Ergo, they will buy the devices regardless the amount of control, simply because they have no clue in what ways these features are limiting them or their devices. And thus manufactures can do just about everything they want. It's sad actually.
 
marxian's Avatar
Posts: 2,448 | Thanked: 9,523 times | Joined on Aug 2010 @ Wigan, UK
#9
Originally Posted by qwazix View Post
it would be trivial for someone to make a nicely named app that sends paid sms in the background.
Was it not Nokia that used our devices to secretly send SMS?
__________________
'Men of high position are allowed, by a special act of grace, to accomodate their reasoning to the answer they need. Logic is only required in those of lesser rank.' - J K Galbraith

My website

GitHub
 

The Following 3 Users Say Thank You to marxian For This Useful Post:
erendorn's Avatar
Posts: 738 | Thanked: 983 times | Joined on Apr 2010 @ London
#10
- as mentionned, the meego implementation is open source (some doc here)
- it is definitely a good idea
- the very stu**d part is that you can't add your own certificate authority (like yourself, or some community repo)!! If you could, man that would be great.
 

The Following User Says Thank You to erendorn For This Useful Post:
Reply

Tags
bendover4nokia, fvck aegis


 
Forum Jump


All times are GMT. The time now is 14:01.