The Following User Says Thank You to naabi For This Useful Post: | ||
![]() |
2010-07-30
, 21:02
|
Posts: 1,746 |
Thanked: 2,100 times |
Joined on Sep 2009
|
#2
|
Motivation behind this post are the news related to security issues related to software available at Android Market and Apple's App Store. Both have had similar cases, where third party software has collected and sent ahead user information from the phone.
All installed applications run in a sandbox, i.e. installed packages have their own UID and in addition there's the Android Java API that has access to limited set of features.
Applications don't have access to phone features by default, so developer needs to grant these privileges via configuration.
If I recall, these privileges are shown to user when installing package. Basically application developers can make sure that other applications don't have access to their data and user has the visibility what these applications are granted to do. Still things like this happens.
So, no we can enter Maemo/Meego (mostly Meego, since Maemo doesn't seem to address this problem?) world, which is an open system from application developer point of view - at least compared to Android and iPhone. Multiple programming languages and API's and easy root access.
Here at TMO software is open source, and malicious software can be identified by browsing source code. What about OVI and other potential sources of closed software?
How is Nokia controlling security of these applications, and does the end-user have any visibility to application capabilities? If OVI store kicks off, there's no way every application can be reviewed manually, so what methods are there to guarantee user security.
And I'm also afraid that Nokia has woken up to these too late, and that will be holding back the OVI Store for Maemo/Meego based devices.
![]() |
2010-07-30
, 23:55
|
Posts: 80 |
Thanked: 40 times |
Joined on Feb 2010
@ UK
|
#3
|
![]() |
2010-07-31
, 00:02
|
|
Posts: 4,672 |
Thanked: 5,455 times |
Joined on Jul 2008
@ Springfield, MA, USA
|
#4
|
![]() |
2010-07-31
, 01:20
|
Posts: 310 |
Thanked: 383 times |
Joined on Jan 2010
|
#5
|
![]() |
2010-08-11
, 08:25
|
Posts: 219 |
Thanked: 94 times |
Joined on Nov 2009
@ Helsinki, Finland
|
#6
|
Same as on your PC. Same as the App Store. Same as the Marketplace. Do you trust the vendor?
![]() |
2010-08-11
, 15:40
|
Posts: 540 |
Thanked: 288 times |
Joined on Sep 2009
|
#7
|
The Following User Says Thank You to rambo For This Useful Post: | ||
If we take a look at Android security from third party point of view, definitely some attention has been given to it. I'm not expert in this area, but following is my knowledge. All installed applications run in a sandbox, i.e. installed packages have their own UID and in addition there's the Android Java API that has access to limited set of features. Applications don't have access to phone features by default, so developer needs to grant these privileges via configuration. If I recall, these privileges are shown to user when installing package. Basically application developers can make sure that other applications don't have access to their data and user has the visibility what these applications are granted to do. Still things like this happens.
So, no we can enter Maemo/Meego (mostly Meego, since Maemo doesn't seem to address this problem?) world, which is an open system from application developer point of view - at least compared to Android and iPhone. Multiple programming languages and API's and easy root access. Here at TMO software is open source, and malicious software can be identified by browsing source code. What about OVI and other potential sources of closed software? How is Nokia controlling security of these applications, and does the end-user have any visibility to application capabilities? If OVI store kicks off, there's no way every application can be reviewed manually, so what methods are there to guarantee user security. There could be something planned / implemented, honestly I don't know. But if there's nothing, it's pretty obvious what's going to happen. And I'm also afraid that Nokia has woken up to these too late, and that will be holding back the OVI Store for Maemo/Meego based devices.
Ham > Turkey