[Q] Public Wifi Security - Android Q&A, Help & Troubleshooting

I will let you know I am a novice to actually understanding how wifi works, but I was wondering if there was an app that would temporarily shut down incoming/outgoing communications (through wifi only preferably) when I am connect to a public wifi like at school or some cafe? With the exception to allow use of dolphin or any other browser surf the web for less private matters. Why? So apps like facebook, banking, email, ebay's personal information cannot be intercepted by a hacker on the same network.Thanks!
I guess the other answer I am looking for is: Do apps like facebook resend password data on use when you have remained logged in from the last session?
EDIT: I have seen some permissions apps, and settings within my rom. Was wondering if there was something that would block all apps at once like a profile setting.

Related

[Q] Browser with AJAX support. Desktop GMAIL interface

I need access to full gmail (not simple html) through web interface. Gmail app and html simple don't work for me, because they ruin the organization and order of messages when compared to desktop interface.
I have tried Skyfire and it does load full Gmail interface, but it is painfully slow, consumes enormous amount of memory and loads cpu to 100%. Pretty much unusable.
I'm not sure if ajax (or gmail in particular) on android wouldn't run any better or if it is just a matter of finding the right software and setting.
I don't have a direct solution, but have you tried the other versions of gmail, stock email, and Sense email apps?
I'm using the ICS 4.0 version of gmail, and I like it a lot.
Search google for the apk.
They may have the layout and options you want.
Thank you for suggestion. I have tried to find something that works, but other than Skyfire (not useable) and Remote Desktop (quite uncomfortable), I couldn't find anything so far.
Here is my problem. I receive ton of emails everyday, I use several workstations to access emails, I sort, label and read them, reply from different workstations. Works great having the same screen on all the machines, no matter where I am. I can start my work on one and finish on the other without loosing track of what I was doing.
I would love to work on my emails using Flyer the same way, but as of right now it is very uncomfortable for me, simply because my mail boxes don't look the same on android.
For example I have one of the mail boxes set up to show important and unread first, next emails marked with specific labels (might have several labels), then everything else (important read, unimportant unread etc). This simple thing saves me a lot of time and I know what to do next regardless of what workstation I access my email from.
When I use GMAIL app on my flyer, my mail box looks like a mess in comparison to desktop version. I get lost there so bad that I miss what needs to be done next. At this point I decided not to use GMAIL app to access work email at all.
I have tried to get to my emails through Web Browsers with desktop user agent string, but it loads in plain HTML, hence I loose the order again.
Only Skyfire browser loads the full version of gmail, but as I have said earlier is consumes more than 200mb of ram and loads CPU to 100% and makes it pretty much unusable. Not sure if it is a problem just on my Flyer or if it is how ajax is done in Skyfire.
I'm hoping to find solution (browser with good ajax?) that would allow me to access full web interface. I was just wondering if anybody knows if such thing or add-on exists. I hope maybe when CHROME browser comes out they have the good ajax support.

Motorola's Suspect APK's

I finally posted on Motorola's Forums asking about the suspect APK's with as much info as possible.
See HERE
If they for some reason take it down I will duplicate it here below:
Ok,
We Motorola owners have been silent and I think its time that we was not. Just last year I signed up for the Electrify Beta test for Motorola's 2.3.5 update for the phone. I received an email from Motorola that within 24 hours I would be getting the updated pushed to my device. At the time I got the email (around 9:30 am) I was using a custom ROM (Cyanogen Mod 7) and I proceeded to back up my phone and flash the phone back to Stock 2.3.4. Once I did that, I never got the update pushed to my device. So in turn I posted that question why I never received it on the Forums.
Mark answered it by saying this:
“Wow you've reset your phone 21 times... Whatever for? The reason you can't get the update is because you've factory reset the phone after the update was sent out. I'll reply in the other thread concerning the wifi issue. It's off topic here.
Mark
Support Forums Manager”
Click to expand...
Click to collapse
To which I answered that it was really non of his or Motorola’s business how many times I reset my device as for one – its MINE. I also asked what else Motorola was tracking from my device and why we users are not made aware of it. Of course I never got an answer to that post.
To be honest it was a Godsend that I never got the update, because as we all know Motorola relocked the Bootloader and has every intention of never making it unlocked again. However that’s a different issue and not the one at hand here.
Now I get that that I missed the update to 2.3.5 because I was on a custom ROM that is totally not supported by Motorola, and quite frankly this isn’t the issue here.
The issue is that my activity was tracked. When I got the phone and activated it I was not aware of any EULA that would state that Motorola would be tracking its users and activities. There was no such message in the Box, Manual, or on the phone on first boot. If it IS in the manual then it is so far embedded in some clause that it’s criminal that it is in there. However I am pretty sure its not.
So I would put that down to my activity was tracked WITHOUT my consent. Which to me, is a pretty big deal.
So this brings me to the meat of this post. A few users have stated there are some suspect apps (Motorola Stock) that are running in the background and require some insane Access Rights.. I will now list them along with the permissions they require (You can see these for yourself on your own phone. Applications > All > and find them on the list.). Some of these are quite the eye opener…
AdService.apk
Network Communication (Full Internet Access)
Phone Calls (ReadPhoneStateand identity)
DataCollection.apk
Your personal Information (Read Contact Data, Read Sensitive Log Data, Read user Defined Dictionary, Write Contact Data)
Services that Cost you Money (Directly Call Phone Numbers, Send SMS Messages)
Your Location (coarse (network-based) location, fine (GPS) location, mock location sources for testing)
Your messages (edit SMS or MMS, Read SMS or MMS, Receive SMS)
Network Communication (control Near Field Communication, Create Bluetooth Connections, Full Internet Access)
Your Accounts (manage the accounts list, use the authentication credentials of an account)
Storage (Modify/delete SD card Contents)
Phone Calls (intercept outgoing calls, read phone state and identity)
hardware Controls (change your audio settings)
System Tools (Bluetooth Administration, change network connectivity, change WiFi State, Change WiMAX State, Change your UI Settings, Modify Global System Settings, Mount and unmount file systems, prevent phone from sleeping, reorder running applications, retrieve running applications, write Access Point Name settings, write Sync Settings)
(Hidden)
Default (Modify battery Statistics, Read Certificates)
Your personal Information (write to user defined dictionary)
network Communication (view network state, view Wi-Fi state, view WiMAX state)
Your Accounts (discover known accounts, read Google service configuration, View configured accounts)
hardware Controls (control vibrator)
System Tools (Automatically start at boot, expand/collapse status bar, kill background processes, measure application storage space, read Home settings and shortcuts, read sync settings, read sync statistics, set wallpaper, write Home settings and shortcuts)
DataCollectorProvider.apk
Your Personal Information (read contact data)
DataCollectorService.apk
Your Personal Information (read contact data)
KpiLogger.apk
Your personal Information (Read Contact Data, Read Sensitive Log Data, Read user Defined Dictionary, Write Contact Data)
Services that Cost you Money (Directly Call Phone Numbers, Send SMS Messages)
Your Location (coarse (network-based) location, fine (GPS) location, mock location sources for testing)
Your messages (edit SMS or MMS, Read SMS or MMS, Receive SMS)
Network Communication (control Near Field Communication, Create Bluetooth Connections, Full Internet Access)
Your Accounts (manage the accounts list, use the authentication credentials of an account)
Storage (Modify/delete SD card Contents)
Phone Calls (intercept outgoing calls, read phone state and identity)
hardware Controls (change your audio settings)
System Tools (Bluetooth Administration, change network connectivity, change WiFi State, Change WiMAX State, Change your UI Settings, Modify Global System Settings, Mount and unmount file systems, prevent phone from sleeping, reorder running applications, retrieve running applications, write Access Point Name settings, write Sync Settings)
(Hidden)
Default (Modify battery Statistics, Read Certificates)
Your personal Information (write to user defined dictionary)
network Communication (view network state, view Wi-Fi state, view WiMAX state)
Your Accounts (discover known accounts, read Google service configuration, View configured accounts)
hardware Controls (control vibrator)
System Tools (Automatically start at boot, expand/collapse status bar, kill background processes, measure application storage space, read Home settings and shortcuts, read sync settings, read sync statistics, set wallpaper, write Home settings and shortcuts)
MasterClearErrorReporter.apk
Your personal Information (Read Contact Data, Read Sensitive Log Data, Read user Defined Dictionary, Write Contact Data)
Services that Cost you Money (Directly Call Phone Numbers, Send SMS Messages)
Your Location (coarse (network-based) location, fine (GPS) location, mock location sources for testing)
Your messages (edit SMS or MMS, Read SMS or MMS, Receive SMS)
Network Communication (control Near Field Communication, Create Bluetooth Connections, Full Internet Access)
Your Accounts (manage the accounts list, use the authentication credentials of an account)
Storage (Modify/delete SD card Contents)
Phone Calls (intercept outgoing calls, read phone state and identity)
hardware Controls (change your audio settings)
System Tools (Bluetooth Administration, change network connectivity, change WiFi State, Change WiMAX State, Change your UI Settings, Modify Global System Settings, Mount and unmount file systems, prevent phone from sleeping, reorder running applications, retrieve running applications, write Access Point Name settings, write Sync Settings)
(Hidden)
Default (Modify battery Statistics, Read Certificates)
Your personal Information (write to user defined dictionary)
network Communication (view network state, view Wi-Fi state, view WiMAX state)
Your Accounts (discover known accounts, read Google service configuration, View configured accounts)
hardware Controls (control vibrator)
System Tools (Automatically start at boot, expand/collapse status bar, kill background processes, measure application storage space, read Home settings and shortcuts, read sync settings, read sync statistics, set wallpaper, write Home settings and shortcuts)
So, to paraphrase Mark….
Wow these Apps need some insane permissions…. WHATEVER FOR??
And aren’t they named well?
I suggest that someone provides FULL DISCLOSURE on what all these apps do. They are NOT required to run the device (if you are rooted you can freeze the processes with no ill effects and can infact remove them) and they most certainly are NOT part of Android’s original OS.. So whatever ARE they for and what ARE they collecting???
So Motorola, the ball is in your court so to speak, I and a great many others would be really curious on telling us what they are for…
Your move..
Click to expand...
Click to collapse
Just a thought on this issue also. maybe a reason you could provide to this **** from Motorola is the fact that these phones have problems out of the box. Random reboots for example. That in itself would be reason enough for me to reset my phone in homes it will go away. Another thing you could point out is that some app developers are using Airpush ads that some people might think are a form of trojan and might also to a reset to try to eliminate them. Bottom line though is you are totally correct and that it's none of their damn business what we do with these phones. Sprint can ***** at us and threaten to void warranties or whatever but Moto has nothing to do with it. I'm curious to know what they respond with. I'm going to post in that forum too
It's funny. Those were the first apps that I had frozen. I have NO problem with my phone since I froze those. It's been about 2 months now and no problems.
My post on that forum rules LOL
Even if they do respond I'll be willing to bet you don't get a straight answer that exposes the truth.
On a side note, are the apps you have listed everything that does the questionable snooping or are there more parts to the puzzle?
I'm a MoPho-er
FernBch said:
Even if they do respond I'll be willing to bet you don't get a straight answer that exposes the truth.
On a side note, are the apps you have listed everything that does the questionable snooping or are there more parts to the puzzle?
I'm a MoPho-er
Click to expand...
Click to collapse
If I knew how to debug and show what those apps did, I would have more "clout" I guess..
I'm sure there's more in there, but those are obvious (and poorly named) with what they do.
I'm not expecting an answer either, but just sitting idly by saying nothing doesn't achieve anything either. It was worth a shot, and if more people post a response in the original thread, then well... its gonna make it harder for them to ignore it as well.
He posted a reply... Usual PR Snuff and tried to make it look like I was the bad one for breaking an NDA on software that was publicly released two months ago..
I think not, so I replied in kind.... Funny how it took a posting of APK's permissions and concerns about privacy (which was brought up before) for him to garner any response on it...
Lets see if this can carry on...
mistaken, your privacy is important and must be protected, in Europe there are strict legislative on this point, and I hope that clarifies why if the European community discovers that unbeknownst to many users, are read everything that trigger sanctions. I also do not want others to know of my sites visited, etc..
sorry for my English
ZeroManArmy said:
It's funny. Those were the first apps that I had frozen. I have NO problem with my phone since I froze those. It's been about 2 months now and no problems.
Click to expand...
Click to collapse
One of the four has something to do with corp. mail now get an error message. Option to FC every thing working though.
Sent from my MB855 using xda premium
Cythrawl,
Honestly, if I would have known that the Electrify would have been like this, I would have stuck with the Hero S. sometimes...I regret switching from the Hero S to the Electrify.
IBMguy said:
Cythrawl,
Honestly, if I would have known that the Electrify would have been like this, I would have stuck with the Hero S. sometimes...I regret switching from the Hero S to the Electrify.
Click to expand...
Click to collapse
If I had have known too, I would have stuck with the Mesmerize until we get the SGII
Love it when people have no idea!
"We Motorola owners have been silent and I think its time that we was not."
"If I knew how to debug and show what those apps did, I would have more "clout" I guess.. "
I would not worry about Moto, the govenment is watching you right now through your tv.
halfdriven said:
Love it when people have no idea!
"We Motorola owners have been silent and I think its time that we was not."
"If I knew how to debug and show what those apps did, I would have more "clout" I guess.. "
I would not worry about Moto, the govenment is watching you right now through your tv.
Click to expand...
Click to collapse
Seeing I don't have TV (or a TV connected to Cable / Sat / OTA) I doubt that...
Thankyou for your really useful post...

[Q] Stock Email passwords still stored in clear text.

I realize that this has been an 'issue' for a while now, but I would like to know if there are any new ways secure and use stock email client with Exchange ActiveSync and not have credentials stored in clear text on the device. The same goes for IMAP and POP accounts using the app.
Yes, this is really only an issue on rooted devices, Google's official answer is to enable Device Encryption and that there are other email clients out there that handle credentials better. I personally switched to Touchdown, but would rather use the stock client.
I am trying to come up with a MDM solution for my company and really don't want to have to block devices if I don't have to. But as it stands my only options are have the user buy a 3rd party email client, force encryption and/or block rooted / jailbroken devices or use Citrix and OWA. I've spent a couple days researching this and haven't come up with anything promising that puts a smile on my face.
Any other Exchange Admins out there? How have you dealt with this?
For those who were not aware of your network username, password and domain being stored in clear text. Using Sql Lite open the Email app, Open EmailProvider.db and select HostAuth. Within you will find your connection info staring back at you, clear as day.
Android Issue Log:
https://code.google.com/p/android/issues/detail?id=10809
Google's Response:
https://code.google.com/p/android/issues/detail?id=10809#c128

[Q] Internet Browser

So I updated the One Max to 4.4 and I after a factory reset, the Internet Browser, (not Chrome), does not sync my Gmail bookmarks anymore, is there a workaround or has someone else noticed this? My DNA, 4.4 also, lost the same function. Also, I know this sounds paranoid, but is there a way to see if a web browser from the play store is URL tracking, data mining, or if my web traffic is passing through servers capable of harvesting my passwords. I like the Mercury browser, but the privacy policy sounds like the garbage Dolphin does. Any advise? FYI, I must have a web browser that I can set a custom user agent or the user agent can be set as a Windows computer. I don't care for Chrome by the way. Thank you for any help.
I'm no expert on browsers... But I've found this Browser does most of what your looking for: https://play.google.com/store/apps/details?id=nu.tommie.inbrowser
Current Device : HTC One MAX / Retired HTC Devices: DNA, Rezound, Thunderbolt, Incredible, Eris
Thank you for replying, I guess I am asking if it is possible that the web browser I prefer, Mercury, is passing my data on to the developers. Is there a way to tell if it is phoning home or is my connection passing through one of their servers so they can use a packet sniffer to pick out information such as passwords? I know this may sound paranoid, but between Chrome and Dolphin's phoning home, I was looking to see if anyone had any information. Update, after testing, i found that Maxthon will also work well for my requirement, so which do any of you think is better, Maxthon or Mercury?
Bump

NoRoot Firewall

Disclaimer: I know nothing on how to configure firewalls except for adding apps to the whitelist/blacklist.
Tried using NRFW and I noticed a few things:
1. I've consumed 12.54GB and 9.77GB was by NRFW. What's happening please.
2. I've tagged some apps that can only connect when I'm on wifi, yet I'm still getting notifications when I'm on mobile data. For example, the Facebook app and some games.
3. How do I determine which IP address should be allowed or blocked? For example, I see IP addresses pointing to Akamai and my ISP.
4. Is it a good idea to turn off background data? I restricted it on mobile data and allowed it when on wifi but some apps would not load properly even when I'm connected to a wifi network.
Thanks in advance! And please excuse me if I posted this in the wrong forum.
EDIT: I'm referring to Grey Shirt's NoRoot Firewall.
I read up a bit and learned that 1e100.net are Google's servers. I understand that these point to ads too. I also noticed my ISP's name shows up under these.
Do I allow these or do I block them?
First of all: sorry for answering so late ;-) ...:
- in my opinion, your traffic from internet is being redirected through this NoRoot Personal Firewall unto your smartphone
- so, the 9.77GB you mentioned were 'routed/directed' through the NRPFW - the rest was not (? - maybe for Android-Updates or anything?)
- as you could most probably see, all of these 9.77GB were allowed to pass through from the internet servers (akamai or google or microsoft or ibm or yahoo or many more..) to your smartphone ('s apps / system apps)
- notifications about your mobile connection(s) MAY simply be wrong (as i found out) - seemingly a bug in the NRPFW-app (?)
- akamai is one of the " intermediate servers" or main server for a couple of websites:
for example, when you open the 'WashingtonPost'-website on your smartphone, (all) contents from their website are upon an akamai-server, because 'WashingtonPost' does not have a server on its own inside their office building maybe big enough to handle all traffic from their website to all readers in the world
- your Internet Service Provider has intermediate servers for (any) web content, too - so, you might want to allow their internet addresses
- furthermore, background data is transferred when you have an email-app and this app (gmail or yahoo-app, e.g.) is transferring data even if you had closed the email-app (so you cannot see it anymore on your launcher) or it's even running in background and checking if there's new mail when auto-started while your smartphone is booting.

Categories

Resources