<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.newlc.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>NewLC - symbian 9, security platform, signing - Comments</title>
 <link>http://www.newlc.com/topic-18011</link>
 <description>Comments for &quot;symbian 9, security platform, signing&quot;</description>
 <language>en</language>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44766</link>
 <description>&lt;p&gt;&lt;div class=&quot;bb-quote&quot;&gt;&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;br /&gt;
During reading the Symbian guides I haven&#039;t found any mentioning, that they demand the developer to be trusted. I don&#039;t think Symbian wants to know the business plans, they just want money. And everything can be solved by the appropriate summ of dollars/euro.&lt;br /&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;/p&gt;

&lt;p&gt;I don&#039;t think Symbian cares either.&lt;br /&gt;
After all, symbian doesn&#039;t create any phones, nor do they have any end user contact.&lt;/p&gt;

&lt;p&gt;But the guys who do care though, is the device manufacturers and platform creators (s60, uiq, nokia, S-E, samsung, etc).&lt;/p&gt;

&lt;p&gt;Nokia for example, writes at one of the pages above: &quot;When the tests are passed, the application will be Symbian Signed. If the application requires DRM and/or TCB capability, a legal agreement [with Nokia] must also be in place before the application can be certified.&quot;&lt;/p&gt;

&lt;p&gt;The thing is, that the whole platform security depends on that only a few and very select services have the TCB capability.&lt;br /&gt;
It doesn&#039;t matter if _you_ aren&#039;t malicious, they also want to be very sure that you also wont mess anything up, and leaving a big gaping back door open to break the security of the phone.&lt;br /&gt;
And if you do... They want to be able to track you down...&lt;/p&gt;

&lt;p&gt;But of course it isn&#039;t impossible to get. &lt;br /&gt;
Just a lot of red tape...&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;</description>
 <pubDate>Tue, 26 Feb 2008 10:18:25 +0100</pubDate>
 <dc:creator>alh</dc:creator>
 <guid isPermaLink="false">comment 44766 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44729</link>
 <description>&lt;p&gt;&lt;div class=&quot;bb-quote&quot;&gt;&lt;blockquote class=&quot;bb-quote-body&quot;&gt;I will.&lt;/blockquote&gt;&lt;/div&gt;&lt;br /&gt;
By all means, do. Don&#039;t let a few fairy-tale-addicted cowards in this forum stand in the way to your luck.&lt;/p&gt;

&lt;p&gt;Will you report back the result? Regardless of outcome? Would be very nice.&lt;br /&gt;
&lt;/p&gt;</description>
 <pubDate>Sat, 23 Feb 2008 09:11:06 +0100</pubDate>
 <dc:creator>rbrunner</dc:creator>
 <guid isPermaLink="false">comment 44729 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44725</link>
 <description>&lt;p&gt;&lt;div class=&quot;bb-quote&quot;&gt;&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;br /&gt;
I at least wouldn&#039;t even dare to contact them and apply for TCB - the holy grail of Symbian - without a very convincing business plan and an impressive track record in the mobile scene that shows that I am serious.&lt;br /&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br /&gt;
+&lt;br /&gt;
&lt;div class=&quot;bb-quote&quot;&gt;&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;br /&gt;
From the conversations I have had with Nokia, you will need to submit a business plan/case AND a development plan to assess the feasability of the design.&lt;br /&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br /&gt;
During reading the Symbian guides I haven&#039;t found any mentioning, that they demand the developer to be trusted. I don&#039;t think Symbian wants to know the business plans, they just want money. And everything can be solved by the appropriate summ of dollars/euro.&lt;/p&gt;

&lt;p&gt;&lt;div class=&quot;bb-quote&quot;&gt;&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;br /&gt;
You can start by sending a request to &lt;script type=&quot;text/javascript&quot;&gt;eval(unescape(&#039;%64%6f%63%75%6d%65%6e%74%2e%77%72%69%74%65%28%27%3c%61%20%68%72%65%66%3d%22%6d%61%69%6c%74%6f%3a%74%65%73%74%69%6e%67%40%6e%6f%6b%69%61%2e%63%6f%6d%22%3e%74%65%73%74%69%6e%67%40%6e%6f%6b%69%61%2e%63%6f%6d%3c%2f%61%3e%27%29%3b&#039;))&lt;/script&gt; (IIRC)&lt;br /&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br /&gt;
I will. &lt;br /&gt;
It seems to me that nobody ever tried to request such capabilities, because there are too many fairy tails about difficulties, and no success stories. &lt;/p&gt;</description>
 <pubDate>Fri, 22 Feb 2008 16:41:45 +0100</pubDate>
 <dc:creator>Hex</dc:creator>
 <guid isPermaLink="false">comment 44725 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44683</link>
 <description>&lt;p&gt;Basically at the barest minimum you need to be a Symbian Partner AND a Nokia Launchpad or Pro member for them to even look at TCB.&lt;/p&gt;

&lt;p&gt;The reason it that these can serverly compromize the phone and the API&#039;s you need are under a Symbian Partner licence so you need to have a solid business record with them before they will talk to you.&lt;/p&gt;

&lt;p&gt;From the conversations I have had with Nokia, you will need to submit a business plan/case AND a development plan to assess the feasability of the design.&lt;/p&gt;

&lt;p&gt;You can start by sending a request to &lt;script type=&quot;text/javascript&quot;&gt;eval(unescape(&#039;%64%6f%63%75%6d%65%6e%74%2e%77%72%69%74%65%28%27%3c%61%20%68%72%65%66%3d%22%6d%61%69%6c%74%6f%3a%74%65%73%74%69%6e%67%40%6e%6f%6b%69%61%2e%63%6f%6d%22%3e%74%65%73%74%69%6e%67%40%6e%6f%6b%69%61%2e%63%6f%6d%3c%2f%61%3e%27%29%3b&#039;))&lt;/script&gt; (IIRC)&lt;/p&gt;</description>
 <pubDate>Wed, 20 Feb 2008 19:13:47 +0100</pubDate>
 <dc:creator>paul</dc:creator>
 <guid isPermaLink="false">comment 44683 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44679</link>
 <description>&lt;p&gt;I don&#039;t see any non-trivial question right now.&lt;/p&gt;

&lt;p&gt;This page&lt;br /&gt;
&lt;a href=&quot;http://developer.symbian.com/main/signed/&quot; class=&quot;bb-url&quot;&gt;http://developer.symbian.com/main/signed/&lt;/a&gt;&lt;br /&gt;
tells quite clearly that for publisher IDs it&#039;s TrustCenter who is running the show now, and Verisign is out.&lt;/p&gt;

&lt;p&gt;And the following link that N/A gave a few posts above already quite nicely sums up Nokia&#039;s policy for granting special capabilities:&lt;br /&gt;
&lt;a href=&quot;http://www.forum.nokia.com/main/technical_services/testing/cap_granting.html&quot; class=&quot;bb-url&quot;&gt;http://www.forum.nokia.com/main/technical_services/testing/cap_granting.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Maybe you are sad because there is probably a very real danger that you won&#039;t be able to convince Nokia to deal with you. I at least wouldn&#039;t even dare to contact them and apply for TCB - the holy grail of Symbian - without a very convincing business plan and an impressive track record in the mobile scene that shows that I am serious.&lt;br /&gt;
&lt;/p&gt;</description>
 <pubDate>Wed, 20 Feb 2008 18:02:31 +0100</pubDate>
 <dc:creator>rbrunner</dc:creator>
 <guid isPermaLink="false">comment 44679 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44678</link>
 <description>&lt;p&gt;Heh... the experts have finished  &lt;img src=&quot;/sites/all/modules/smileys/packs/example/sad.png&quot; title=&quot;Sad&quot; alt=&quot;Sad&quot; /&gt;  As I ask some nontrivial question - there&#039;s no answer. It&#039;s sad, very sad...  &lt;img src=&quot;/sites/all/modules/smileys/packs/example/sad.png&quot; title=&quot;Sad&quot; alt=&quot;Sad&quot; /&gt; &lt;/p&gt;</description>
 <pubDate>Wed, 20 Feb 2008 16:55:44 +0100</pubDate>
 <dc:creator>Hex</dc:creator>
 <guid isPermaLink="false">comment 44678 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44654</link>
 <description>&lt;p&gt;I&#039;ve downloaded &quot;The complete guide to Symbian Signed&quot;. As I understand, I need &quot;Express signed&quot; to be able to request TCB and other previledged capabilities. In the guide they say that I need to buy the publisher ID from Trust Center:  &lt;br /&gt;
&lt;a href=&quot;https://www.trustcenter.de/cs-bin/PublisherID.cgi/en/155102&quot;&gt;https://www.trustcenter.de/cs-bin/PublisherID.cgi/en/155102&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The publisher ID is also provided by Verisign at step 2&lt;br /&gt;
&lt;a href=&quot;http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/&quot;&gt;http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;What is the difference between these publisher ID&#039;s?&lt;br /&gt;
&lt;/p&gt;</description>
 <pubDate>Tue, 19 Feb 2008 17:11:00 +0100</pubDate>
 <dc:creator>Hex</dc:creator>
 <guid isPermaLink="false">comment 44654 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44647</link>
 <description>&lt;p&gt;&lt;div class=&quot;bb-quote&quot;&gt;&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;br /&gt;
I never heard that the DRM, AllFiles and TCB capabilities have a price, where you pay the price and then get it. I think how to treat you will be decided on a case-by-case basis by the &quot;powers that be&quot;.&lt;br /&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br /&gt;
For Windows Mobile there were two types of code signing: &lt;br /&gt;
1) code signing for applications that don&#039;t need previledged API. &lt;br /&gt;
2) code signing for applications that uses previledged API. &lt;/p&gt;

&lt;p&gt;&lt;div class=&quot;bb-quote&quot;&gt;&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;br /&gt;
Furthermore, if you write a driver for Symbian, are you sure that you will be able to use it, regardless of capabilities? I am not sure, but as far as I know Nokia&#039;s 3rd edition phones won&#039;t load drivers from anything than ROM. If this is true, are you ready to produce ROM images containing your driver and flash a limited number of phones with it?&lt;br /&gt;
Just out of curiositiy: What driver is it anyway? What in a phone or connected to a phone needs a driver?&lt;br /&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br /&gt;
I want to make File system plugin. It should be loaded by RFs::AddFileSystem(). It should be able to be loaded from C:\Sys\.&lt;br /&gt;
I&#039;ve dumped security information for efat32.fsy by petran and found out, that to make my own FSY I&#039;ll need:&lt;br /&gt;
TCB&lt;br /&gt;
CommDD&lt;br /&gt;
PowerMgmt&lt;br /&gt;
ProtServ&lt;br /&gt;
DiskAdmin&lt;br /&gt;
AllFiles&lt;br /&gt;
&lt;/p&gt;</description>
 <pubDate>Tue, 19 Feb 2008 14:15:00 +0100</pubDate>
 <dc:creator>Hex</dc:creator>
 <guid isPermaLink="false">comment 44647 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44646</link>
 <description>&lt;p&gt;I never heard that the DRM, AllFiles and TCB capabilities have a price, where you pay the price and then get it. I think how to treat you will be decided on a case-by-case basis by the &quot;powers that be&quot;.&lt;/p&gt;

&lt;p&gt;Furthermore, if you write a driver for Symbian, are you sure that you will be able to use it, regardless of capabilities? I am not sure, but as far as I know Nokia&#039;s 3rd edition phones won&#039;t load drivers from anything than ROM. If this is true, are you ready to produce ROM images containing your driver and flash a limited number of phones with it?&lt;/p&gt;

&lt;p&gt;Just out of curiositiy: What driver is it anyway? What in a phone or connected to a phone needs a driver?&lt;br /&gt;
&lt;/p&gt;</description>
 <pubDate>Tue, 19 Feb 2008 13:45:29 +0100</pubDate>
 <dc:creator>rbrunner</dc:creator>
 <guid isPermaLink="false">comment 44646 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44641</link>
 <description>&lt;p&gt;Symbian made the certification too complex. At Windows Mobile we&#039;ve just sent an email to microsoft where we&#039;ve described the API we wanted to use. Then they approved it and we&#039;ve paid the money. In a week we were able to implement drivers for windows mobile. &lt;/p&gt;

&lt;p&gt;I don&#039;t understand what is &quot;Forum Nokia/S60 evaluation of the request&quot; step. Also I couldn&#039;t find any prices for DRM, AllFiles and TCB capabilities certificate. The only thing i&#039;ve found is:&lt;br /&gt;
&lt;a href=&quot;http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/&quot;&gt;http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/&lt;/a&gt;&lt;br /&gt;
What capabilies will be granted by such ACS?&lt;br /&gt;
&lt;/p&gt;</description>
 <pubDate>Tue, 19 Feb 2008 12:03:28 +0100</pubDate>
 <dc:creator>Hex</dc:creator>
 <guid isPermaLink="false">comment 44641 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44630</link>
 <description>&lt;p&gt;Just getting a certificate for TCB is not enough for developing a device drivers.&lt;/p&gt;

&lt;p&gt;For Nokia phones, and getting programs signed with &quot;sensitive capabilities&quot; like TCB, read this for starters:&lt;br /&gt;
&lt;a href=&quot;http://www.forum.nokia.com/main/technical_services/testing/cap_granting.html&quot;&gt;http://www.forum.nokia.com/main/technical_services/testing/cap_granting.html&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;</description>
 <pubDate>Tue, 19 Feb 2008 07:25:47 +0100</pubDate>
 <dc:creator>N_A</dc:creator>
 <guid isPermaLink="false">comment 44630 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-44616</link>
 <description>&lt;p&gt;Is it possible to buy the ceritificate for TCB capability? I want to develop drivers for Symbian 9.x&lt;/p&gt;</description>
 <pubDate>Mon, 18 Feb 2008 15:18:24 +0100</pubDate>
 <dc:creator>Hex</dc:creator>
 <guid isPermaLink="false">comment 44616 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-38253</link>
 <description>&lt;div class=&quot;smf-content&quot;&gt;habier: The installer creates a checksum of every installed binary, which is stored on the internal disk, so tampering with binaries on the memory card means that you can&amp;#039;t run them anymore.&lt;/div&gt;</description>
 <pubDate>Wed, 04 Apr 2007 14:47:44 +0200</pubDate>
 <dc:creator>puterman</dc:creator>
 <guid isPermaLink="false">comment 38253 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-38252</link>
 <description>&lt;div class=&quot;smf-content&quot;&gt;hi,&lt;br /&gt;&lt;br /&gt;thanks Eric. I supposed it was not possible to modify ur own exe in v9.&lt;br /&gt;&lt;br /&gt;Perhaps dumping the flash, parsing the fat and modifying the file from outsite the phone,and writing the flash again... its a not factible way but it would be interesting to test it &lt;img src=&quot;/sites/all/modules/smf_filter/smf_smileys/tongue.gif&quot; alt=&quot;Tongue&quot; border=&quot;0&quot; /&gt;&lt;br /&gt;&lt;br /&gt;Thanks for your answers.&lt;/div&gt;</description>
 <pubDate>Thu, 29 Mar 2007 23:24:14 +0200</pubDate>
 <dc:creator>habier</dc:creator>
 <guid isPermaLink="false">comment 38252 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011#comment-38251</link>
 <description>&lt;div class=&quot;smf-content&quot;&gt;&lt;div class=&quot;quoteheader&quot;&gt;Quote&lt;/div&gt;&lt;div class=&quot;quote&quot;&gt;But i have a question yet. WHat it happens when u must to correct a bug or to add a small modification after signing? I guess its necesary to sign again?&lt;/div&gt;Yes!&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;quoteheader&quot;&gt;Quote&lt;/div&gt;&lt;div class=&quot;quote&quot;&gt;But in the moment the application was installed, if the binaries (main .exe for example) are modified (by a way or by other) in the aplication installation directory directly, the system will load this modified binary?? or it will keep a checksum of the installed filed yet?&lt;/div&gt;You won&amp;#039;t have write access to your binaries so no possibility to modify your executables. That is a drawback with Symbian Signed: you cannot deliver updates or fix bug frequently. A new cerification is necessary for each release.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</description>
 <pubDate>Thu, 29 Mar 2007 21:46:15 +0200</pubDate>
 <dc:creator>eric</dc:creator>
 <guid isPermaLink="false">comment 38251 at http://www.newlc.com</guid>
</item>
<item>
 <title>symbian 9, security platform, signing</title>
 <link>http://www.newlc.com/topic-18011</link>
 <description>&lt;div class=&quot;smf-content&quot;&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://www.newlc.com/topic-18011&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.newlc.com/topic-18011#comments</comments>
 <category domain="http://www.newlc.com/forums/security-payment">DRM / Security / Payment</category>
 <pubDate>Mon, 26 Mar 2007 19:08:57 +0200</pubDate>
 <dc:creator>habier</dc:creator>
 <guid isPermaLink="false">17498 at http://www.newlc.com</guid>
</item>
</channel>
</rss>
