<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.newlc.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>NewLC - Symbian Platform Security - hacked? - Comments</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked</link>
 <description>Comments for &quot;Symbian Platform Security - hacked?&quot;</description>
 <language>en</language>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42794</link>
 <description>&lt;p&gt;And..  the smart developer develops for whatever phone system that sells at the moment, and doesn&#039;t lock himself to one system...&lt;br /&gt;
Right now it is still quite easy to decide what smartphone system to put the most focus on though.&lt;br /&gt;
Check the numbers for symbian phones vs windows mobile and linux...&lt;/p&gt;

&lt;p&gt;But of course, never forget to keep your eye on the horizon....&lt;/p&gt;

&lt;p&gt;But all this &quot;this system is better then that&quot; is mostly amusing for anyone with some insight in the business...&lt;br /&gt;
&lt;/p&gt;</description>
 <pubDate>Mon, 05 Nov 2007 09:25:56 +0100</pubDate>
 <dc:creator>alh</dc:creator>
 <guid isPermaLink="false">comment 42794 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42790</link>
 <description>&lt;p&gt;Hi, Eric! &quot;name just one good ... Linux&quot; It is bored. I think you are clever enough to google it. But if you wish, look at this wiki.xda-developers.com for example. I am not going to compare symbian and microsoft phones. I just remember words from one user. After inserting 2 Gb card, phones are freezing for time. User said that it is faster and cheaper to use P535 with 4Gb card. For me, symbian is not the best, and now sertificates do not let programmers to do it better.&lt;br /&gt;
I think it will be like Sun Microsystems and solaris. After losing everything, they will open symbian, but it will be too late.&lt;br /&gt;
By the way, I was a symbian developer for 3 years(3650(my own old phone),6600,P800,6630...). I remember a lot of bugs and disadvantages of symbian. I used your site too, it was very usful. But now I stop any symbian development and begin to learn windows and linux mobile. You can do what ever you want, remove my comment for example. It is up to you.&lt;/p&gt;</description>
 <pubDate>Mon, 05 Nov 2007 00:02:45 +0100</pubDate>
 <dc:creator>free_f9999</dc:creator>
 <guid isPermaLink="false">comment 42790 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42789</link>
 <description>&lt;p&gt;Can you name just one good and reliable smartphone running Linux ? (not a feature phone running java apps only, not a developer preview model, just a smartphone for average user). &lt;/p&gt;

&lt;p&gt;And considering that Windows Mobile is fast compared to Symbian OS is probably just a joke (Or we never used the same phone - but I admit that I don&#039;t know the P535 - which can be  fast it has a 520MHz processor in it....).&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;</description>
 <pubDate>Sun, 04 Nov 2007 20:22:13 +0100</pubDate>
 <dc:creator>eric</dc:creator>
 <guid isPermaLink="false">comment 42789 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42785</link>
 <description>&lt;p&gt;Yep, you&#039;re right! Having read your comment I think I&#039;ll forget all those joyful years that I&#039;ve spent with Symbian development and change to other better &lt;span style=&quot;font-style:italic&quot;&gt;&lt;span style=&quot;font-weight:bold&quot;&gt;operational&lt;/span&gt;&lt;/span&gt; (sic!) systems. Damn, why does such an idiot comment an article that doesn&#039;t even know what he&#039;s talking about?  &lt;img src=&quot;/sites/all/modules/smileys/packs/example/puzzled.png&quot; title=&quot;Puzzled&quot; alt=&quot;Puzzled&quot; /&gt; &lt;/p&gt;</description>
 <pubDate>Sat, 03 Nov 2007 23:11:41 +0100</pubDate>
 <dc:creator>tote</dc:creator>
 <guid isPermaLink="false">comment 42785 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42784</link>
 <description>&lt;p&gt;Hi! To my mind you need not to hack symbian. Just throw away this slow and stupid operational system and buy linux or windows communicator, like ASUS P535 etc.&lt;/p&gt;</description>
 <pubDate>Sat, 03 Nov 2007 22:37:03 +0100</pubDate>
 <dc:creator>free_f9999</dc:creator>
 <guid isPermaLink="false">comment 42784 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42713</link>
 <description>&lt;p&gt;It&#039;s a failing in Nokia&#039;s firmware update format which will be addressed quickly no doubt now that it&#039;s public.&lt;br /&gt;
It doesn&#039;t break the capability model.&lt;/p&gt;

&lt;p&gt;No technology solution to security will ever be 100% secure because there are humans involved in the chain. An ex nokia empoyee who is familiar with the flashing mechanism could also &quot;turn bad&quot;. &lt;/p&gt;

&lt;p&gt;Hacks like this are not mainstream problems for the casual user. But they totally undermine the use of platsec for enforcing DRM.&lt;br /&gt;
I can now write some code which will stream the PCM audio from a DRM codec into a file and then dump it as an MP3 yay!&lt;/p&gt;</description>
 <pubDate>Wed, 31 Oct 2007 21:17:35 +0100</pubDate>
 <dc:creator>twmd</dc:creator>
 <guid isPermaLink="false">comment 42713 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42689</link>
 <description>&lt;p&gt;not exactly, davinci team flashes (and unlock) FW to almost any Sony Ericsson phone. Hacked FW for UIQ3 just one of options.&lt;/p&gt;</description>
 <pubDate>Wed, 31 Oct 2007 13:55:22 +0100</pubDate>
 <dc:creator>wl</dc:creator>
 <guid isPermaLink="false">comment 42689 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42686</link>
 <description>&lt;p&gt;Wow, they&#039;re selling the hack, that&#039;s amusing!  &lt;img src=&quot;/sites/all/modules/smileys/packs/example/smile.png&quot; title=&quot;Smiling&quot; alt=&quot;Smiling&quot; /&gt; Or not?  &lt;img src=&quot;/sites/all/modules/smileys/packs/example/puzzled.png&quot; title=&quot;Puzzled&quot; alt=&quot;Puzzled&quot; /&gt; &lt;/p&gt;</description>
 <pubDate>Wed, 31 Oct 2007 13:43:47 +0100</pubDate>
 <dc:creator>tote</dc:creator>
 <guid isPermaLink="false">comment 42686 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42679</link>
 <description>&lt;p&gt;btw, for UIQ3 was made the same long time ago:&lt;br /&gt;
&lt;a href=&quot;http://www.seuniverse.com/forums/thread9850.html&quot;&gt;http://www.seuniverse.com/forums/thread9850.html&lt;/a&gt;&lt;/p&gt;</description>
 <pubDate>Wed, 31 Oct 2007 11:27:02 +0100</pubDate>
 <dc:creator>wl</dc:creator>
 <guid isPermaLink="false">comment 42679 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42643</link>
 <description>&lt;p&gt;Yes, it is indeed bad, of course a malicious person could hand out patched updates...&lt;/p&gt;

&lt;p&gt;One immediately ask, even if they don&#039;t encrypt the flash image data as suggested, shouldn&#039;t they at least have a signed checksum? or any checksum?&lt;br /&gt;
From the description, it seems there is no such checks...  not even an unsigned checksum.&lt;br /&gt;
I should be able to use this for a lot more advanced hacks then just changing installer settings.&lt;/p&gt;

&lt;p&gt;Even the flash updates to my old calculator has signed checksums...&lt;/p&gt;

&lt;p&gt;Edit: There seems to be some checks, judging from the comments with people who have turned their N-phones into bricks...&lt;/p&gt;</description>
 <pubDate>Mon, 29 Oct 2007 16:04:35 +0100</pubDate>
 <dc:creator>alh</dc:creator>
 <guid isPermaLink="false">comment 42643 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42628</link>
 <description>&lt;p&gt;Well, you can&#039;t grant &lt;span style=&quot;font-weight:bold&quot;&gt;&lt;span style=&quot;font-style:italic&quot;&gt;any&lt;/span&gt;&lt;/span&gt; capabilities with your DevCert, unless you have a (&lt;span style=&quot;font-style:italic&quot;&gt;VeriSign&lt;/span&gt;) Publisher ID that enables you to do so. You know, the most powerful capabilities are &lt;span style=&quot;font-weight:bold&quot;&gt;still phone manufacturer dependent&lt;/span&gt;. On the other hand, as I&#039;m sure you know Symbian signing will change considerably: you can&#039;t have a DevCert w/o (&lt;span style=&quot;font-style:italic&quot;&gt;TrustCenter&lt;/span&gt;) Publisher ID. In other words, for a hacked firmware package you don&#039;t have to be &quot;&lt;span style=&quot;font-style:italic&quot;&gt;traceable&lt;/span&gt;&quot;, for a new DevCert you do.&lt;/p&gt;

&lt;p&gt;And I&#039;m unsure if it&#039;s a local problem, either. I haven&#039;t updated the firmware of my phone, so my assumption can be very easily wrong, but: &lt;span style=&quot;font-weight:bold&quot;&gt;can I hack a firmware update package (say, for N95) and then make it downloadable for others&lt;/span&gt;?&lt;/p&gt;</description>
 <pubDate>Mon, 29 Oct 2007 11:56:58 +0100</pubDate>
 <dc:creator>tote</dc:creator>
 <guid isPermaLink="false">comment 42628 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42625</link>
 <description>&lt;p&gt;At least you have to modify your phone firmware to do this, so it isn&#039;t really much more useful then a DevCert, which also grants you any capabilities for a given phone.&lt;br /&gt;
And it also does not mean a security breach that could be used by a malicious attacker.&lt;/p&gt;</description>
 <pubDate>Mon, 29 Oct 2007 11:25:13 +0100</pubDate>
 <dc:creator>alh</dc:creator>
 <guid isPermaLink="false">comment 42625 at http://www.newlc.com</guid>
</item>
<item>
 <title>Re: Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked#comment-42623</link>
 <description>&lt;p&gt;There was a very similar problem with the first Windows Smartphone models (SPV&#039;s) - there was a proviisioning file in the root that specified the security model and this could be updated in the ROM image on the pc then reflashed.&lt;/p&gt;

&lt;p&gt;Certainly sounds plausable.&lt;/p&gt;</description>
 <pubDate>Mon, 29 Oct 2007 11:05:19 +0100</pubDate>
 <dc:creator>paul</dc:creator>
 <guid isPermaLink="false">comment 42623 at http://www.newlc.com</guid>
</item>
<item>
 <title>Symbian Platform Security - hacked?</title>
 <link>http://www.newlc.com/en/symbian-platform-security-hacked</link>
 <description>&lt;p&gt;Platform Security hacked?! According to Symbaali, it is, so even &lt;code&gt;AllFiles&lt;/code&gt; and &lt;code&gt;DRM &lt;/code&gt;are grantable. Read on for more details!&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://www.newlc.com/en/symbian-platform-security-hacked&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.newlc.com/en/symbian-platform-security-hacked#comments</comments>
 <category domain="http://www.newlc.com/en/taxonomy/term/12">Misc.</category>
 <category domain="http://www.newlc.com/en/taxonomy/term/41">Symbian OS</category>
 <category domain="http://www.newlc.com/en/taxonomy/term/368">Hack</category>
 <category domain="http://www.newlc.com/en/taxonomy/term/367">Symbian Platform Security</category>
 <category domain="http://www.newlc.com/en/taxonomy/term/143">Symbian Signed</category>
 <pubDate>Mon, 29 Oct 2007 09:25:37 +0100</pubDate>
 <dc:creator>tote</dc:creator>
 <guid isPermaLink="false">19411 at http://www.newlc.com</guid>
</item>
</channel>
</rss>
