LightBlog

samedi 27 février 2016

Give Your TWRP 3.0.0 New Colors with Lovely Dark Themes

blue_landscape

One of the best TWRP’s features, apart helping us be flashoholics, is theme support. XDA Senior Member fichl created a nice set of dark stock themes that can change your current TWRP 3.0.0 into a beauty.



from xda-developers http://ift.tt/1RvHwS9
via IFTTT

Best Microsoft Apps for Android

microsoft app thumbnail

Microsoft is a large company, and while we may just think of them as making Windows and failing at making Windows Phone success that is now all they do. They have a lot of apps that are available for Android. Some of these apps are cross platform, but if you wanted to know which Microsoft apps available on Android are best, check out this video. Ronald talks about the apps and gives demonstrations of their features. There are all sorts of cool and interesting apps that you probably have never heard of on the XDA forum “The Best Apps You’ve Never Heard of”.

Be sure to check out other great XDA TV Videos.

Best Apps You’ve Never Heard of Forum Link

Please subscribe to XDA TV.



from xda-developers http://ift.tt/1Uqr6wW
via IFTTT

vendredi 26 février 2016

Baidu Browser found to be Leaking Personal User Data – What it means for you

baidu

You’ve probably heard of Baidu before. Known somewhat as China’s Google (though that may change if Google finally decides to re-enter the market this year), the mammoth search engine giant/advertising platform/online encyclopedia has dabbled in developing numerous applications designed around its service ecosystem for both Android and Windows (much like Google).

These apps have millions of users, most of whom are located in China, but as evidenced by the install count of Baidu Browser and other apps on the Play Store, there are a lot of users outside of China as well. Which makes a recent report from Toronto’s Citizen Lab all the more worrying. According to the group, Baidu Browser has been caught leaking sensitive personal information from its users.


Baidu Not Track

Man-in-the-middle attack on Baidu Browser's Updater

Man-in-the-middle attack on Baidu Browser’s Updater

The firm has summarized its research of Baidu Browser’s security failings into several key findings:

  • Baidu Browser, a web browser for the Windows and Android platforms, transmits personal user data to Baidu servers without encryption and with easily decryptable encryption, and is vulnerable to arbitrary code execution during software updates via man-in-the-middle attacks.
  • The Android version of Baidu Browser transmits personally identifiable data, including a user’s GPS coordinates, search terms, and URLs visited, without encryption, and transmits the user’s IMEI and a list of nearby wireless networks with easily decryptable encryption.
  • The Windows version of Baidu Browser also transmits a number of personally identifiable data points, including a user’s search terms, hard drive serial number model and network MAC address, URL and title of all webpages visited, and CPU model number, without encryption or with easily decryptable encryption.
  • Neither the Windows nor Android versions of Baidu Browser protect software updates with code signatures, meaning an in-path malicious actor could cause the application to download and execute arbitrary code, representing a significant security risk.
  • The Windows version of Baidu Browser contains a feature to proxy requests to certain websites, which permits access to some websites that are normally blocked in China.
  • Analysis of the global versions of Baidu Browser indicates that the data leakage is the result of a shared Baidu software development kit (SDK),1 which affects hundreds of additional applications developed by both Baidu and third parties in the Google Play Store and thousands of applications in one popular Chinese app store.

If you’ve installed the browser, or any application that was developed using the Baidu SDK (such as ES File Explorer), then it’s possible some of your personal data may have been compromised. The security leakage found in applications developed using Baidu’s SDK is massive, and the fact that the data was transmitted unencrypted (or with easily decryptable encryption) shows how little effort Baidu took in securing your personal data. Was it all transmitted to the Chinese government? While we can’t confirm either way, Baidu denies any such allegation according to a statement made to Citizen Lab.


 

Baidu’s and Don’ts

To be fair to Baidu, they have patched some of the security holes leading to leaked sensitive data. Keyword “some.” After Citizen Lab performed its due diligence and reported the security issues to the company, Baidu updated its application. Citizen Lab re-tested Baidu’s browser, and found the following for the Android version:

  1.  Leaks sensitive data on startup and Phones home with sensitive data about every page view
    • These issues appear to have been resolved insofar as the same information appears to be communicated by the application to Baidu servers but now it is encrypted using SSL.
  2. Leaks sensitive data and address bar contents when inputting into address bar
    • This issue remains unresolved. In our communications with Baidu, they indicated they would not be fixing this issue. However, in addition to the contents of user searches, the browser still also includes sensitive data such as a user’s IMEI in an easily decryptable format in the request URL
  3. Insecurely checks for software updates
    • This issue has been resolved. Software updates are now checked using HTTPS.

And for the Windows version:

  1. Leaks address bar contents when inputting into address bar
    • This issues remains unresolved. In our communications with Baidu, they indicated they would not be fixing this issue.
  2. Communicates with Baidu servers via an easily decryptable protocol and Phones home information about every page view that includes hardware serial numbers
    • These issues remain unresolved. Our analysis indicates that data is still transmitted with easily decryptable encryption. In addition, every protobuf request sent to the dr.br.baidu.com domain now includes the user’s hard drive serial number and MAC access unencrypted in the header, a behavior not identified in the earlier version 7.6.100.2089 of the application that we analyzed in this report.
  3. Insecurely checks for software updates
    • The application still checks for software updates unencrypted over HTTP; however, it now verifies the authenticode digital signature of the downloaded update to have been signed by Baidu.

So in short, most of the critical security compromises allowing malicious attackers from taking over your browser have been patched, and your data is now safe from leakage (albeit still being transmitted to Baidu’s servers itself). If you’re worried about third-parties from getting a look at your personal data, then you’re safe for now. But if you’re worried about the Chinese government or Baidu selling your data, well, then you’ll remain skeptical of the app. We hope such a security issue doesn’t turn you off of applications made by Chinese developers, but rather makes you more critical of what apps you’re installing and what permissions they request.

Ever used Baidu? If so, let us know in the comments!

 



from xda-developers http://ift.tt/1oNBEL4
via IFTTT

Hard-mod your Nexus 6P to Greatly Reduce Thermal Throttling

gorgtech-nexus-6p-thejik6k

XDA Senior Member Gorgtech has posted a picture guide on how they hard-modded their Nexus 6P to improve cooling and greatly reduce thermal throttling. Check it out if you think your device overheats too much!



from xda-developers http://ift.tt/1TEmR0g
via IFTTT

The G5’s Modularity has Lots of Potential, but it Needs to get Better Friends

What Do You Think of the LG G5’s Modularity? Thoughtful Addition, or Gimmick?

lgg5

The LG G5 now allows you to detach the bottom chin of the otherwise-unibody design in order to remove the battery and also expand the phone’s functionality through its “friends”… little hardware modules that can add camera controls, better sound through a special DAC, a bigger battery and more. The feature also allows LG to create even more modules later on, expanding the functionality and perhaps the lifespan of the device.

But would you use the modules? Is this an actually-good selling point?

For some module ideas and discussion, head over to this thread!



from xda-developers http://ift.tt/1OARltw
via IFTTT

ASUS Publishes Their Marshmallow Update Roadmap

Android Marshmallow

ASUS says they will be updating the following devices to Android 6.0 Marshmallow in the 2nd quarter of this year: PadFone S (PF500KL), ZenFone 2 (ZE550ML, ZE551ML), ZenFone 2 Deluxe (ZE551ML), ZenFone 2 Deluxe Special Edition (ZE551ML), ZenFone 2 Laser (ZE500KG, ZE500KL, ZE550KL, ZE551KL, ZE600KL, ZE601KL), ZenFone Selfie (ZD551KL), ZenFone Max (ZC550KL) and the ZenFone Zoom (ZX551ML).



from xda-developers http://ift.tt/1QL0jfg
via IFTTT