![]() |
#1 |
Junior Member
![]() Posts: 1
Karma: 10
Join Date: Dec 2020
Device: none
|
Spyware in firmware
Looks like the latest models and maybe also older models use a Linux, with changed kernel, which is not public.
I read that other products from China send data to specific ips. How to prevent that, would rooting that device helpful to solve this issue? |
![]() |
![]() |
![]() |
#2 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,910
Karma: 3933245
Join Date: Sep 2012
Location: Salzburg AT
Device: Bigme 3/3, Boox 4/14, Like-/Meebook 2/8, Tolino 1/10, Ki/Ko 0/8
|
Do you do bank business with this device?
|
![]() |
![]() |
Advert | |
|
![]() |
#3 |
Junior Member
![]() Posts: 4
Karma: 10
Join Date: Aug 2020
Device: Onyx Boox Nova 2
|
I can't speak for the original poster, but it seems to me that bank information is not the only thing I worry about keeping private and secure. Login information for websites, personal data like tax IDs and account #s at places other than banks just to name a few. And some of that information would be highly convenient to store on an eInk reader, because I tend to carry that device with me everywhere.
About the only thing I can suggest is to keep WiFi disabled, which may or may not work for your use case. --Avonelle |
![]() |
![]() |
![]() |
#4 |
Connoisseur
![]() ![]() ![]() ![]() ![]() ![]() Posts: 87
Karma: 527
Join Date: Sep 2019
Device: Max3
|
I agree, privacy is more than just protecting bank accounts. Passwords, documents, contacts, browsing habits etc is worth at least some concern. Depending on what device your talking about, for onyx, they mostly run some version of android. Your best bet for protecting data is to use an app like "NoRoot Firewall" and use strict firewall rules. How strict of rules depends on your paranoid level
Edit: or like above poster said, just disable wifi connectivity altogether |
![]() |
![]() |
![]() |
#5 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,910
Karma: 3933245
Join Date: Sep 2012
Location: Salzburg AT
Device: Bigme 3/3, Boox 4/14, Like-/Meebook 2/8, Tolino 1/10, Ki/Ko 0/8
|
Then I suggest not using any device, because there is hardly one that was not produced in China.
Even a battery-free smartphone does not make calls to China. |
![]() |
![]() |
Advert | |
|
![]() |
#6 |
Connoisseur
![]() ![]() ![]() ![]() ![]() ![]() Posts: 87
Karma: 527
Join Date: Sep 2019
Device: Max3
|
|
![]() |
![]() |
![]() |
#7 | |
Junior Member
![]() Posts: 7
Karma: 10
Join Date: Dec 2020
Device: Onyx Max Lumi
|
I'd say it is very likely Onyx software contains spyware and backdoors.
Quote:
Rooting the device will not help unless you completely replace all software including bootloaders, which is currently not possible as far as I am aware. |
|
![]() |
![]() |
![]() |
#8 | |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,419
Karma: 6513838
Join Date: Mar 2016
Device: More than I need, but not as many as I would like.
|
Quote:
https://www.sammobile.com/where-are-samsung-phones-made |
|
![]() |
![]() |
![]() |
#9 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,910
Karma: 3933245
Join Date: Sep 2012
Location: Salzburg AT
Device: Bigme 3/3, Boox 4/14, Like-/Meebook 2/8, Tolino 1/10, Ki/Ko 0/8
|
I don't care whether they call China or the NSA - I don't particularly like either.
But NSA is closer and the danger is probably greater Last edited by ottischwenk; 12-13-2020 at 04:57 PM. |
![]() |
![]() |
![]() |
#10 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 4,466
Karma: 6900052
Join Date: Dec 2009
Location: The Heart of Texas
Device: Boox Note2, AuraHD, PDA,
|
There are a number of functions on my new Onyx Boox Note 2 (10.3") that won't work without phoning home. This includes the fingerprint detection, screensaver app. (still can add your own locally), and others.
Luck; Ken |
![]() |
![]() |
![]() |
#11 |
Zealot
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 122
Karma: 43580
Join Date: Apr 2016
Device: KPW3, Kobo Clara HD, Onyx Boox Nova 2
|
I run it and monitored the traffic using Wireshark for a while, and there wasn't much really, just some analytics, but just in case I run it over wireguard connected to PiHole, with onyx domains blacklisted. Only when I update device do I whitelist them and block again after I'm done. Additionally network traffic is allowed only over VPN (wireguard) connection. Funny enough, google play services is much worse then Onyx.
|
![]() |
![]() |
![]() |
#12 |
Zealot
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 117
Karma: 2086978
Join Date: Nov 2019
Location: Roma, Italia
Device: kindle oasis 2,ONYX boox max lumi
|
Boh, I think until own country or european union has an own Operating System, it's impossible block the stream of data to China or Usa. The hardware and Os aren't european....
|
![]() |
![]() |
![]() |
#13 |
Guru
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 942
Karma: 149883
Join Date: Jul 2013
Location: Rotterdam
Device: HiSenseA5ProCC, Cracked OnyxNotePro, Note5, Kobo Glo, Aura
|
Hmmm. I still have to look into this further. For now I NetGuard will have to block unwanted information exchange.
It's not only my Onyx Note Pro that might call home, but also my Hisense A5 Pro cc eInk mobile. Interestingly, this phone manufactured by one of China's state-sponsored/-owned firms also includes an app PayGuard that keeps telling me if apps have a permission that might be damaging my privacy: Like apps that send my location information even when they are not being used. For now, it seems that the Onyx Boox ereaders and the Hisense eInk mobiles are safer than Samsung's Google services based devices. You can disable Google on Onyx and can't even install them on Hisense. However, I still have to check with the devices running over a proxy, whether I am blocking all that I want to. |
![]() |
![]() |
![]() |
#14 |
cosiñeiro
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,396
Karma: 2451781
Join Date: Apr 2014
Device: BQ Cervantes 4
|
Note that telemetry is not spyware. We could argue if it is somehow malware if there's no way to disable it, but not spyware if used to:
- report crashes - collect and send anonymous reports, like usage patterns within an app In that respect we (outside China) use google services to do that. Chinese people use other service providers. Baidu push service is common to perform bug reports in mainland China. The important stuff is what the program tracks, not which service is used to deliver what's tracked. One can use Firebase to report a bug or to report all installed applications in a device. In the same vein it can use baidu push service. In the case of google nobody will say "it's phoning china", but if used to steal user data it is the same spyware with or without pushing that data to chinese servers. |
![]() |
![]() |
![]() |
#15 | |
Connoisseur
![]() ![]() ![]() ![]() ![]() ![]() Posts: 87
Karma: 527
Join Date: Sep 2019
Device: Max3
|
Quote:
|
|
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Firmware Update Instructions and the latest Firmware Versions | mitchwah | Ectaco jetBook | 113 | 10-24-2023 09:02 PM |
Trojan spyware in calibre mac OS build | zaster | Calibre | 9 | 06-28-2019 03:38 AM |
Firmware glitch - typing text slow on some firmware+device combinations | mdp | Onyx Boox | 11 | 11-11-2017 12:48 AM |
candy.js spyware embedded in ebooks | fjtorres | News | 69 | 08-13-2015 11:52 PM |
Kindle 3 scans 2 worms and 1 spyware after using Calibre? | dancingbacon | Devices | 4 | 06-13-2011 08:05 AM |