![]() |
#3556 |
Ex-Helpdesk Junkie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
|
Try installing the latest version of the hack, from the Snapshots thread.
Or install it using the MobileRead Package Installer. Problem: the old packager had a bug that made it only work for older versions/build numbers, and the recent firmware update bumped it over the threshold. |
![]() |
![]() |
![]() |
#3557 |
Member
![]() Posts: 21
Karma: 10
Join Date: May 2011
Device: Kindle 3
|
thanks for your reply.
Unfortunately, I do not know what you are referencing. I have unsuccessfully attempted to install Update_jailbreak_0.13.N_k3g_install.bin, I thought that was the latest. If you happen to have a link pointing me to the information you mentioned, I will use it and try to resolve this problem. Again, thank you. |
![]() |
![]() |
Advert | |
|
![]() |
#3558 | |
Going Viral
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
|
Quote:
Forum index page ; Just below the blue bar ; Set the prefix filter to "tools" ; Click the "show threads" ; Find the "Snapshots" thread near the top of those shown. PS: The snapshot items always carry the current release number, it will not be increased until they are released. So yes, the things in the snapshot thread **are newer** - unlike the impression the version number might give. |
|
![]() |
![]() |
![]() |
#3559 |
Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 37
Karma: 27450
Join Date: Aug 2013
Device: Kindle DX graphite
|
This may be off topic here but I couldn't find a better fit, I was told to ask in the "hack area". https://www.mobileread.com/forums/sho...20#post3122620
Twitter, Wikipedia, etc. recently disabled SSL 3.0 http://blog.fastmail.com/2014/10/15/...vulnerability/ which old kindles used to access them. Amazon apparently fixed it for Kindle Keyboard in the latest software update v3.4.1., but their tech support told me that they are unlikely to do it for Kindle DXG that I have. Is a there a user made hack that restores access to those sites? |
![]() |
![]() |
![]() |
#3560 | |
Going Viral
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
|
Quote:
It is labeled "New Thread". - - - - I think the only thing that v3.4.1 did was install a current set of trusted web certificates. I.E: That would not change what TLS protocol was nogoiated by the client. - - - - You do not mention what browser you are using on the DX. But if your using the Amazon provided one, you should consider using a different browser. (After updating the trusted certificate set yourself - that may be the only thing you need to change.) We have had alternate browsers posted here, I do not know if any of them work (or are supposed to work) on the DX/DXG. You would have to do some search/research here to learn about what devices the various alternative browsers support. |
|
![]() |
![]() |
Advert | |
|
![]() |
#3561 |
Ex-Helpdesk Junkie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
|
re: alternate browsers, I am only aware of Midori and Skipstone, both of which only support the KT and on.
But I want to know when the heck update 3.4.2 came out for the K3. ![]() Bunch of miscellaneous fixes all over the place, not just certs: Spoiler:
As for the 3.4.1 update, as knc1 said, it only patched the certs (and libsoup and libcurl ![]() Last edited by eschwartz; 07-11-2015 at 11:18 PM. |
![]() |
![]() |
![]() |
#3562 | |
Going Viral
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
|
Quote:
I should have known, twobob was doing nearly all of his work for the KT (last to have audio support). Ah, right - I had forgotten about 3.4.2 - last winter sometime, it only got mentioned here a few times. Amazon did post sources labeled 3.4.2 - which **should** contain the patched sources. Not to say that it does, but with the labeling of the patches, it should be easy to know where to look. Then to re-spin those source code changes for the K2/DX/DXG (they all run the same 2.5.8 build) - that might be a bit ambitous - even for Amazon. Hmm.... The 'magic' this poster seeks might be in that ...ssl... patch. (That would be a good place to disable a client protocol.) |
|
![]() |
![]() |
![]() |
#3563 |
Ex-Helpdesk Junkie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
|
I remember the 3.4.1 update, just mentioned a few times. Don't remember hearing a peep about 3.4.2 -- and I keep a close eye on the threads in this forum!
Anyway, agreed it will probably be somewhere in the SSL patches. ![]() |
![]() |
![]() |
![]() |
#3564 |
Going Viral
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
|
Two thoughts occured to me after sleeping on the question -
Disabling a client protocol in the ssl libraries would do nothing for the non-encrypted clients. There must be other places the change was made. (If it is in the Amazon code, we are SoL.) It might help if we knew what was common between 2.5.8, 3.4.1 and 3.4.2, after discarding identical files, it might be easier to judge if it is even worth looking deeper into the fix. I will try to get some numbers on that question today by running the cataloging/audit scripts on a tree of the three source bundles. - - - - A third thought occured to me while writing this post. If Amazon is still selling re-furbished DX/DXG devices, did they re-furbish the firmware also? Perhaps some of our members who have recently purchased one of these re-furbished devices could tell us it the problem was 'fixed' by the re-furbisher. I have at least one each, of each K2, DX and DXG model. We could do a search for the "binary solution" if the re-furbished devices have been fixed and the owner will share a copy of the re-furbished firmware that is installed. (I am certain that I still have the scripting to copy-out a DX image, the script I wrote for twobob.) |
![]() |
![]() |
![]() |
#3565 |
Ex-Helpdesk Junkie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
|
I suspect if Amazon had fixed refurbished the DXG firmware, they would be more than happy to offer it as an OTA upgrade.
![]() |
![]() |
![]() |
![]() |
#3566 |
Going Viral
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
|
Here is the catalog of 2.5.8, 3.4.1, and 3.4.2 source file releases.
Bottom line: Looks like too many differences to find and fix 2.5.8 |
![]() |
![]() |
![]() |
#3567 | |
Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 37
Karma: 27450
Join Date: Aug 2013
Device: Kindle DX graphite
|
Quote:
After some experimenting I found that while urls (www.m.wikipedia.org) and links from Google searches do not work, Wikipedia links from Yahoo searches do work, and once I am in internal Wikipedia links also work (?????). Unfortunately, this only works for Wikipedia and I have a feeling it won't last, some blogs and forums I used to read are now blinking out of access from saved urls, and both Google and Yahoo. Customer service told me that they are not selling new DXs since 2013, and I remember reading a review back then which complained that Amazon did not bother to make even the most basic updates before they started reselling them. Last edited by Jedidiyah; 07-16-2015 at 02:30 PM. |
|
![]() |
![]() |
![]() |
#3568 |
Going Viral
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
|
I was wrong about the alternate browsers, none of them work on a (physical) keyboard device.
Do you have a few more example urls that do not work? One is a sort of small sample. I suspect the problem isn't usage of SSLv3, the only way that would fail is if the client (on DX) claimed to support **ONLY** SSLv3. And since the built-in browser is a web-kit based browser, the chances of that are slim to none. Note: The url in the post is http:// - - (port 80) which requires the browser to follow a redirect to https:// - - (port 443) And the K2/DX/DXG browser has always had trouble with some redirects. = = = = = The following **is not** from a K2/DX/DXG - Not working (limited to SSLv3 **only**): Note: This may well be a IIS server (not Apache). Code:
core2quad ~ $ openssl s_client -showcerts -ssl3 -connect www.m.wikipedia.org:443 CONNECTED(00000003) 3078097048:error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure:s3_pkt.c:1199:SSL alert number 40 3078097048:error:1409E0E5:SSL routines:SSL3_WRITE_BYTES:ssl handshake failure:s3_pkt.c:595: --- no peer certificate available --- No client certificate CA names sent --- SSL handshake has read 7 bytes and written 0 bytes --- New, (NONE), Cipher is (NONE) Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE SSL-Session: Protocol : SSLv3 Cipher : 0000 Session-ID: Session-ID-ctx: Master-Key: Key-Arg : None PSK identity: None PSK identity hint: None Start Time: 1437074016 Timeout : 7200 (sec) Verify return code: 0 (ok) --- Code:
core2quad ~ $ openssl s_client -showcerts -tls1 -connect www.m.wikipedia.org:443 CONNECTED(00000003) depth=1 C = BE, O = GlobalSign nv-sa, CN = GlobalSign Organization Validation CA - SHA256 - G2 verify error:num=20:unable to get local issuer certificate verify return:0 --- Certificate chain 0 s:/C=US/ST=California/L=San Francisco/O=Wikimedia Foundation, Inc./CN=*.wikipedia.org i:/C=BE/O=GlobalSign nv-sa/CN=GlobalSign Organization Validation CA - SHA256 - G2 Last edited by knc1; 07-17-2015 at 07:40 AM. |
![]() |
![]() |
![]() |
#3569 |
Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 37
Karma: 27450
Join Date: Aug 2013
Device: Kindle DX graphite
|
Twitter link was suggested in the original thread by Little.Egret, I tried and it didn't work https://twitter.com/abellio_surrey (he is the one who suggested that the reason was SSL 3.0)
Just a few days ago this blog stopped working https://www.washingtonpost.com/news/volokh-conspiracy Or rather I can still access the blog itself, but not the linked articles, e.g. not https://www.washingtonpost.com/news/...heir-property/ Last edited by Jedidiyah; 07-16-2015 at 07:29 PM. |
![]() |
![]() |
![]() |
#3570 |
Going Viral
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
|
The person who suggested SSL 3.0 is (was) not sure what device they had.
See: https://www.mobileread.com/forums/sho...54&postcount=8 (PS: it was SSLv2 that was taken out of service - nearly a decade ago.) The rest of that thread seems to agree - we just need to install a current trusted certificate store. Tomorrow, time permitting, I will check those other links (and do an ascii dump of the certificates - in particular, the root certificate - which should be on the Kindle). We can probably generate the required root certificate collection - but the K2/DX/DXG will have to be jail broken to install it (same firmware build on all three devices, the DX(G) are just large screen K2 models). Last edited by knc1; 07-16-2015 at 08:35 PM. |
![]() |
![]() |
![]() |
Tags |
fonts, fw3, hack, jailbreak 3.1, niluje's hacks, screensavers, usbnet |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
USB network can't connect | Slusho64 | Kindle Developer's Corner | 22 | 01-23-2013 09:00 PM |
USB Network help? | XxKryoxX | Kindle Developer's Corner | 6 | 12-31-2012 08:47 AM |
Is there a hacks to install Time to read feature in other Kindles ? | Biberkopf | Kindle Developer's Corner | 1 | 11-27-2012 04:08 PM |
Hacks DXG Font hacks ? | nimblem | Amazon Kindle | 2 | 09-21-2010 03:35 PM |
Font Hacks | wildchild06241 | Introduce Yourself | 5 | 06-24-2010 08:08 PM |