Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Readers > Amazon Kindle > Kindle Developer's Corner

Notices

Reply
 
Thread Tools Search this Thread
Old 07-16-2016, 12:46 AM   #16
Yourcat
Groupie
Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.
 
Posts: 175
Karma: 54048
Join Date: Mar 2016
Device: PW3 5.6.5-usbnet
I also think that one is quite save even if the hotspot is hacked. We don't have keys to sign firmware images - an evil hacker could have them. There are enough job offers at lab126 so they may have already hired a hacker.
Yourcat is offline   Reply With Quote
Old 07-16-2016, 08:40 AM   #17
geekmaster
Carpe diem, c'est la vie.
geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.
 
geekmaster's Avatar
 
Posts: 6,433
Karma: 10773670
Join Date: Nov 2011
Location: Multiverse 6627A
Device: K1 to PW3
Quote:
Originally Posted by Yourcat View Post
I also think that one is quite save even if the hotspot is hacked. We don't have keys to sign firmware images - an evil hacker could have them. There are enough job offers at lab126 so they may have already hired a hacker.
Again, just like you are more vulnerable to hacked computers on your own network, you are also vulnerable to hackers at the vendor's company. Both ends of the encrypted "pipe" are open. It is only intermediate computers on the TCP/IP route where encryption fully protects you (other than weak PRNG problems and 0-days the NSA knows about) from Man-In-The-Middle (MITM) attacks. The endpoints are not encrypted. These are risks we take with companies and products and networks and services that we choose to trust, hopefully with an informed decision. The price of convenience. Technology is a double-edged sword.

But hacking and spying can go both ways. Kindle hackers (of lesser ethics) can tunnel traffic of all kinds through the kindle proxy by pretending to be normal kindle web browser traffic, exploiting corkscrew and "clicks to google". We do not support nor condone such things at this website. I only mentioned it to demonstrate that trust must go both ways. The service provider is also vulnerable as well.

Last edited by geekmaster; 07-16-2016 at 08:43 AM.
geekmaster is offline   Reply With Quote
Advert
Old 07-16-2016, 02:49 PM   #18
knc1
Going Viral
knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.
 
knc1's Avatar
 
Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
Quote:
Originally Posted by Yourcat View Post
Actually Kindle creates outgoing connections (to Amazon servers) which one could terminate on a local server and send custom replies. No need to penetrate the firewall. As we have seen one could delete developer keys. Locking the device could also be possible.
Outgoing HTTPS (TLS-1.2) connections.
Lots of luck faking that.

Where have you seen that one could delete developer keys?
(Other than by changing your registration status with Amazon)
Link please.

Now what do you mean by "Locking the device"?

- - - -

At the very bottom line -
What do you have on a Kindle worth protecting?
Translation:
So what.
knc1 is offline   Reply With Quote
Old 07-16-2016, 03:50 PM   #19
geekmaster
Carpe diem, c'est la vie.
geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.
 
geekmaster's Avatar
 
Posts: 6,433
Karma: 10773670
Join Date: Nov 2011
Location: Multiverse 6627A
Device: K1 to PW3
Quote:
Originally Posted by knc1 View Post
Outgoing HTTPS (TLS-1.2) connections.
Lots of luck faking that.

Where have you seen that one could delete developer keys?
(Other than by changing your registration status with Amazon)
Link please.

Now what do you mean by "Locking the device"?

- - - -

At the very bottom line -
What do you have on a Kindle worth protecting?
Translation:
So what.
Agreed. What use would it be to steal or delete our public dev key? We could just install it again with another jailbreak, so what would be the point? A lot easier to download a jailbreak here (no account needed) and extract the dev key directly.

The digital sky is not falling.

Last edited by geekmaster; 07-16-2016 at 03:57 PM.
geekmaster is offline   Reply With Quote
Old 07-16-2016, 03:55 PM   #20
knc1
Going Viral
knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.
 
knc1's Avatar
 
Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
We Publish our developer's key-pair!
Been that way forever, and have never heard of it being misused.

Agreed -
The digital sky is not falling on the Kindle users.
knc1 is offline   Reply With Quote
Advert
Old 07-18-2016, 02:52 PM   #21
Yourcat
Groupie
Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.Yourcat knows the way to San Jose.
 
Posts: 175
Karma: 54048
Join Date: Mar 2016
Device: PW3 5.6.5-usbnet
The digital sky is not falling on the Kindle users.
If one asks what could be done one may give a proper answer even if it is very unlikely that it will ever happen.
Kaspersky may release a virus scanner for KUAL
Yourcat is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Free (Kindle) Hot Doug's [Chicago Local Restaurant History, Memoir, & Hot Dog Trivia] ATDrake Deals and Resources (No Self-Promotion or Affiliate Links) 2 07-06-2015 12:07 PM
Kindle Voyage bright spots pufff Amazon Kindle 3 11-11-2014 01:04 PM
Fun with Amazon Kindle TV spots Alexander Turcic Amazon Kindle 3 08-07-2013 04:18 PM


All times are GMT -4. The time now is 11:06 PM.


MobileRead.com is a privately owned, operated and funded community.