Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Readers > Onyx Boox

Notices

Reply
 
Thread Tools Search this Thread
Old 12-13-2020, 08:38 AM   #1
vcot
Junior Member
vcot began at the beginning.
 
Posts: 1
Karma: 10
Join Date: Dec 2020
Device: none
Spyware in firmware

Looks like the latest models and maybe also older models use a Linux, with changed kernel, which is not public.
I read that other products from China send data to specific ips.
How to prevent that, would rooting that device helpful to solve this issue?
vcot is offline   Reply With Quote
Old 12-13-2020, 09:12 AM   #2
ottischwenk
Wizard
ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.
 
ottischwenk's Avatar
 
Posts: 2,880
Karma: 3933245
Join Date: Sep 2012
Location: Salzburg AT
Device: Boox 4/14, Like-/Meebook 1/8, Tolino 1/10, Kobo 0/5, Kindle 0/3
Quote:
Originally Posted by vcot View Post
Looks like the latest models and maybe also older models use a Linux, with changed kernel, which is not public.
I read that other products from China send data to specific ips.
How to prevent that, would rooting that device helpful to solve this issue?
Do you do bank business with this device?
ottischwenk is online now   Reply With Quote
Advert
Old 12-13-2020, 11:21 AM   #3
alovhaug
Junior Member
alovhaug began at the beginning.
 
Posts: 4
Karma: 10
Join Date: Aug 2020
Device: Onyx Boox Nova 2
Quote:
Originally Posted by ottischwenk View Post
Do you do bank business with this device?
I can't speak for the original poster, but it seems to me that bank information is not the only thing I worry about keeping private and secure. Login information for websites, personal data like tax IDs and account #s at places other than banks just to name a few. And some of that information would be highly convenient to store on an eInk reader, because I tend to carry that device with me everywhere.

About the only thing I can suggest is to keep WiFi disabled, which may or may not work for your use case.

--Avonelle
alovhaug is offline   Reply With Quote
Old 12-13-2020, 12:00 PM   #4
diabl0w
Connoisseur
diabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enough
 
Posts: 87
Karma: 527
Join Date: Sep 2019
Device: Max3
I agree, privacy is more than just protecting bank accounts. Passwords, documents, contacts, browsing habits etc is worth at least some concern. Depending on what device your talking about, for onyx, they mostly run some version of android. Your best bet for protecting data is to use an app like "NoRoot Firewall" and use strict firewall rules. How strict of rules depends on your paranoid level

Edit: or like above poster said, just disable wifi connectivity altogether
diabl0w is offline   Reply With Quote
Old 12-13-2020, 01:04 PM   #5
ottischwenk
Wizard
ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.
 
ottischwenk's Avatar
 
Posts: 2,880
Karma: 3933245
Join Date: Sep 2012
Location: Salzburg AT
Device: Boox 4/14, Like-/Meebook 1/8, Tolino 1/10, Kobo 0/5, Kindle 0/3
Then I suggest not using any device, because there is hardly one that was not produced in China.
Even a battery-free smartphone does not make calls to China.
ottischwenk is online now   Reply With Quote
Advert
Old 12-13-2020, 03:41 PM   #6
diabl0w
Connoisseur
diabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enough
 
Posts: 87
Karma: 527
Join Date: Sep 2019
Device: Max3
Quote:
Originally Posted by ottischwenk View Post
Then I suggest not using any device, because there is hardly one that was not produced in China.
Even a battery-free smartphone does not make calls to China.
Samsung is based out of South Korea so thats a pretty big list right there alone
diabl0w is offline   Reply With Quote
Old 12-13-2020, 03:57 PM   #7
mr_sm1th
Junior Member
mr_sm1th began at the beginning.
 
Posts: 7
Karma: 10
Join Date: Dec 2020
Device: Onyx Max Lumi
I'd say it is very likely Onyx software contains spyware and backdoors.

Quote:
Originally Posted by vcot View Post
How to prevent that, would rooting that device helpful to solve this issue?
Simple: do not connect to the internet when using Onyx devices.

Rooting the device will not help unless you completely replace all software including bootloaders, which is currently not possible as far as I am aware.
mr_sm1th is offline   Reply With Quote
Old 12-13-2020, 04:03 PM   #8
Question Mark
Wizard
Question Mark ought to be getting tired of karma fortunes by now.Question Mark ought to be getting tired of karma fortunes by now.Question Mark ought to be getting tired of karma fortunes by now.Question Mark ought to be getting tired of karma fortunes by now.Question Mark ought to be getting tired of karma fortunes by now.Question Mark ought to be getting tired of karma fortunes by now.Question Mark ought to be getting tired of karma fortunes by now.Question Mark ought to be getting tired of karma fortunes by now.Question Mark ought to be getting tired of karma fortunes by now.Question Mark ought to be getting tired of karma fortunes by now.Question Mark ought to be getting tired of karma fortunes by now.
 
Question Mark's Avatar
 
Posts: 1,414
Karma: 6513838
Join Date: Mar 2016
Device: More than I need, but not as many as I would like.
Quote:
Originally Posted by diabl0w View Post
Samsung is based out of South Korea so thats a pretty big list right there alone
But that's not where they make the majority of their phones. Until last year, they did have a factory in China. However, it seems that the majority of their phones for the global market are made in Vietnam.

https://www.sammobile.com/where-are-samsung-phones-made
Question Mark is offline   Reply With Quote
Old 12-13-2020, 04:04 PM   #9
ottischwenk
Wizard
ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.ottischwenk ought to be getting tired of karma fortunes by now.
 
ottischwenk's Avatar
 
Posts: 2,880
Karma: 3933245
Join Date: Sep 2012
Location: Salzburg AT
Device: Boox 4/14, Like-/Meebook 1/8, Tolino 1/10, Kobo 0/5, Kindle 0/3
I don't care whether they call China or the NSA - I don't particularly like either.
But NSA is closer and the danger is probably greater

Last edited by ottischwenk; 12-13-2020 at 04:57 PM.
ottischwenk is online now   Reply With Quote
Old 12-13-2020, 04:54 PM   #10
Ken Maltby
Wizard
Ken Maltby ought to be getting tired of karma fortunes by now.Ken Maltby ought to be getting tired of karma fortunes by now.Ken Maltby ought to be getting tired of karma fortunes by now.Ken Maltby ought to be getting tired of karma fortunes by now.Ken Maltby ought to be getting tired of karma fortunes by now.Ken Maltby ought to be getting tired of karma fortunes by now.Ken Maltby ought to be getting tired of karma fortunes by now.Ken Maltby ought to be getting tired of karma fortunes by now.Ken Maltby ought to be getting tired of karma fortunes by now.Ken Maltby ought to be getting tired of karma fortunes by now.Ken Maltby ought to be getting tired of karma fortunes by now.
 
Ken Maltby's Avatar
 
Posts: 4,465
Karma: 6900052
Join Date: Dec 2009
Location: The Heart of Texas
Device: Boox Note2, AuraHD, PDA,
There are a number of functions on my new Onyx Boox Note 2 (10.3") that won't work without phoning home. This includes the fingerprint detection, screensaver app. (still can add your own locally), and others.

Luck;
Ken
Ken Maltby is offline   Reply With Quote
Old 12-13-2020, 06:20 PM   #11
Galunid
Zealot
Galunid herds cats with both ease and graceGalunid herds cats with both ease and graceGalunid herds cats with both ease and graceGalunid herds cats with both ease and graceGalunid herds cats with both ease and graceGalunid herds cats with both ease and graceGalunid herds cats with both ease and graceGalunid herds cats with both ease and graceGalunid herds cats with both ease and graceGalunid herds cats with both ease and graceGalunid herds cats with both ease and grace
 
Posts: 122
Karma: 43580
Join Date: Apr 2016
Device: KPW3, Kobo Clara HD, Onyx Boox Nova 2
I run it and monitored the traffic using Wireshark for a while, and there wasn't much really, just some analytics, but just in case I run it over wireguard connected to PiHole, with onyx domains blacklisted. Only when I update device do I whitelist them and block again after I'm done. Additionally network traffic is allowed only over VPN (wireguard) connection. Funny enough, google play services is much worse then Onyx.
Galunid is offline   Reply With Quote
Old 12-14-2020, 06:31 AM   #12
mitra1
Zealot
mitra1 ought to be getting tired of karma fortunes by now.mitra1 ought to be getting tired of karma fortunes by now.mitra1 ought to be getting tired of karma fortunes by now.mitra1 ought to be getting tired of karma fortunes by now.mitra1 ought to be getting tired of karma fortunes by now.mitra1 ought to be getting tired of karma fortunes by now.mitra1 ought to be getting tired of karma fortunes by now.mitra1 ought to be getting tired of karma fortunes by now.mitra1 ought to be getting tired of karma fortunes by now.mitra1 ought to be getting tired of karma fortunes by now.mitra1 ought to be getting tired of karma fortunes by now.
 
Posts: 103
Karma: 2086978
Join Date: Nov 2019
Location: Roma, Italia
Device: kindle oasis 2,ONYX boox max lumi
Boh, I think until own country or european union has an own Operating System, it's impossible block the stream of data to China or Usa. The hardware and Os aren't european....
mitra1 is offline   Reply With Quote
Old 12-14-2020, 08:50 AM   #13
Markismus
Guru
Markismus causes much rejoicingMarkismus causes much rejoicingMarkismus causes much rejoicingMarkismus causes much rejoicingMarkismus causes much rejoicingMarkismus causes much rejoicingMarkismus causes much rejoicingMarkismus causes much rejoicingMarkismus causes much rejoicingMarkismus causes much rejoicingMarkismus causes much rejoicing
 
Markismus's Avatar
 
Posts: 898
Karma: 149877
Join Date: Jul 2013
Location: Netherlands
Device: Cracked HiSenseA5ProCC, Cracked OnyxNotePro, Note5, Kobo Glo, Aura
Hmmm. I still have to look into this further. For now I NetGuard will have to block unwanted information exchange.
It's not only my Onyx Note Pro that might call home, but also my Hisense A5 Pro cc eInk mobile. Interestingly, this phone manufactured by one of China's state-sponsored/-owned firms also includes an app PayGuard that keeps telling me if apps have a permission that might be damaging my privacy: Like apps that send my location information even when they are not being used.
For now, it seems that the Onyx Boox ereaders and the Hisense eInk mobiles are safer than Samsung's Google services based devices. You can disable Google on Onyx and can't even install them on Hisense.
However, I still have to check with the devices running over a proxy, whether I am blocking all that I want to.
Markismus is offline   Reply With Quote
Old 12-14-2020, 06:28 PM   #14
pazos
cosiñeiro
pazos ought to be getting tired of karma fortunes by now.pazos ought to be getting tired of karma fortunes by now.pazos ought to be getting tired of karma fortunes by now.pazos ought to be getting tired of karma fortunes by now.pazos ought to be getting tired of karma fortunes by now.pazos ought to be getting tired of karma fortunes by now.pazos ought to be getting tired of karma fortunes by now.pazos ought to be getting tired of karma fortunes by now.pazos ought to be getting tired of karma fortunes by now.pazos ought to be getting tired of karma fortunes by now.pazos ought to be getting tired of karma fortunes by now.
 
Posts: 1,289
Karma: 2200073
Join Date: Apr 2014
Device: BQ Cervantes 4
Note that telemetry is not spyware. We could argue if it is somehow malware if there's no way to disable it, but not spyware if used to:

- report crashes
- collect and send anonymous reports, like usage patterns within an app

In that respect we (outside China) use google services to do that.
Chinese people use other service providers. Baidu push service is common to perform bug reports in mainland China.

The important stuff is what the program tracks, not which service is used to deliver what's tracked. One can use Firebase to report a bug or to report all installed applications in a device. In the same vein it can use baidu push service. In the case of google nobody will say "it's phoning china", but if used to steal user data it is the same spyware with or without pushing that data to chinese servers.
pazos is offline   Reply With Quote
Old 12-14-2020, 08:20 PM   #15
diabl0w
Connoisseur
diabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enoughdiabl0w will become famous soon enough
 
Posts: 87
Karma: 527
Join Date: Sep 2019
Device: Max3
Quote:
Originally Posted by Question Mark View Post
But that's not where they make the majority of their phones. Until last year, they did have a factory in China. However, it seems that the majority of their phones for the global market are made in Vietnam.

https://www.sammobile.com/where-are-samsung-phones-made
okay, well as far as i know vietnam is not china
diabl0w is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Firmware Update Instructions and the latest Firmware Versions mitchwah Ectaco jetBook 113 10-24-2023 09:02 PM
Trojan spyware in calibre mac OS build zaster Calibre 9 06-28-2019 03:38 AM
Firmware glitch - typing text slow on some firmware+device combinations mdp Onyx Boox 11 11-11-2017 12:48 AM
candy.js spyware embedded in ebooks fjtorres News 69 08-13-2015 11:52 PM
Kindle 3 scans 2 worms and 1 spyware after using Calibre? dancingbacon Devices 4 06-13-2011 08:05 AM


All times are GMT -4. The time now is 01:14 AM.


MobileRead.com is a privately owned, operated and funded community.