Security question.

Mercurybird

Member
Feb 21, 2013
49
2
0
Texarkana
How would you know if someone cooked a back door into their ROM. A back door that would allow them to monitor a phone's contents remotely. A phone that's running their ROM of course.
 

AndrewSh

Senior Member
Jan 17, 2006
2,081
841
193
Minsk
forum.asusmobile.ru
How would you know if someone cooked a back door into their ROM. A back door that would allow them to monitor a phone's contents remotely. A phone that's running their ROM of course.
Normally this can happen only with vendor's signed rom. Only vendors do this sometimes. Examples: Conflipper, 911sniper and recently some other guys. Vendor was naturally HTC.
They all uploaded a lot of official roms to the private host, HTC investigated the case, found the possible leak source and framed them leaking the rom with backdoor. Thus vendor got personal data and later ganged up on them threatening prosecution.
So if you want to be 100% sure that you have back-door-free rom - cook custom :) Because chiefs don't give a $hit about your personal data, vendor - does!
P.S. And of course:
Remember, just because you're paranoid that doesn't mean that everyone's not out to get you! :)
 
Last edited:

eefdriehuis

Senior Member
Sep 8, 2009
69
4
0
Vinkeveen
than use only the shipt roms from factory , i have used many custum roms and never a problem now i use dynamics 2.0 and he is perfect.
the only thing wath is sure in live is your bird and dead
 

ultrashot

Inactive Recognized Developer
May 26, 2009
1,478
2,046
0
St.Petersburg
How would you know if someone cooked a back door into their ROM. A back door that would allow them to monitor a phone's contents remotely. A phone that's running their ROM of course.
Oh. Don't tell this idea to anyone! :(
I have just bought a new sports car based on money stolen from your phones. New flat to come. Please, wait a little more! Don't spread this information.
 

ultrashot

Inactive Recognized Developer
May 26, 2009
1,478
2,046
0
St.Petersburg
How would you know if someone cooked a back door into their ROM. A back door that would allow them to monitor a phone's contents remotely. A phone that's running their ROM of course.
Now without irony.
Of course, you can never be sure. But:
1) XDA-developers is a community of enthusiasts. If we were to steal anything, we could do it long ago. But, in that case, any other developer can reveal the truth about ROM internals and totally ruin reputation of that developer.
While reputation is just an "integer" value stored somewhere in XDA databases and people's minds, maintaining good "karma" in internet is still much more useful IRL (I guess many devs here can confirm it).
It is a pure hobby for almost everyone. Most of us have work, studies, lots of other things to do.
2) Windows Phone isn't really interesting for majority of "evil" hackers. It is a niche platform currently. It is nearly impossible to earn donations or get money any other way on this platform via development. Thus, I am quite sure all developers still keeping this platform alive are real enthusiasts without any criminal thoughts in minds.
3) Low interest leads to small amount of developers, lack of manuals, etc. Even "evil hackers" have to learn _how_ to do harm on specific platform. WP7 unofficial development has a big entry barrier, effectively filtering even power users.

You can ask what are the reasons most of us still work on this platform? Each software engineer loves when his code _works_, and WP7 limitations is better in this case. Because relatively small amount of native code works "out of the box" - I mean, without hours in debugger, decompiler, eyes red due to display backlight, nights spent in code :)
 
Last edited:

Mercurybird

Member
Feb 21, 2013
49
2
0
Texarkana
Now without irony.
Of course, you can never be sure. But:
1) XDA-developers is a community of enthusiasts. If we were to steal anything, we could do it long ago. But, in that case, any other developer can reveal the truth about ROM internals and totally ruin reputation of that developer.
While reputation is just an "integer" value stored somewhere in XDA databases and people's minds, maintaining good "karma" in internet is still much more useful IRL (I guess many devs here can confirm it).
It is a pure hobby for almost everyone. Most of us have work, studies, lots of other things to do.
2) Windows Phone isn't really interesting for majority of "evil" hackers. It is a niche platform currently. It is nearly impossible to earn donations or get money any other way on this platform via development. Thus, I am quite sure all developers still keeping this platform alive are real enthusiasts without any criminal thoughts in minds.
3) Low interest leads to small amount of developers, lack of manuals, etc. Even "evil hackers" have to learn _how_ to do harm on specific platform. WP7 unofficial development has a big entry barrier, effectively filtering even power users.

You can ask what are the reasons most of us still work on this platform? Each software engineer loves when his code _works_, and WP7 limitations is better in this case. Because relatively small amount of native code works "out of the box" - I mean, without hours in debugger, decompiler, eyes red due to display backlight, nights spent in code :)
Great comments all around. I'm not a paranoid person. But I couldn't help wondering. I have faith in the community all around, like you said. Accountability doesn't lead to deviousness, it leads to integrity. I've heard that the Android is the hacker phone of choice. Or maybe I was misled in my naivete'. One of the things that I noted in my toying with the xda apps, the root tools tell you to be careful about allowing all of your apps. It's big fun watching what you guys crank out. keep up the good work, and if there is threat out there- crank out some apps for it.:highfive:
 
Our Apps
Get our official app!
The best way to access XDA on your phone
Nav Gestures
Add swipe gestures to any Android
One Handed Mode
Eases uses one hand with your phone