Re: dillo security question

2008-10-22 Thread Matthias Apitz
El día Tuesday, October 21, 2008 a las 10:35:23PM -0400, Yaroslav Halchenko 
escribió:

  Who is the author of this port of dillo to arm4? There is no reference
  and the only available download site is http://misc.andi.de1.cc/dillo/
 that page is pointed to from the original dillo's website
 http://www.dillo.org/download.html
 
 thus it might be worth asking dillo's author(s)?
 
 .dsc file lists
 Maintainer: Devid Filoni [EMAIL PROTECTED]
 so it might be the same person who did ipk?
 
 
  So what? Who did this port and is it safe to install this on the FR?
  I'm asking because I think it would be easy to write some maleware which
  let your FR dial every second some expensive service number or send out
  SMS as SPAM. Don't get me wrong, I'm only speaking about the possibility
  and that we should know *what* we install on our FR. I'm wrong?
 nope
 
 possibility of malware on FR exists, but they will have hard time to do
 anything 'useful' due to the variety of ports and inconsistent
 interfaces :-P
 
 For those needing security assurance I would recommend to stick to
 Debian

In my original posting I have put Jorge Arellano Cid, the primary and
security contact developer of Dillo.org into Cc: (and I do it now
again); Jorge replied to me (thanks) in private mail that he knows who did the
package of the dillo team and that he will contact the developer to let
him 'sign' somehow this binary package; for reasons of netiquette I will
not put his name into this e-mail but Bcc:'ed him in this e-mail; we
must await his reaction; thanks in advance;

matthias
-- 
Matthias Apitz
Manager Technical Support - OCLC GmbH
Gruenwalder Weg 28g - 82041 Oberhaching - Germany
t +49-89-61308 351 - f +49-89-61308 399 - m +49-170-4527211
e [EMAIL PROTECTED] - w http://www.oclc.org/ http://www.UnixArea.de/
b http://gurucubano.blogspot.com/
A computer is like an air conditioner, it stops working when you open Windows
Una computadora es como aire acondicionado, deja de funcionar si abres Windows

___
Openmoko community mailing list
community@lists.openmoko.org
http://lists.openmoko.org/mailman/listinfo/community


Re: dillo security question

2008-10-21 Thread Yaroslav Halchenko
 Who is the author of this port of dillo to arm4? There is no reference
 and the only available download site is http://misc.andi.de1.cc/dillo/
that page is pointed to from the original dillo's website
http://www.dillo.org/download.html

thus it might be worth asking dillo's author(s)?

.dsc file lists
Maintainer: Devid Filoni [EMAIL PROTECTED]
so it might be the same person who did ipk?


 So what? Who did this port and is it safe to install this on the FR?
 I'm asking because I think it would be easy to write some maleware which
 let your FR dial every second some expensive service number or send out
 SMS as SPAM. Don't get me wrong, I'm only speaking about the possibility
 and that we should know *what* we install on our FR. I'm wrong?
nope

possibility of malware on FR exists, but they will have hard time to do
anything 'useful' due to the variety of ports and inconsistent
interfaces :-P

For those needing security assurance I would recommend to stick to
Debian

-- 
  .-.
=--   /v\  =
Keep in touch// \\ (yoh@|www.)onerussian.com
Yaroslav Halchenko  /(   )\   ICQ#: 60653192
   Linux User^^-^^[17]



___
Openmoko community mailing list
community@lists.openmoko.org
http://lists.openmoko.org/mailman/listinfo/community


dillo security question

2008-10-20 Thread Matthias Apitz

Hello,

After the lightweight webbrowser dillo was mentioned in the October
Community Update
http://wiki.openmoko.org/wiki/Community_Updates/October_19th,_2008
I was thinking to give it a try on my Fr, but I'm unsure if I should do so;

Who is the author of this port of dillo to arm4? There is no reference
and the only available download site is http://misc.andi.de1.cc/dillo/
which has no information about who did this port. In addition if you
search in Google for the string 'dillo_2.0-r0_armv4t.ipk' you will not
get any other reference or download point, nor any MD5 sum.

So what? Who did this port and is it safe to install this on the FR?
I'm asking because I think it would be easy to write some maleware which
let your FR dial every second some expensive service number or send out
SMS as SPAM. Don't get me wrong, I'm only speaking about the possibility
and that we should know *what* we install on our FR. I'm wrong?

Thx

matthias
-- 
Matthias Apitz
Manager Technical Support - OCLC GmbH
Gruenwalder Weg 28g - 82041 Oberhaching - Germany
t +49-89-61308 351 - f +49-89-61308 399 - m +49-170-4527211
e [EMAIL PROTECTED] - w http://www.oclc.org/ http://www.UnixArea.de/
b http://gurucubano.blogspot.com/
A computer is like an air conditioner, it stops working when you open Windows
Una computadora es como aire acondicionado, deja de funcionar si abres Windows

___
Openmoko community mailing list
community@lists.openmoko.org
http://lists.openmoko.org/mailman/listinfo/community