Messaging security - Security Discussion

Who thought that Threema and Telegram would save your privacy may have a look on this... I can not really believe that ad-networks would care about your privacy. Btw. MinMinGuard is an X-Posed module.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Tapagetalkt via Mahdi ROM vom Nexus 7 (flo)

Okay... I don't understand this. What does Threema do? I use it because I thought it would be more save than Facebooks Whatsapp..
Sent from my GT-I9195 using XDA Free mobile app

Zwulf said:
Who thought that Threema and Telegram would save your privacy may have a look on this... I can not really believe that ad-networks would care about your privacy. Btw. MinMinGuard is an X-Posed module.
Tapagetalkt via Mahdi ROM vom Nexus 7 (flo)
Click to expand...
Click to collapse
I hope you don't really believe those apps are secure! Just because someone wrote something about them, this doesn't mean they are really secure! Just give a check about their permissions:
Threema:
Identity
read your own contact card
find accounts on the device
add or remove accounts
Contacts/Calendar
read your contacts
modify your contacts
Location
precise location (GPS and network-based)
SMS
receive text messages (SMS)
Photos/Media/Files
modify or delete the contents of your USB storage
test access to protected storage
Device ID & call information
read phone status and identity
Other
receive data from Internet
full network access
view network connections
create accounts and set passwords
read sync settings
toggle sync on and off
prevent device from sleeping
run at startup
control vibration
install shortcuts
read Google service configuration
Google Play license check
Telegram:
Identity
find accounts on the device
add or remove accounts
read your own contact card
Contacts/Calendar
read your contacts
modify your contacts
Location
approximate location (network-based)
precise location (GPS and network-based)
SMS
receive text messages (SMS)
Photos/Media/Files
modify or delete the contents of your USB storage
test access to protected storage
Camera/Microphone
record audio
take pictures and videos
Wi-Fi connection information
view Wi-Fi connections
Device ID & call information
read phone status and identity
Other
receive data from Internet
read Google service configuration
full network access
view network connections
prevent device from sleeping
toggle sync on and off
read sync settings
create accounts and set passwords
control vibration
draw over other apps
run at startup
So just use some common sense and ask yourself why some app (if it's a text-secure app) needs that much permissions? These apps are BS! If you need a secure app-to-app texting solution, I suggest you to check Surespot . Is not that fancy, and the voice part of the app is a bit screwed, but for texting is really ok, and is secure with no ****ty ads or percise GPS location tracking, or identity check or other fishy permissions.
Surespot:
In-app purchases
Identity
find accounts on the device
Photos/Media/Files
modify or delete the contents of your USB storage
test access to protected storage
Camera/Microphone
take pictures and videos
record audio
Other
receive data from Internet
full network access
prevent device from sleeping
control vibration
view network connections
Hope this helped!

Related

[APP] remotephone.mobi

Remote Phone is the best way to interact with your Andorid device from any browser.
Phone status, contact list, text archive, device localization are on-line available in such a way you can back-up and work with these data even if the device is off-line. You can also text, change between ring/vibration/silent modes, ring an alarm or ask for the precise localization (GPS coordinates) of your device from your pc. This app enables you to fully control your mobile even if it is not just near you. Settings are fully customizable, including sync period and information you want to sync.
All transmission of data occurs over an encrypted channel (SSL).
All data stored on server are encrypted (AES-256) using a random secret key protected by the user password. No one is able to view any user's data.
Visit https://remotephone.mobi in order to register your account!
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
I created an account and am fiddling around with it.
Looks good so far. One small remark, when you advertise full control, it would be nice to actually have full control.
Enabling GPS etc..
Will play around with it in the next few days and I'll report back my findings.
Please, don't take my comment the wrong way, I like what you've created so far !
Wobstar said:
I created an account and am fiddling around with it.
Looks good so far. One small remark, when you advertise full control, it would be nice to actually have full control.
Enabling GPS etc..
Will play around with it in the next few days and I'll report back my findings.
Please, don't take my comment the wrong way, I like what you've created so far !
Click to expand...
Click to collapse
I didn't create any app!
For me this app is sensational...
chaikouk said:
Remote Phone is the best way to interact with your Andorid device from any browser.
Phone status, contact list, text archive, device localization are on-line available in such a way you can back-up and work with these data even if the device is off-line. You can also text, change between ring/vibration/silent modes, ring an alarm or ask for the precise localization (GPS coordinates) of your device from your pc. This app enables you to fully control your mobile even if it is not just near you. Settings are fully customizable, including sync period and information you want to sync.
All transmission of data occurs over an encrypted channel (SSL).
All data stored on server are encrypted (AES-256) using a random secret key protected by the user password. No one is able to view any user's data.
Visit https://remotephone.mobi in order to register your account!
Click to expand...
Click to collapse
Great news!
Now all transmission of data occurs over an encrypted channel (SSL)... even more secure!
The server upgrade is over and all services are up again.
Remote Phone is ready to sync more and more users! Yeahhhh..
Has anyone tried this besides me?

Remote Access Phone Manage your android device from the internet

Remote Access Phone​Manage android device from the internet
Remote Access Phone is a application for manage your android phone from the Internet like htcsense.com but with more features and for all the android device.
For manage your android device remotely go on: http://www.remoteaccessphone.com/ and login with your google account
For uninstall you must deactivate the admin rights
Features:
From the website you can:
*See your information system:
In "General information": Phone Number, Device Serial, Sim Serial, Network Operator Name, Network Country Iso, Sim Operator, NameNext Alarm Formatted.
In "Memory Usage": free, Used, Total for internal memory and and external memory (SD Card).
In "Settings information": ADB active, Data Roaming active, Current Failed Password Attempts, Bluetooth Active, WIFI Active, Current Network Active.
In "Battery information": percentage, Temperatureand Voltage.
*Localisation:
Localise your android device from the website with the GPS or the Mobile network, and you can keep a history if you wish
*SMS:
Read and write Text message from the website, keep a thread of discussion, when you send a text message from the website, it will be add to thread of discussion on your android device. You can see on the website the acknowledgment.
*Contacts:
See your Contacts on website for search a phone number or use a list of contacts for select a recipient when your write a sms from the website.
*Push Message:
Send a push message on your android phone from the website or from a php script, it may be useful when you develop a website, you can keep a history on your android device and on the webiste of all the push message sent.
*Settings:
Edit your phone settings from the website.
In "Power Control": Enable or Disable the WIFI, GPS, Sync and the Bluetooth
In "Factory data reset": you can erase all the data on your phone if you are a urgency.
In "Lock Device": you can lock your device with a password from the website if you have lost your phone.
In "Reset application's password": you can lock Remote Access Phone with a password.
*File Manager:
Upload a file on website and push the file on your android device, you can too keep the file on the website for backup, you can too download the file on your computer if you have lost it.
*Call Logs:
See all your call logs on the website with the duration of the call, all the calls are sorted by: Incoming, Outgoing and Missed
The website of Remote Access Phone is: http://www.remoteaccessphone.com
Remote Access Phone is secured by ssl
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
..........

I've been hacked, can you help me to see where was the problem?

Hello
Information:
Just 2 hours ago I have been hacked and I think that was in my phone. I was making a paypal payment to a friend using the paypal app when sudently, seconds after sending the payment I received a mail of paypal with that transaction and another one of 2.500€ that obviously I never did.
The payment was never make because I don't have so many funds, but they tried 5 times with different quantities and all of my cards. Well, after seeing this I changed my password and all of that **** and right now I want to know before I make a clean rom install if I could investigate where the hack came from.
I am using a Galaxy note 3, it is rooted but limited apps have access to root and I also use xprivacy.
The apps with access to root and the xposed modules are this ones
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
and my rooted apps
Hacker paypal data
The data of the money receptor is:
Sent to: Enrique Gallardo Boto (The recipient of this payment is Non-US – Verified)
Email: [email protected]
What I want
I want to investigate if is possible a little bit more of this. I was thinking on restoring a Titanium of all my apps to yesterday, open logcat or any app that can help me to know where the leak came and what app was the malware and try to make another legit transaction to see if happens anything from my phone.
The problem is that I don't really know how should I proceed and I want to solve this for me and more people.
Any idea?
Is the network you used secure out of curiosity? What kind of apps do you have as far as security just curious?
You could try taking a look at some of the applications' play store reviews as well as the modules' forum threads to see if anything had been reported. I'm always very cautious with root permissions, hard to always know what an app will use it for. Personally I stick to my PC for transactions and stay as far away from Google wallet as I can
Sent from my SCH-I605 using xda app-developers app
There's a VirusTotal app you could try, maybe one of your apps is malicious. But if you'd know how to, I'd also just copy all the apps to your PC and then upload them to VirusTotal that way, it'd be a lot easier.
There's also some pc malware out that can infect your phone even. I'd run a decent anti virus on both your phone and your pc as well. (I like Kaspersky, Malwarebytes and ESET personally).
The other thing too is maybe your passwords are just really weak. I'd recommend a password generator like Keepass.
Fyi only
Jus saw this https://blog.lookout.com/blog/2014/03/06/dendroid/ dendroid malware can takeover ur cam and audio and sneak into your googe play.. features:
Ability to intercept and block SMS received by the target device
Download Pictures from the target device
Spy on the user by taking pictures or making audio and video recordings
Download the user’s web browser history and any saved bookmarks
Download any other accounts (email, social media, VPN) stored on the device
Send texts as the device owner
Record any ongoing calls
Open a dialogue box to ask for passwords or send messages to the victim

[APP] Find ME - It's better to have it than you missed it..

Find Me: is an integrated solution for people in crisis and emergency situations, that helps you keep in touch with someone who cares about you
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
☆ Allowing you -when in danger- to send a prewritten SMS message with your location to your Emergency Contact that you have already chosen, just by pressing the Emergency button.
☆ and by allowing your Emergency Contact -when he is worried about you- to find where you are by sending you an SMS message with a Location Code (which is preset by you), and then the app will automatically reply with your location.
☆ Also the app will send an alert SMS message to your Emergency Contact including your location upon changing your phone’s SIM card that may indicate a safety warning like kidnapping or robbery.
☆NEW☆ If you are in a very critical situation and you're not able to reach your phone, or if you had put your device in silent mode and you didn't notice that someone was calling you.. In either case when your Emergency Contact is worried about you and you didn't answer his calls, he can send you an SMS message with a Callback Code and the app will automatically make a call from your device to his number and set your speaker phone on, and that lets your emergency contact either to start talking trying to check up on you, or he just listens to the surrounding sounds trying to figure out the situation.
Additional features:
- The sent message will include a link can be opened by Google Maps or any internet browser to show your location.
- If the device can't detect your current location your last known location with its time and date will be sent instead (the app will periodically check your location every half hour).
- Only the device that should be located, must have the app installed on it, but your Emergency Contact mobile doesn't have to be an Android device at all, and of course doesn't need the app.
Non-emergency uses:
Although the app is used especially in emergency situations, it can also be used in many other situations, for example:
* If you are invited to a party but you get lost, you can use the “Emergency” button to send a message with your location to your host..
* If your phone was lost or stolen, you can find it by sending the location message code..
* And with the location message code, you can check for example if your child has arrived to his piano lesson, without interrupting his lesson to answer your call..
* If a senior person, a child, or someone with disability is not able to answer your calls, you can use the Callback code to check up on him.
Notice:
* Although your device uses to detect your location many different resources but being in certain locations (like being indoors, or underground..), may make this operation difficult if not impossible and take longer time to detect your location. For best results you should always keep Location enabled on your device, and having an internet connection.
Download on Google Play:
https://play.google.com/store/apps/details?id=joe.findme
If you have a question, suggestion, or a problem using the app please reply to this thread and tell me about it...
Try the app and keep it on your phones.. It's better to have it even if you don't use it, than you missed it when you need it..
New version available now on Google Play:
https://play.google.com/store/apps/details?id=joe.findme

omacp "unsupported browser", what browser?

I've got a Unihertz Jelly 2 with T-Mobile service. It's running Android 11. First thing I did when getting it, about two weeks ago, was disable a bunch of Google-ish apps because I'd mostly like Google out of my life. I know from past experience that I can't disable them all because, eg, play store is too useful for me to do without. I'm afraid I may have caused this issue I'm seeing because of my disable frenzy and I'm hoping someone can help me understand what's gone wrong.
Every couple of days I get these messages from number 2903: "We see your phone does have correct settings to access the internet or send MMS. Settings will be sent to your handset."
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
They are accompanied by notifications from Omacp app:
In Omacp I see requests to install things. When I click the button to do the full install I get a report that the APN installed fine but the "browser" failed:
Afterwards it tells me the browser is "unsupported":
What "browser" is it talking about? I thought it might have been Chrome, which was one of the apps I disabled, but re-enabling Chrome did not resolve this.
Still disabled on my phone: Assistant, Calculator, Calendar, Drive, Duo, Files by Google, Google TV, Keep Notes, Photos, Youtube, Youtube Music.
Not disabled (because I thought it would break stuff, I coudn't, or the warning messages too dire): Android Accessibility Suite, Android Auto, Android System Webview, Carrier Services, Game Mode, Gboard, Gmail, Google, Google Play Store, Maps, Messages, Phone, Settings, Sim Toolkit.
When I get the messages from 2903 for omacp, I need to do the install or MMS messaging does not work. This sort of feels like it should be happening automatically in the background.
I have the same issue. Any resolution on this?
What browser
@neccowafer
Delete Omacp: it's a virus!
The virus may perform the following malware-related activities without your permission:
Periodically scan the phone.
Obtain the phone's contacts.
Complete control of the SMS solution.
Complete control over the phone calls phone.
Changing the malicious web server from which virus files are downloaded.
Creating a lock screen on your device and displaying a third-party website.
Running scripts that collect password and username information for various purposes.
Turning off and/or restarting your device.
This is why removing the OMACP virus from your Android is highly advisable.

Categories

Resources