[Completed] Are custom ROMs or GAPPS stealing users' data? - XDA Assist

Hi everybody!
Some webpages in my country are forbidden so we could not see their content in normal ways, unless we use some tools that changes our IPs.
I used to have CyanogenMod custom ROM in my phone, not surprisingly, with GAPPS alongside. When I visited a forbidden page accidentally, I saw that the page came up without any problem. first I thought that there is a bug in my country's censorship system, But after going back to Samsung stock ROM, I faced with the forbidden message as I opened that page.
So I am suspicious that there was something happening in my phone.
Now I'm asking you to check your IP with different browsers in a custom ROM (no matter which) to see if your IP belongs to your country?
To check your IP simply visit this webpage:Mod Edit link removed

This is not the purpose of XDA Assist.
Please read the OPENING THREAD and the Second one , too.
Thread closed
Thank you for your attention in this matter.
malybru
Senior Moderator

Related

[Q] custom rom user

hi i use custom roms on my s4 i9505, i told my friend and he said i was stupid because people can attach harmful code to any rom or program.
that can give a crook access to your pc or phone. he played me a couple of videos showing this because he has been hit on his self using third party apps, and antivirus programs do not see this code..
Can anyone elaborate on this and prove this is not true about custom roms.
Many thanks
fezz64 said:
hi i use custom roms on my s4 i9505, i told my friend and he said i was stupid because people can attach harmful code to any rom or program.
that can give a crook access to your pc or phone. he played me a couple of videos showing this because he has been hit on his self using third party apps, and antivirus programs do not see this code..
Can anyone elaborate on this and prove this is not true about custom roms.
Many thanks
Click to expand...
Click to collapse
custom roms on this site are required to be open source. that means the developer must post the source code to his work or it can not be posted here. for this reason it is highly unlikely you will find any nefarious code in any of the roms posted here. as for roms posted on other sites, i cant speak for their policies.
apps are always subject to malware, thats why you should only download them from a trusted source like the play store or this site.
bweN diorD said:
custom roms on this site are required to be open source. that means the developer must post the source code to his work or it can not be posted here. for this reason it is highly unlikely you will find any nefarious code in any of the roms posted here. as for roms posted on other sites, i cant speak for their policies.
apps are always subject to malware, thats why you should only download them from a trusted source like the play store or this site.
Click to expand...
Click to collapse
hi thanks for your help i will continue useing echoe rom as i cannot fault it...
.........THANKS TO ALL..........
stick to one developr
stick to one developer and follow the custom rom threads carefully so that u can understand who is a very good developer

[Completed] Custom ROM for Huawei GX1S

Hi,
I recently purchased a Huawei GX1S and overall found it a good phone except for one thing: the ROM. It uses a Huawei customized ROM which I personally find horrible as it doesn't have any of the regular apps like Play Store or Chrome. It uses Huawei update servers, EMUI, as its system update download server so therefore I can't get any of the Google official updates.
I've Googled up several times to try and find the original Google custom ROM and haven't found anything related to it. The best I could find were 2 tutorial sites that had survey locked download links which I honestly don't trust and wouldn't waste my time on. There seems to be no information at all for this product. Are there any available custom ROMs out there that I can use with this device?
Thanks
Hello,
Welcome to XDA.
I'm not finding anything at XDA for your device.
Try posting your question in the forum linked below.
http://forum.xda-developers.com/android/help
The experts there may be able to help.
Remember to register an XDA account so you can post and reply in the forums. Good luck.

[Completed] Stock ROM for Huawei Y625-u43: I found it!

After a lot of time searching on internet, someone else uploaded the stock rom for this cellphone (which for some reason its NOT in the oficial huawei page). Please notice that the link is not mine, I just found it.
By the way, I tried it on my cellphone and it worked!
The link: 4shared.com/rar/_c8dHlNFce/Y625-U43V100R001C464B105.html
(Just add the www thing to the link: I am new to this community and I think this will be the only thing I will post, at least for a while)
If for some reasons the link gets broken or something, please tell me and I´ll upload it to some page
proundmega said:
After a lot of time searching on internet, someone else uploaded the stock rom for this cellphone (which for some reason its NOT in the oficial huawei page). Please notice that the link is not mine, I just found it.
By the way, I tried it on my cellphone and it worked!
The link: 4shared.com/rar/_c8dHlNFce/Y625-U43V100R001C464B105.html
(Just add the www thing to the link: I am new to this community and I think this will be the only thing I will post, at least for a while)
If for some reasons the link gets broken or something, please tell me and I´ll upload it to some page
Click to expand...
Click to collapse
Hello,
This forum is for newbies finding their way around XDA Developers.
You may post in Miscellaneous android development forum, so that users with the same device and looking for the same could use your help. Good luck!
Thread closed.
-Vatsal

Custom ROMs - Device Security

Hi Guys,
I am new to Android (a noob) - Started with flashing some custom ROMs on my devices and i am bothered by the security of my device, although android is open source, is it possible that a custom ROM is bugged to steal your personal or financial information? I don't have any experience with android development and i don't have time to jump into Android development so even if the ROM is open source i wont be going through the code to check for leaks or potential built-in hacks.
Basically my question is, is it safe to install Unofficial ROMs such as CM unofficial? I understand, the majority of apps store sensitive data on device in encrypted way but still, i don't think it will be hard to just modify the ROM to develop a built-in key-logger OR read username/password from a username/password fields while user is typing using an on-screen keyboard, save it as LOG file and when connected to the internet, send it to the 'unknown' source. I can see so many possibilities, the user wont even have a clue that they are sharing data. it is like Microsoft making windows Open Source and people making their own versions of Windows and users installing them on thier PCs.
Please help me understand - How safe are our devices when running on custom ROMs from developers we don't even know (no disrespect to any dev, all this amazing work is appriciated, I just want to understand the security of android - Please help me understand as after flashing custom ROMs on my devices i am avoiding installation of sensitive apps or even using chrome to type my passwords) - am i paranoid ?
Cheers
It's entirely possible that a malicious custom ROM could steal your data (or worse), and there's really no technical way to mitigate it. You're implicitly trusting the developer of a ROM by flashing it. All you can really do is make sure that whatever ROM you choose is from a well-known, trusted developer.
aliusman999 said:
Hi Guys,
I am new to Android (a noob) - Started with flashing some custom ROMs on my devices and i am bothered by the security of my device, although android is open source, is it possible that a custom ROM is bugged to steal your personal or financial information? I don't have any experience with android development and i don't have time to jump into Android development so even if the ROM is open source i wont be going through the code to check for leaks or potential built-in hacks.
Basically my question is, is it safe to install Unofficial ROMs such as CM unofficial? I understand, the majority of apps store sensitive data on device in encrypted way but still, i don't think it will be hard to just modify the ROM to develop a built-in key-logger OR read username/password from a username/password fields while user is typing using an on-screen keyboard, save it as LOG file and when connected to the internet, send it to the 'unknown' source. I can see so many possibilities, the user wont even have a clue that they are sharing data. it is like Microsoft making windows Open Source and people making their own versions of Windows and users installing them on thier PCs.
Please help me understand - How safe are our devices when running on custom ROMs from developers we don't even know (no disrespect to any dev, all this amazing work is appriciated, I just want to understand the security of android - Please help me understand as after flashing custom ROMs on my devices i am avoiding installation of sensitive apps or even using chrome to type my passwords) - am i paranoid ?
Cheers
Click to expand...
Click to collapse
You are paranoid but that's good!
Yes we are trusting the devs (or Samsung et al with stock) AND hopefully smart coders who regularly check the code (but I suspect checking doesn't happen a lot!). You can use a firewall/packet sniffer to check what servers your phone is connecting to and see (some) of the data being sent to reduce your risk and put your mind at ease. But still it's no guarantee, as I understand it (I'm no expert!).
---
trainsuit said:
If you get a stock android you are also trusting the developer. Just look at these lenovo laptops which had malware served on their stock windows versions. Best is to always start clean when buying any form of product.
Click to expand...
Click to collapse
That's true, but how do you define ”clean”? In theory, you could build AOSP for your device yourself so you're only trusting Google, but that's completely impractical for most people. If you just switch from stock to someone else's custom ROM, you're just changing who you're trusting.
---
Perhaps it's a silly question but I do it: do you think that a XDA Senior Member with one or two thousand of thanks is reliable?
Bach_J said:
Perhaps it's a silly question but I do it: do you think that a XDA Senior Member with one or two thousand of thanks is reliable?
Click to expand...
Click to collapse
Another question for you: if a ROM has malicious code that send personal information to unknown servers, is using a firewall like AFWall+ twhich blocks all system apps sufficient to prevent this malicious ROM to stole data?
Thanks
Bach_J said:
Perhaps it's a silly question but I do it: do you think that a XDA Senior Member with one or two thousand of thanks is reliable?
Click to expand...
Click to collapse
Probably.
Bach_J said:
Another question for you: if a ROM has malicious code that send personal information to unknown servers, is using a firewall like AFWall+ twhich blocks all system apps sufficient to prevent this malicious ROM to stole data?
Thanks
Click to expand...
Click to collapse
No, a custom ROM could make data look like it's coming from any app it wants, or just bypass the firewall completely.
josephcsible said:
No, a custom ROM could make data look like it's coming from any app it wants, or just bypass the firewall completely.
Click to expand...
Click to collapse
Alternatively if the device is on your own network you could wireshark it using a computer and monitor IP addresses that the device attempts to connect to.
LyricalMagical said:
Alternatively if the device is on your own network you could wireshark it using a computer and monitor IP addresses that the device attempts to connect to.
Click to expand...
Click to collapse
This is helpful but not perfect. There's a bunch of ways to stealthily exfiltrate data over a monitored network, and don't forget a malicious ROM might only do its dirty work over cell and not Wi-Fi for this very reason.
josephcsible said:
This is helpful but not perfect. There's a bunch of ways to stealthily exfiltrate data over a monitored network, and don't forget a malicious ROM might only do its dirty work over cell and not Wi-Fi for this very reason.
Click to expand...
Click to collapse
I agree with you it's not a perfect solution; this question is sort of like asking if you can trust someone who has a root account to your computer when you cannot see what they are doing, it's an incredibly disadvantaged situation from the start.
LyricalMagical said:
I agree with you it's not a perfect solution; this question is sort of like asking if you can trust someone who has a root account to your computer when you cannot see what they are doing, it's an incredibly disadvantaged situation from the start.
Click to expand...
Click to collapse
I don't want to flash custom ROMs anymore! :crying:
It can be very dangerous! Or am I paranoid and I can trust xda developers?
Bach_J said:
I don't want to flash custom ROMs anymore! :crying:
It can be very dangerous! Or am I paranoid and I can trust xda developers?
Click to expand...
Click to collapse
Remember, everything I've been saying is reasons not to flash a ROM unless you trust the dev. None of it is saying that devs aren't trustworthy. I don't know of a single instance when a well-respected XDA member's ROM turned out to be malicious.
josephcsible said:
Remember, everything I've been saying is reasons not to flash a ROM unless you trust the dev. None of it is saying that devs aren't trustworthy. I don't know of a single instance when a well-respected XDA member's ROM turned out to be malicious.
Click to expand...
Click to collapse
Thank you for clarifying that but the question comes once more: how to recognize a well-respected XDA member? With the number of thanks? It is obvious that if the smartphone you are interested in is not so famous, there will be few comments on custom ROMs, too. So, how to evaluate the reliability of a xda dev who is developing ROM for not-well-known devices?
Are ROMs in Original development Section trustworthy?
Bach_J said:
Thank you for clarifying that but the question comes once more: how to recognize a well-respected XDA member? With the number of thanks? It is obvious that if the smartphone you are interested in is not so famous, there will be few comments on custom ROMs, too. So, how to evaluate the reliability of a xda dev who is developing ROM for not-well-known devices?
Are ROMs in Original development Section trustworthy?
Click to expand...
Click to collapse
Number of thanks can hardly tell that a dev is reliable or not(in some cases it can), rather it's the quality of their work and their expertise on the related topics that could clarify their position a bit. the recognized contributors, recognized developers, recognized themers you should look at cause
these are given to a member after being checked and passed by moderaters here on XDA. So they are pretty much reliable guys. in cases where there are no recognized developers and hardly any comments. you will have to check and find out yourself
1. ask the dev if he has tested the ROM himself?
2. how did he compiled the ROM? is it a port or just a modified copy of another ROM or a build from source.
3. check the link of the download, if it's to some survey site or ask for a password, stay away from it.
4. if you trust the download link, then download scan with antivirus and unzip the file.
5. generally I look inside app if there are apps which I don't trust and I remove them, then check build.prop, init.d folders. basic things to look for is any references of some other website/ports in between codes. if you're more paranoid you can check bin folder as well and every other you want.
6.don't install the ROM simply Root and debloat.
billysam said:
Number of thanks can hardly tell that a dev is reliable or not(in some cases it can), rather it's the quality of their work and their expertise on the related topics that could clarify their position a bit. the recognized contributors, recognized developers, recognized themers you should look at cause
these are given to a member after being checked and passed by moderaters here on XDA. So they are pretty much reliable guys. in cases where there are no recognized developers and hardly any comments. you will have to check and find out yourself
1. ask the dev if he has tested the ROM himself?
2. how did he compiled the ROM? is it a port or just a modified copy of another ROM or a build from source.
3. check the link of the download, if it's to some survey site or ask for a password, stay away from it.
4. if you trust the download link, then download scan with antivirus and unzip the file.
5. generally I look inside app if there are apps which I don't trust and I remove them, then check build.prop, init.d folders. basic things to look for is any references of some other website/ports in between codes. if you're more paranoid you can check bin folder as well and every other you want.
6.don't install the ROM simply Root and debloat.
Click to expand...
Click to collapse
Thanks for the complete explanation!
billysam said:
Number of thanks can hardly tell that a dev is reliable or not(in some cases it can), rather it's the quality of their work and their expertise on the related topics that could clarify their position a bit. the recognized contributors, recognized developers, recognized themers you should look at cause
these are given to a member after being checked and passed by moderaters here on XDA. So they are pretty much reliable guys. in cases where there are no recognized developers and hardly any comments. you will have to check and find out yourself
1. ask the dev if he has tested the ROM himself?
2. how did he compiled the ROM? is it a port or just a modified copy of another ROM or a build from source.
3. check the link of the download, if it's to some survey site or ask for a password, stay away from it.
4. if you trust the download link, then download scan with antivirus and unzip the file.
5. generally I look inside app if there are apps which I don't trust and I remove them, then check build.prop, init.d folders. basic things to look for is any references of some other website/ports in between codes. if you're more paranoid you can check bin folder as well and every other you want.
6.don't install the ROM simply Root and debloat.
Click to expand...
Click to collapse
I've just unzipped ROM but I can't find what you said. I've only found build.prop and nothing else!
Here a screenshot:
Bach_J said:
I've just unzipped ROM but I can't find what you said. I've only found build.prop and nothing else!
Here a screenshot:
Click to expand...
Click to collapse
That's because lollipop and marshmallow ROM files are further zipped into system.new.dat files which needs another method to extract, https:\\forum.xda-developers.com/android/help/extract-dat-marshmallow-lollipop-easily-t3334117
Just a small correction. When going to aosp you I ly are trusting yourself as you can inspect everything you add and remove what you don't.
Now to add to your paranoia. A custom rom could be made that allows all apps root permission without the users knowing. Add in a Key logger and have e it all headed without you ever knowing. This is common is xiaomi and other china based devices.
Heck there are a few key parts in the playstore with built in Key loggers.
Heck most of the go apps send all their data to China. Things like their Keylogger files, screen recording and device usage. But mind you it is all legal

Links Not Working?(Dev Host)

Guys and Dear Senior Members,
It seems like none of the dev host (d.hst) links are working. At first I thought the problem was with the particular link I was downloading from...but since then I have tried downloading from many other threads(for custom ROM,Patches etc) and none of the links are working. I use IDM(Internet Download Manager) for downloading and every time I get this error message as quoted below
" An existing connection was forcibly closed by the remote host...."
Hope You guys can clear our doubt and tell us when we can start downloading again.
Thanking you,
A Junior Member

Categories

Resources