IRC log of #maemo for Monday, 2015-12-21

mvahi there!06:32
mvacan you advice me with actual ("alive") maemo repos links? "extras" ones seems to be a bit zombies :-/06:33
mvaAlthough, I somehow got an "update" with bootmenu (I thought it wan't installed before, so dunno why do it installednow) and <cssu repo smth> (new update arrived, but did nothing), but, say, syncevolution-client still broken (can't find syncevolution itself to install). So I decied I missing some repos. Isn't it?06:39
*** fishbulb has joined #maemo08:51
fishbulbis there any way some f-head who KNOWS I run an n900 could have logged into my phone when it's connected via usb, and made it (for example) email them the text messages?08:52
fishbulbon a previous linux install that I now know was totally compromised08:52
fishbulbbecause unlike an android phone, it's a small linux computer, which is easier to "hack" than any android08:53
mvabencoh: it is working (fapman kinda syncing them). But, say, syncevolution-client is broken, some packages too. And... I didn't meant unavailability under "death". Just lack of updates (including fixes) ;)09:25
*** geaaru has joined #maemo10:40
Siceloso it seems my IT dept. can't help me with OWA,10:43
Sicelo"outlook web access is available through the link without a Pulse Secure connection. The user must have a cert that matches their user account, and the username must be entered as domain\username" .. excerpt from the documents for OWA. so i asked my local IT dept. to get me this cert and they say i need to use Pulse :(10:50
Sicelohave spent over an hour explaining that i'm not looking to use Pulse. gawd. someimes techs can be difficult people if they don't get what you want or why you want it.10:51
Sicelo s/get/understand/10:56
*** eijk_ has joined #maemo10:58
mva(that's why you shouldn't ask XY-syndrome questions to techs)11:08
Siceloand where is xy syndrome in what i'm asking them?11:14
*** xorly has joined #maemo11:21
KotCzarnyfishbulb: any device with physical access is usually easily hackable11:41
*** eMHa__ has quit IRC20:29
fishbulbis it possible for someone to have "rooted" my n90020:32
fishbulband send the texts to them20:32
fishbulbit's usually on me, but I've used it so much without reflashing, and connected to so many free or totally dodgy  hotspots, that it might as well have had unprotected sex with 350 prostitutes20:34
KotCzarnyif you are feeling unsafe just reflash20:34
fishbulbI rember last time, there was't a "just" involved20:35
infobotextra, extra, read all about it, maemo-flashing is, or - on linux PC - download&extract, cd into it, do sudo ./flash-it-all.sh20:35
KotCzarnydownload the script, unpack, run, done20:35
KotCzarnycant get any easier20:35
fishbulbyou're right, does software still exist for backing up important stuff?20:36
infobotit has been said that backupmenu is
*** frals has joined #maemo20:42
*** frals has joined #maemo20:42
*** flo_lap has joined #maemo20:53
*** eMHa__ has joined #maemo20:56
sixwheeledbeastbackups of a compromised system isn't a good idea. I doubt anyone would bother to attack a device with so little market share21:03
KotCzarnyswb: anyone with basic linux knowledge and being his 'friend'21:03
Sicelofishbulb: you may have actually sent the sms'es yourself by mistake? it's happened to me couple of times. just last week a friend said i sent him an empty email and he wanted to be sure my systems were not compromised. turns out in my sleep (with unlocked N900 close by) i must have pressed the thing enough to send.21:12
Sicelo(no wonder they say monekys could produce a novel if left alone with a typewriter) :D21:12
KotCzarnyif alcohol/drugs are involved its even more probable21:12
Sicelowell i've never indulged in any of those21:13
fishbulbKotCzarny: you are exactly right21:15
fishbulbI have known some pieces of SHIT21:15
fishbulbI've kept this phone for so long because of "linux"21:16
fishbulbbut in reality it's probably frar easier to hack than any android device21:17
KotCzarnynot true21:17
KotCzarnyandroid is much more popular == MUCH mure exploits21:17
fishbulbyes I do realise that it's one of the two phones on the planet, basically21:17
KotCzarnyand if your droid isnt supported by the maker anymore (usually most stop being supported in 6-12 months after release)21:18
KotCzarnythen have luck patching holes21:18
fishbulbI know, I don't need a 400 dollar phone, and won't buy one until all my n900's are dead21:18
KotCzarnyand as such n900 should be considered MORE secure21:18
fishbulband I don't like android21:18
fishbulbbut it's literally a tiny linux computer that has a phone attached21:19
Sicelotrying to imagine the motive .. someone sending himself texts from your device .. hehe21:19
fishbulbanyone who is "hacking" into my gmail would find this easier than a decent "hardened" android phone, I have a tablet I got to learn about android, it's.. actually good for some things21:20
fishbulbit's related to how someone gets past 2 step auth on my gmail21:21
fishbulbI had some garbage in my apartment, they went through my stuff, now I have problems.21:21
*** krnlyng has joined #maemo21:21
Siceloby the way .. do you know the contents of the SMSes? do they remain in Conversations application? do you perhaps have smscon installed?21:21
*** sq-one has joined #maemo21:21
fishbulbis smscon the security thing for missing phones? I had that installed once21:22
KotCzarnyjust flash it and put lock code on it21:22
fishbulbI want to find out of I'm being paranoid still21:22
sixwheeledbeastIt's probably SMSCON causing it.21:23
Siceloyes. smscon is for that. i have it, and after configuring it nicely, am very happy with the results21:23
fishbulbI can't think of another way of someone getting past 2 step auth on gmail21:23
sixwheeledbeastset it up wrong and you will have random texts and emails.21:23
fishbulbnobody touches my phone anyway21:24
* Sicelo is lost between Gmail step 2 & N90021:24
fishbulboh. someone was getting past the 2 step21:24
Siceloand how does that relate to N900?21:24
fishbulba piece of garbage who I rented a room to21:24
fishbulbbecause this is my only phone ,and the texts for 2 step go to it21:24
Siceloso we're troubleshooting N900 when we should be troubleshooting Gmail21:25
fishbulbwell maybe21:26
fishbulbbut it's still useful to me :)21:26
Sicelowhen the step 2 texts come, they come from the usual/correct phone number?21:26
Siceloand in gmail, you should be able to see previous successful logins21:27
fishbulbI know, the ip addresses have all been from this place21:27
Siceloshared connection?21:28
*** florian_kc has joined #maemo21:28
fishbulbit shouldn't be21:28
fishbulbI'm not voluntarily sharing it21:28
fishbulbzero other people shoud have access21:29
Sicelothe you have something in there which is likely already pre-approved for authentication, or your gf/wife is the one logging into your gmail :D21:30
KotCzarnydoes smscon have some kind of log?21:32
Siceloit does. but the problem here is not that N900 sends/receives messages. the real "problem" is someone/thing is logging into his Gmail successfully, so that N900 receives successful login acknowledgement message21:33
Sicelointerogate your gf! :D21:33
SiceloN900 is innocent21:33
KotCzarnyor just change all the locks and passwords21:33
KotCzarnyand review security settings on your gmail21:33
fishbulbI have done all that, nuked my partitions, installed new distros, blah blah21:34
fishbulbI just wanted to know how probable the phone was for being compromised21:34
fishbulband it's "at least as much as any other phone, if not more"21:34
KotCzarnythe same as your pc/android21:34
fishbulbyeah. but these days it seems like android is harder21:35
KotCzarnyhaving physical access == no problem with compromising21:35
KotCzarnyever heard of stagefright?21:35
KotCzarnyanything from 2.x to 4.x21:35
fishbulbyeah if you have physical access you can do literally anything, and this is the last thing left that hasn't been nuked from orbit (partitions zeroed, all that shit)21:35
KotCzarnyand if your android phone is not on the 'supported with patches' list, bad luck, no way to fix the exploit21:36
KotCzarnyfishbulb: compromising droid with something as simple as opening video attachment or playing a video21:36
fishbulbthere's all this shit about "oh I'm a hacker, but it's only because I'm so smart, and I'm responsible, it's a challenge and I'm not doing any harm" etc etc21:37
*** Maxdamantus has quit IRC21:37
fishbulband a lot of people totally accept that21:37
Sicelofishbulb: you saying even after changing gmail pass, the smses continue?21:38
fishbulbbut if I was like "I have a rock, I've been practicing breaking windows, and for scientific purposes I already broke in and rubbed my balls all over your clothes and toothbrush last week"21:38
KotCzarnyno, he doesnt know for sure21:38
KotCzarnythats why i asked for log21:38
fishbulbabout 100% of people would have a problem with that21:39
KotCzarnyfishbulb: i have my n900 since 2009, never reflashed after initial setup, no problem21:39
KotCzarnyit's the human link that is usually the exploitable hole21:40
SiceloKotCzarny: i meant password for gmail :) smscon has no business there21:40
KotCzarnysimilar with my laptop's os (slackware 4.0 and just update since then)21:40
fishbulbKotCzarny: you're without a doubt waaaay better with linux than I am21:41
KotCzarnyi just dont go to dangerous places21:42
KotCzarnyand dont do suspicious software21:42
fishbulbbasically after dos 6.11 (I knew that shit back to front) I found myself without much computer access until about 6 years ago, and I'm 2 years into linux21:42
KotCzarnyif you want to know linux run it without graphical ui21:43
fishbulbwell. if you know dodgy people, dodgy shit is going to happen. like I've lived in 20+ sharehouses, had most of my stuff stolen, but this invasion of my privacy is persisting21:43
fishbulbthere's the option of trying to harden the security, and hope the person doing it doesn't know all the exploits, but from what I've seen, they haven't left many traces21:44
Siceloyou don't write gmail password on sticky note somewhere, of course?21:44
KotCzarnyencrypted os for laptop21:44
fishbulbthe other option, I go to his house, bash his teeth in with a pipe21:44
KotCzarnyand not leaving phone unattended21:44
Sicelolol fishbulb. you have no proof it's someone else. all evidence is pointing to yourself :p21:45
fishbulbor I just go there, and choke him out then kick his ribs in.21:45
KotCzarnybefore you start bashing you should know what and where21:45
KotCzarnyotherwise it could only get worse21:45
Siceloand be careful, he might just shoot, while you're busy raising pipe :D21:45
fishbulbthis is australia, beatings are almost a currrency21:46
KotCzarnysounded like a ghetto in us21:47
fishbulbit's just like that21:47
fishbulbmost large cities are pretty similar21:47
KotCzarnycheck gmail first then21:48
KotCzarnyfor logs, accesses21:48
KotCzarnygo there, deauth all devices21:48
fishbulbit's always come from this ip21:48
fishbulbinside the router21:48
fishbulbthe only way to get into my gmail and whatever, is with the codes from my phone21:49
Sicelochange WiFi password?21:49
Sicelocodes from your phone? meaning?21:50
fishbulb2 step auth21:50
KotCzarnyoh, and change the router21:50
fishbulbI can't afford to but I was going to try decent firmware21:50
fishbulbsurely that's good enough?21:50
KotCzarnyif its a dlink etc and still on the firmware that it came with..21:51
KotCzarnythen i guess anything would be better21:51
KotCzarnyyou might also disable wifi altogether21:51
KotCzarnyand go wired21:51
fishbulbit's an asus whatever21:52
Sicelothis 2 step thing, lol.21:52
fishbulbno I'm not giving up anything, if I can't stop the wind I won't try, if they're actually not as good as I think they are, I could probably harden things enough21:53
KotCzarnybut to not let them sniff out your passwords you should start from the bottom up21:54
Siceloi never enabled it .. so i don't know what happens exactly -- so you attempt to login via password (step 1), then google sends an sms with a code to your number (step 2), you enter the code and login. after this google sends you a confirmation sms?21:54
fishbulbI don't know if it's the passwords they're even sniffing out, because they got straight through 2 step auth with no problem21:54
Sicelois this the correct sequence?21:54
fishbulbno, I get a code, then I log in21:54
fishbulbthere's never a confirmation one21:55
KotCzarnyhmm, is your cellphone on some shared plan?21:55
fishbulbshared with who?21:55
fishbulblike an ex? no way21:55
* Sicelo goes to check this google thing (curiosity kicking in)21:56
fishbulbI know who is doing this, the guy is trash, it's not unknown. nobody would bother doing this to look at how much money I don't have or get a kick out of reading my stuff if they were like, in latvia, becuse they can't transfer money anyway, and wouldn't give a shit what I do in gmail or facebook21:57
Siceloah, if you know him then there's nothing to troubleshoot :)22:00
KotCzarnyif there is something, clear it22:02
KotCzarnyand all those other settings22:02
KotCzarnyalso, all forwardings etc in gmail22:04
Sicelowould generate a login code though22:05
Siceloanyway, KotCzarny you're on CSSU or stock?22:06
fishbulbwell, right now I'm locked out anyway22:06
KotCzarnymy main phone is still on stock22:06
Sicelo*wouldn't generate...22:06
KotCzarnydev and testing on cssu-thumb22:06
KotCzarnyout of your account?22:06
KotCzarnyalso, check your 'recovery email' setting22:07
Sicelogreat. could i ask you to set camera on 1.3Mpix capture mode, then see if captured picture is exactly what you see in the viewfinder22:07
fishbulbI'm locked out of my account anyway22:07
SiceloKotCzarny: ^^22:08
fishbulbI have a tablet that runs cyanogenmod, and that's authorised22:08
KotCzarnysicelo: i think it's what viewfinder shows22:08
KotCzarny+/- my shaky hands22:08
Siceloplease try anyway22:08
fishbulband I don't think any other device is, I don't use my n900 for much, facebook doesn't really work, does gchat?22:08
Sicelofishbulb: suspect that tablet22:09
KotCzarnysicelo: just tried and said22:09
fishbulbI didn't have the tablet at the time22:09
fishbulbI barely ever use it22:09
KotCzarny1.3M low resolution setting22:09
SiceloKotCzarny: ok. so camera2-ui has a bug .. i get a cropped/zoomed result22:09
fishbulbI have 3 n900's, what's the coolest thing you can think of doing with more than 1? there were competitions ages back that had some pretty cool entries22:10
KotCzarnysicelo, viewfinder is cropped if one selects nonidentical-to-screen aspect ratio22:10
fishbulband now, all that source code has disappeared22:10
KotCzarnyfishbulb: just anything you can do with linux22:11
KotCzarnyi wrote me an audio player22:11
KotCzarnyif you know/learn, its perfect for testing code22:11
SiceloKotCzarny: check on your dev/testing devices ;)22:11
fishbulbyeah but I'm not much of a coder, and someone spent months if not years doing some aerial photography thing for kites22:11
KotCzarnysicelo: im away from home, ask again tomorrow22:11
fishbulbnow that I'm scratch building a drone, the n900 seems like the ultimate companion22:12
fishbulbto learn the sort of coding I can steal immediately from github or whatever and modify, would take years, and I'd never get the stuff done22:13
fishbulbstealing then modifying code is one way to gradually learn, learning the foundations is of course the best way22:13
stryngsfishbulb: check pm22:14
KotCzarnyfishbulb: you can only steal the code if you violate copyright, with gpl you are just forking ;)22:15
Sicelostryngs :)22:17
sixwheeledbeastgrr, another kernel panic third in two weeks22:21
fishbulbyou know what I mean, take code I didn't write then use it22:24
sixwheeledbeastnah buntu22:24
fishbulbnot many projects would get done without doing that though22:24
KotCzarnyits the open source, it encourages sharing, using, changing (as long as you distribute modified source with your project you arent stealing anything)22:25
*** pozitron has quit IRC23:14
Sicelofennec performing quite well for me since i stopped the opening of numerous tabs23:36
Sicelocan actually open,, etc.23:37
bencohare you seriously using those on your phone?23:41
bencohhow long does it take to load / print proper routing instructions (for instance) ?23:42
Sicelohaha. i use Ovi Maps. i was just testing. it's slow, but definitely not as bad as before. if you have urgent need to access a 'modern' site and you only have N900 with you .. it may come in really handy23:45
OksanaaIsn't it weird when filepicker opens at /home/user directory, and shows its contents, not only MyDocs?23:58

