Live data from Hacker News

Aquaris E4.5 Ubuntu Edition

bq.com

211–220 of 280 posts

Re: Aquaris E4.5 Ubuntu Edition

#211
post #201

Being burned by two FirefoxOS phones (mostly burned by not being to upgrade to anything latest and stuck to some version). So I'll be careful this time... But I so much wanted to try it out...

>Being burned by two FirefoxOS phones (mostly burned by not being to upgrade to anything latest and stuck to some version).

Which ones? I had the same experience with the ZTE Open C but found great community updates for this and other phones. Open C updates are this way: http://builds.firefoxos.mozfr.org/doc/en/devices/zte-open-c

Re: Aquaris E4.5 Ubuntu Edition

#212

Earlier quoted context omitted.

WP is dead because of it's restrictions (eg. on WP you can't even install Webkit/Blink based browser)

Yeah, because that's what millions of users out there are asking for.

Ofcourse they aren't asking for it, they just didn't buy the phones. Why would they ask for it when they are using Android?

Re: Aquaris E4.5 Ubuntu Edition

#213

Earlier quoted context omitted.

The only reason why some sites still use http is because of the need to purchase an ssl certificate from one of the cartelized CA providers.

How about ad fill rates? I'm not directly involved in add ops myself, but I've heard that now, even in 2015, major web properties still see a roughly 60% drop in ad revenue on HTTPS. Thats a big deal for an advertising supported website. (Though obviously not so much a big deal for a website like this selling an Ubuntu cell phone).

[deleted]

Re: Aquaris E4.5 Ubuntu Edition

#214
post #11
post #10

Nice touch that the clock on the screen shows "14:10", which is of course similar to the latest released Ubuntu version (14.10, from October last year). Coincidence? :) Not sure how the phone version of Ubuntu is versioned ( http://www.ubuntu.com/phone didn't help), though.

Not a coincidence. :)

Isn't the ubuntu phone using the RTM archive which has a different version number? :P

Re: Aquaris E4.5 Ubuntu Edition

#215

Earlier quoted context omitted.

Things like that always bug me. What if I live in Spain and only speak English. What if I live in a Catalan region and want Catalan? What if I live in GB and want to read it in Spanish as it's my first language? With the world being as global as it is and people readily moving around, geographic location does not equal language preference. Ideally the site would have geographic specific sections but allow all languag…

It would be quite a bit of work, to attend a very limited use case. Every Catalan (or Galician, Valencian, Basque) speaks Spanish, as do the vast majority of the expats I know (and I'm one myself). You can still access the specific site of the language you are interested in. Or, in the worst case, use Google translate.

That's too simplistic, and as expected wrong.

Some of those regions are known for being proud of their language and culture, so in case of similar specs and cost many people will chose a vendor that covers their native (or L2 but local) language instead of one that doesn't. Something to take into account is that e.g. Catalan (or Valencian or Balearic, you name it) represents between ~9M and ~11M native and L2 speakers (depending on sources). What else... Oh yes, the regions where Catalan is official in Spain are among the wealthiest when considering the average income for its residents. That sounds like a good pond to fish for early adopters. Basques with even less population (and less L1 and L2 speakers, even in % than Catalans) are also among the wealthiest. The use case doesn't seem that narrow anymore, doesn't it?

Every single big company in Spain is able to communicate in any official language. Dude, it means business!

Finally, and I'm leaving a lot of stuff behind, people are usually not very thick skinned and calling the support of these languages "very limited use case" could be considered, well... inconsiderate at least.

Re: Aquaris E4.5 Ubuntu Edition

#216
post #166

Earlier quoted context omitted.

Not necessarily. Allowing access on both http and https is indeed a bad practice, but not in regards to the scenario you described. The scenario you described has been covered since long by the 'secure' attribute, available when creating cookies. Assuming the authentication was performed from within the https channel, the cookie won't be disclosed when requests are triggered on the http channel. This covers the 'Redd…

In either case it leaks information. Even if I can't get your session key, I can see every URL you visit, and every field you put in. Also, if your login form can be served over HTTP (or any included script is, which thankfully Chrome now disallows when the page loads over HTTPS), I can just get your password. Guess how Reddit serves their login form? Yup, it's right on http://www.reddit.com/ .

You are right, all your Reddit traffic should be encrypted, but the reason is not because it's a vulnerability, it's because you have a personal expectation of privacy, which is different from an unexpected or undesired incident in their information system.

Let's not forget that from Reddit's point of view, the browsing of the public content is not confidential, hence no need to hide it. Only your credentials are confidential, hence their transmission is configured to happen through a secure channel by default (if you're lucky). As long as it matches their security policy, it is not a vulnerability, per say. The vulnerability here is that Reddit 1) accepts authentication events sent through HTTP and that 2) Reddit keeps considering accounts as reliable after a successful HTTP authentication. We could also argue on the quite insignificant consequences of your Reddit account being hacked (for most users) in opposition to the disclosure of a password that you have not used anywhere else (isn't it?).

As a user, you believe that the Reddit pages you browse should be private, which led you to conclude Reddit is flawed. I agree that Reddit users' traffic should be kept private. But, we are still in an era where information security is defined by the expectations of corporations, not those of customers/users. The total cost induced by the fact that anyone on the same network as you can see your Reddit traffic remains lower than improving the security of the platform.

If you want Reddit to consider this as a "vulnerability", you need to either convince lots of users to stop using Reddit until they fix this (traffic volume pressure) or convince loud people to start shaming their owners on large audience news sites (shame pressure). These two strategies are the only ones that work, to my knowledge. As long as their business keeps running and there is no shamming, they don't have any real incentive to pull the source code and fix this: it's not a major security vulnerability. (the fact that browsers overwrite https cookies from http responses is a major one, though...)

Re: Aquaris E4.5 Ubuntu Edition

#218

Interesting price strategy. They're obviously not aiming what you'd think of as the professional developer / early adopter market, otherwise they would have reduced the bezel, switched to a higher resolution screen, increased the specifications, and at least doubled the price. Are they hoping for this to be stocked in retail stores, and directly compete with Android at the Moto G sort of level? That does sound fairly…

bq is already a very popular brand here in Spain, so I suppose they will be targeting their current market (and if they get devs in the process, better).

Re: Aquaris E4.5 Ubuntu Edition

#219
post #216

Earlier quoted context omitted.

In either case it leaks information. Even if I can't get your session key, I can see every URL you visit, and every field you put in. Also, if your login form can be served over HTTP (or any included script is, which thankfully Chrome now disallows when the page loads over HTTPS), I can just get your password. Guess how Reddit serves their login form? Yup, it's right on http://www.reddit.com/ .

You are right, all your Reddit traffic should be encrypted, but the reason is not because it's a vulnerability, it's because you have a personal expectation of privacy, which is different from an unexpected or undesired incident in their information system. Let's not forget that from Reddit's point of view, the browsing of the public content is not confidential, hence no need to hide it. Only your credentials are con…

I consider them vulnerable. As a test I successfully hijacked a Reddit identity using nothing but tcpdump on my router. Leaking credential information is a form of vulnerability. Just because lots of people do this does not make it less vulnerable.

Even if Reddit allowed you to log in via HTTPS only and kept your session cookie secure, but let you browse anonymously over HTTP, they'd still be leaking info about what you are browsing, as you said. I agree, this is a problem for the user. Say, the user is looking at topics about maternity leave while her boss doesn't know she is pregnant. What can the boss do with this info? Or say the user is looking into methadone clinic experiences at work?

Browsing over HTTP also lets an attacker inject content. Ads are the obvious and somewhat innocuous case, but think about the phishing opportunities here. "Please log in to proceed" with a form that submits the password to the attacker.

You are right they won't change until either their users start complaining, or something really bad happens as a result of this negligence, but I am simply using them as an example of a pretty widespread issue. Lots of sites do this and it's very unfortunate.

Re: Aquaris E4.5 Ubuntu Edition

#220

OT: If anyone from bq.com is reading this: Why can't I select Germany, France, or Austria as a country to ship to? Why do I have to provide my nationality (personal information, not part of the shipping address)?

Looks like at least Germany and Austria have their own shop.

https://store-de.bq.com/de/

Post reply on HN