Live data from Hacker News

Kindle Touch jail broken via ID3 Tag

yifan.lu

31–36 of 36 posts

Re: Kindle Touch jail broken via ID3 Tag

#31

Earlier quoted context omitted.

I don't think Amazon has that much of a problem with the jailbreaks. I can't see how they would loose any money with it, and who uses them, knows that he can potentially brick the device.

whether they are looking the other way on jailbreaks or not, this sounds like a rather serious security problem. it's nice that i can run my own code on the device, but that also means that any mp3 files i download off the internet can run other, potentially malicious code.

Thankfully, this is the Kindle Touch, not the Kindle Fire. I"m guessing maybe 1% of people will use their Kindle Touch as an MP3 player, so this is mostly positive news - A jailbreak vector with little damage seen in the wild - the potential is their, it's just unlikely to be leveraged.

Re: Kindle Touch jail broken via ID3 Tag

#33
post #11

Earlier quoted context omitted.

I don't think Amazon has that much of a problem with the jailbreaks. I can't see how they would loose any money with it, and who uses them, knows that he can potentially brick the device.

I guess, this would mean that a user can remove the ads from the ad-supported Kindle and save $40. This would mean that Amazon loses almost 30% in revenue each time they sell a Kindle Touch that is to be jailbroken.

The ads are so good that I'd choose an ad-supported kindle over an ad-free one at the same price point. Virtually all my shopping, aside from perishable foods, can be done at Amazon.com -- I've bought toilet paper, ketchup, packing supplies, cereal, etc. there -- that the offers will probably pay for the device.

Re: Kindle Touch jail broken via ID3 Tag

#34

That's great. As a summary: This guy found out that most of the GUI is HTML and Javascript. Some of the JS functions are mapped to OS calls, including one that will run any script as root (nativeBridge.dbgCmd();). This function is disabled in the browser, so it needs to be called from somewhere else. So he injects the function call into the ID3 tag of an MP3 file and plays the file on the native mp3 player which has…

What a great, simple (not to diminish in any way), hack. Why did Amazon allow a call that always runs as root? Is it necessity, oversight, or something else?

dbgCmd() suggests it was originally there for debugging. It runs as root because the UI runs as root, AIUI.

Re: Kindle Touch jail broken via ID3 Tag

#35
post #11

Earlier quoted context omitted.

I guess, this would mean that a user can remove the ads from the ad-supported Kindle and save $40. This would mean that Amazon loses almost 30% in revenue each time they sell a Kindle Touch that is to be jailbroken.

Although the other "special offer" kindles have been jailbroken for some time, the kindle hacking community seems to be doing a good job of refusing to (at least for the relative layman) disable advertisements on them or enable any sort of tethering over 3g.

You must have a certain website or subset of the community in mind. I actually got a Kindle 3 a couple months ago and the majority of the discussion that I could find about homebrew on the device was centered around removing the ads. I browsed 4 or 5 forums before deciding it was a lost cause.

In fact, I wasn't even really able to find anything other than removing the ads and changing the screensaver as what you can do after your kindle is jailbroken.

Re: Kindle Touch jail broken via ID3 Tag

#36
post #32

It's an exploit and it will get fixed, but I'd like to see what people can do with root access. Will we see vanilla Android ports?

> but I'd like to see what people can do with root access. epub support!

All of the previous kindles have been rooted and I don't know of any homebrew to support epub on Kindle 3.
Post reply on HN