How you can’t get root

One of the first things I checked out on the 770 was how serious Nokia’s attitude was towards making it a secure system. I was pleased to find that there is decent privilege separation for the 770 and there was at least an attempt at shipping a secure system (albeit one nerfed for development purposes…) After a brief look around the system I found nothing embarrassingly obvious. Contrast this to Sharp’s Zaurus which had an empty root password, and even setting one was nearly useless, as I discovered /etc/shadow was world readable (why even use a shadow file then?) and there were world-writable configuration files that were executed in scripts run as root.

I would rather prefer an easier way to get root than the flasher method, I mostly never used the Zaurus’s dock, preferring to transfer data using scp, even doing upgrades using a compact flash card. The Zaurus had a number of applications that required root access, and installing them wasn’t a major hassle.  I think the 770 could benefit from a happy medium between the Zaurus’s total openness and the locked down configuration the 770 ships with.

Leave a Reply

You must be logged in to post a comment.