Showing posts with label web browsers. Show all posts
Showing posts with label web browsers. Show all posts

Friday, 1 March 2013

New Skyfire drops Flash video, old Skyfire keeps it


Flash is old, eats batteries for breakfast, and has almost as many bugs as Windows. But there are plenty of websites out there that don't work without it, so the old Flash is gonna be with us for some time to come.

Web browser Skyfire has watered-down Flash support. The only Flash it delivers is Flash video. You know, those video files in ".flv" format. Skyfire is useful for a few other video sites that other browsers won't touch.

But Skyfire made a very stupid decision. The new Skyfire drops Flash video support. Since the video capabilities are the only reason to use the app (it's not a very good web browser), Skyfire is useless since version 5.

But if you ever had version 4 running on your Android you get to keep video support. And because v5 is a totally new app, you can run the old and new Skyfire together if you want to.

If you never had version 4 installed, don't bother installing it now. The old Skyfire will only do Flash video for users who had the app before the switch to the Flashless version 5.

• old Skyfire v4.0 (with Flash video, but not for new users)
• new Skyfire (no Flash)

• how to force Flash on your Android phone or tablet


tweet this reddit digg this StumbleUpon digg this digg this

Wednesday, 12 September 2012

Dolphin Browser plugs location hole, gestures lose direction, Flash back, splash gone


Where do you surf?

Dolphin Browser is one of the best Android web browsers out there, mainly because of its highly customisable gesture controls and the way it handles tabs.

Unfortunately Dolphin has the nasty habit of pushing out updates with privacy issues. Last year they added a "webzine" feature that sent your entire surfing history to who-knows-where. They fixed it, but only after the web cried out and Dolphins reputation started to smell like rotten fish.

You still need to block traffic to https://tracken.dolphin-browser.com to keep your Android ID and other data out of Dolphins fins.

Where are you?

A couple of days ago a new Dolphin update punched a new hole in the app. After the update Dolphin started to poll your location at every app launch for no good reason. It took while, but eventually they released an update that fixes the location polling issue. Dolphin's more or less clean again, at least for now.

Do these privacy violations mean that Dolphin is a piece of malware made by spammers and scammers? Possibly, but given the speed with which they fixed the issues I think Dolphins programmers are not malicious but merely incompetent.

Where does my swipe point to?

The update that brought the location bug also brought more precise gesture control. Good stuff, but not really. The gesture update came at a price that I'm not willing to pay.

You see, I set up Dolphin to switch tabs with a single horizontal swipe. Drawing a line from left to right brings me one tab to the right, swiping to the left brings me one tab to the left.

But after last update Dolphin decided that a left-to-right swipe is too similar to a right-to-left swipe. The only way I could keep my gesture controls the way I want them was to restore my old Dolphin settings from my Titanium backup, because the new Dolphin no longer accepts a left-to-right swipe if you already set a swipe in the opposite direction. The direction of the swipe movement is no longer enough for Dolphin to tell different gestures apart.

Flash back, splash gone

Android 4.1, a.k.a. Jellybean, no longer supports Flash. Well, not officially. You can sideload Flash to your Jellybean device if you want to keep access to Flash-only sites. The problem is that Dolphin won't run Flash on Jellybean anymore unless you force it to, which requires root access.

If you restore a Titanium backup of your Dolphin settings from an earlier Android version Flash comes back to Dolphin, but only if you had Flash enabled or "on demand" when you made the backup. Of course you can use other backup apps like MyBackup to restore your old Flash-capable settings, but only if you made such a backup before you switched to Jellybean. If you don't have a suitable backup there's an alternative: just delete Dolphins settings file in its system folder and it will run Flash again.

The splash screen that entered Dolphin last update (probably to hide its slower startup) is gone. That's good, because if your app starts so slow that it needs a splash screen you have to fix its load time, not hide it behind a bit of eye candy.

• Dolphin Browser (Google Play Store)

• Flash in Dolphin on Jelly Bean (xda)

• Adobe Flash installer


tweet this reddit digg this StumbleUpon digg this digg this

Friday, 7 September 2012

Fishy browser Dolphin tries to track your location for no reason



History lesson

Dolphin Browser is possibly the best Android web browser out there, mainly because no other Android web browser can match Dolphins custom gesture feature.

But Dolphin doesn't always know how to behave. Last year it was caught sending all the URLs you visited to its own server. Unencrypted! Even when visiting https sites! After lots of bad publicity Dolphin cleaned up its act, but two weeks later the marine mammal started phoning home again. This time it sent your Android ID (a number that stays with your phone forever), a Dolphin client ID, and your carrier and phone specifications to itself. You can stop this, but only if your phone is rooted so you can block all traffic to https://tracken.dolphin-browser.com with an app like AdAway.

Dolphin didn't learn

And today Dolphin received another update that smells fishy.

When you launch the new Dolphin you'll find that it starts up slower than the previous version. The new edition throws a splash screen on your display, probably to hide the slower startup.

And then the real issue kicks in. Because the updated Dolphin asks your phone for your GPS location for no apparent reason. Some websites may ask for your location for a good reason, but Dolphin now tries to find out where you are even if you set a homepage that doesn't want to know your whereabouts.

Disabling location in Dolphins settings doesn't stop it from trying to grab your location. You can use apps like LBE Privacy Guard to stop Dolphin from polling your GPS, but this also stops legit location requests from sites like Nokia Maps.

Update 1: I got a mail from Dolphin in which they explained that  the location request on launch is a mistake. They're gonna kick their developers asses and make 'em fix their error. So Dolphin is not malicious but merely incompetent.
Thank you so much for your information.
We are so sorry for the trouble. We have tested and figured out that our developers changed the code which cause this issue by mistake.
Our senior engineers checked and confirmed that we did not upload your location data to the server. It is just a no-data transmission action.
We will correct this error and update soon. If you found any further issues, please don’t hesitate to contact us.
Update 2: Dolphin fixed the loaction leak.

Some good news

Dolphin is still an excellent mobile phone web browser once you stop it from phoning home and snooping on your whereabouts. The update added a few useful things too.

The new Dolphin has a download manager, a file manager, more accurate gestures, and it lets you switch off search suggestions.

The gesture improvement is very welcome. Because of the super customisable gestures and the way Dolphin handles tabs I still use Dolphin, but if a competing browser manages to match its gesture controls I may be tempted to ditch Dolphin.

Flash on Jelly Bean

Android officially stopped supporting Flash since Jelly Bean, and Dolphin on Jelly Bean won't run Flash anymore. Well, not officially, but there's a way to make it work on Jelly Bean anyway.

Restoring a Titanium backup of your Dolphin settings from an earlier Android version revives Flash on Dolphin, but only if you had Flash enabled or "on demand" when you made the backup. Of course you can use MyBackup or any of the other backup apps out there, as long as they're able to backup your app settings in addition to the app itself. Deleting Dolphins settings file in its system folder makes it run Flash too. Both methods require root access. Full details on the xda forum. Of course you need to sideload a copy of Flash too, but you can get it straight from Adobe.

• Dolphin Browser (Google Play Store)
• Flash in Dolphin on Jelly Bean (xda)
• Adobe Flash installer


tweet this reddit digg this StumbleUpon digg this digg this

Friday, 24 August 2012

I don't want your app, I already have a web browser


What's with websites that want you to install an app that loads a single site and no more than that?

Surf to any online forum on your phone and there's a good chance it will pop up some annoying Tapatalk spam.

Anything Tapatalk can do is possible with some HTML5 in any web browser, but at least Tapatalk lets you surf multiple forums in one app.

But what are sites like The Verge thinking?

The Verge has a mobile app. They could advertise it with a small banner or a line of text on their mobile site, but instead they shove it in your face with something that's even worse than a popup ad.

Popup ads are horrible, but at least you can click 'em away and arrive straight at the site you wanted to go to, because the popup and the site that spawns it load at the same time.

The Verge loads a screen nagging you about its app, and when you tap the "screw you, take me to the page I asked for" link it starts loading the page you're after, even though it knows you wanted to go there from the very beginning. You may continue to your target destination later, but next time you fire up your browser the ordeal starts all over again.

The Verge is not the only site that annoys the hell out of me. Plenty of other sites use the same obnoxious method to advertise their app. I'd welcome a mobile browser plugin that auto-skips all these nag screens. It would be even better if that plugin can make the Tapatalk popups drop dead too.

There's no way to make these popups and nag screens disappear yet, but at least you can kill most banner ads with apps like AdAway.


tweet this reddit digg this StumbleUpon digg this digg this

Tuesday, 14 August 2012

Flash for Android is dead, dig up a copy from the graveyard


Yes, Flash is old, buggy, slow, and it sucks your battery dry. So is it a good thing that Adobe pulled Flash out of the Google Play Store?

Flash is also unavoidable because many websites still use it, and some will keep using Flash until the end of times.

For example, the typical bar and restaurant site requires Flash to read the menu and book a table. These sites will ditch Flash eventually, but it's gonna take a while.

Artists use lots of Flash. Paintings, photos, poetry, literature, without Flash your online culture choices are very limited. And because art sites live a lot longer than the artists who built them you're gonna need Flash for years to come.

Games? Movies? Not all of them will be converted to HTML5 or other formats, so you'll need an old Flash player to see what was hot when your grandparents were young.

But with Flash no longer available in the Play Store you'll have to get your fix of Flash somewhere else. Fortunately that's really easy.

Adobe maintains an archive of old Flash versions. It has all the Android installers too, so you can simply download the APK file, check the "unknown sources" box in Androids app settings screen, and hit install. Don't forget to set your Flash Player privacy and security settings.

If Adobe ever pulls the Android Flash installers from their site there are plenty of sites, forums, P2P networks and other sources to dig up a corpse copy of Flash.

Keep in mind that your web browser needs to support Flash for the plugin to work. Chrome doesn't, and Opera crashes when it bumps into Flash. Current versions of Dolphin Browser, Firefox for Android, and the stock browser up to Android 4.0 (Ice Cream Sandwich) support Flash, but new versions may break it so backup your browser before you update it.

• Flash for Android on adobe.com

(if this link stops working, leave a comment or hit the contact link on the bottom of this page and I'll add other links)


tweet this reddit digg this StumbleUpon digg this digg this

Wednesday, 18 July 2012

BugMeNot for Android remembers


Bugmenot.com stores user names and passwords of "public" accounts for forums and other websites. If a site demands that you log in but you don't want to make an account, BugMeNot often helps out.

The BugMeNot Android app makes using BugMeNot in Android web browsers a lot easier. Instead of having to copy/paste the offending URL into bugmenot.com you can send it to the app with Androids built-in share menu.

Repeat visits don't require repeat sending of the URL to the BugMeNot app, because it now remembers the sites you asked passwords for. Of course you can remove remembered sites from the list, so don't let the new search history feature stop you from sneaking into (cough) wildlife picture sites.

You still have to copy/paste the user name and password back into the target site, though. Maybe this will be automated one day, but it looks like this requires a browser specific solution. A BugMeNot add-on for popular mobile browser Dolphin would be a good start.

• BugMeNot on Google Play
• bugmenot.com


tweet this reddit digg this StumbleUpon digg this digg this

Tuesday, 5 June 2012

BugMeNot moves to Android share menu


Don't want to sign up and log in to visit a site? BugMeNot.com stores user names and passwords of "public" accounts to get you in.

There's an Android app for it too. You can copy/paste the offending URL into it to get the login data, but the latest version makes things a bit easier. The update brings BugMeNot to the share menu, so you can launch it straight from your web browser with the URL filled in.

You still need to copy the login details back to your browser. Maybe a future BugMeNot update can automate that too?

• BugMeNot on Google Play
• bugmenot.com


tweet this reddit digg this StumbleUpon digg this digg this

Saturday, 19 May 2012

Dolphin browser spring cleaning, gestures need a finishing touch



Gestures

My favourite feature of Dolphin Browser HD is the custom gesture option. A swipe to switch tabs, an arrow to go to the next page, a cross to close the current tab, etc.

But when Dolphin decided to glue the gesture button to the bottom left corner without the old but useful option to move it to the other side I was not amused.

Fortunately Dolphin listened. The option to choose your own corner returned in the latest update of the app.

Almost perfect. It would be even better when I could choose different corners depending on whether I use my phone in portrait or landscape mode.

When you're right-handed, the bottom left corner is within easy reach of your thumb when you're phone is in portrait mode. In landscape mode things turn different. Now my thumb is close to the bottom right, and the bottom left is hard to reach. For left-handed people it's the other way 'round, which is why the position of frequently used buttons should always be left to the preferences of the user. As phone screens get bigger and bigger, the bottom right will be out of reach for the left-handed, and the right-handed won't reach the bottom left.

So Dolphin should expand its gesture button location settings. My choice would be "bottom left in portrait mode, bottom right in landscape view." If you're left-handed you'd want it the other way around. The best way would be to let us drag'n'drop the gesture button to our own preferred location on the screen, which could be different corners depending on the screen orientation.

Cleaning up

Dolphin cleaned up its user interface too. You can manage your bookmarks straight from the bookmarks bar. The quick access button is gone. That's not a big loss, because almost all of its functions are built into the menu. Except for one: your browsing history is buried in a counterintuitive place in the bookmarks bar, and you can't create a custom gesture for quick access to your history.

The gestures screen overlay could be a bit more transparent too.

Finally, sometimes you want to clean things up yourself, but Dolphin makes you tap way too much to throw out the trash. Clearing your cookies, passwords, history, etcetera requires a trip to the depths of the settings screen (this deserves a prominent place in the main menu!), and no matter what you select to throw out, Dolphin won't remember it. Next time you want to clean things up only the top three entries (cache, history, HTML5 data) are checked, and you have to retap everything else. Clearing the default entries takes six taps, zapping cookies and passwords takes even more.

But like all apps, Dolphin will be a work in progress forever. Let's see if future updates make the chore of cleaning up a bit less tedious. Maybe they can add a cookie manager too? And a Tapatalkblocker and a BugMeNot add-on? And and and...

• Dolphin HD


tweet this reddit digg this StumbleUpon digg this digg this

Friday, 18 May 2012

I don't want Tapatalk, so stop spamming me



There are plenty of discussion boards all over the web, and some of them are really useful. Unfortunately, many of them hate mobile browsers.

Search Google for any topic and there will be forum discussions in the search results. Hit one of those forum threads on your Android phone and you'll see a popup that tries to spam you into buying Tapatalk or similar forum reader apps. Some sites (xda, for example) even have their own forum app. As if anyone is gonna install an app that works for one forum only... next we'll be installing apps that only load a single website. Oh wait...

The most annoying thing about all those Tapatalk and Forum Runner popups is that they keep coming back. The only way to get them out of the way for a while is by allowing them to set a cookie on your phone, and keeping that cookie installed. If your browser deletes all cookies upon shutdown (you know, to try make the advertisers forget you) the Tapatalk popups never end. And junkfilters like AdAway or AdFree can't touch them, because the Tapatalk spam loads from a javascript on the forum site itself.

I wonder if those forums get a kickback on the app sales, because I can think of no other reason why any forum would allow such an annoying stream of popups to launch from their sites. A simple unobtrusive text link on the bottom of their website would do the job without making their sites look like an online casino that promises free pr0n and browser toolbars full of "interesting offers tailored to your interests." Maybe it's the Vigilink affiliate advertising spam in Tapatalk that makes forum admins drool with dollar signs in their eyes?

(Yes, this site has ads too. Feel free to block them, you're equally welcome if you do. Just block "pagead2.googlesyndication.com" and you'll never see those Google ads again.)

If anyone knows a way to kill the Tapatalk popups without having to make my mobile browser pretend to be a desktop browser or allow the Tapatalk cookies to stay on my phone forever, please leave a comment or hit the contact link on the bottom of this page.

Those Tapatalk popups have to die. All of them.

p.s. When I searched "block Tapatalk popup" on my phone, the built-in error correction automatically changed "popup" into "poop." Android is even smarter than I thought!


tweet this reddit digg this StumbleUpon digg this digg this

Thursday, 17 May 2012

BugMeNot for Android

Many sites want you to sign up and log in before they let you do anything. Not all, though. The xda forums saw the light a long time ago, and they removed the login requirement to download apps from their forum.

But there are plenty of sites that want you to sign up, hand over your email address, and log in whenever you want to read or download something. This can get annoying real quick, especially for sites that you plan to use only once.

Enter BugMeNot. This service at bugmenot.com uses community-generated login/password data to use sites without signing up for an account.

And now there is an Android app for it. Copy/paste the offending URL into the app, then copy/paste the login data back into your web browser to sign in without signing up.

Bug to spray away: special characters often show up as little rectangles or other crazy symbols, and those logins don't work. BugMeNot should learn how to deal with different character encoding formats.

Edit: Good news! A BugMeNot update killed the bug.

BugMeNot won't remember anything, so if you visit a site more often you have to feed the URL into the BugMeNot app over and over again. A bookmark feature in BugMeNot would make the app a lot better. It could use some browser integration too. It would be really convenient to hit the "share" button in your mobile browser, tap BugMeNot, and have the login details automatically filled into the form fields.

Edit: BugMeNot is now available from the share menu and takes you straight to the passwords. You still have to copy/paste 'em into the form fields yourself, but maybe that will be automated in a future update? A BugMeNot add-on for Dolphin would be great too.

For now you might as well bookmark bugmenot.com in your browser, but if the app matures a bit it may become a welcome addition to your arsenal of useful Android apps.

• BugMeNot on Google Play
• bugmenot.com


tweet this reddit digg this StumbleUpon digg this digg this

Tuesday, 15 May 2012

Firefox for Android wins Flash, loses sidebar


Flash outdated? Most artists have sites that require Flash, and if you try to check restaurant opening hours or book a table you'll find that nine out of ten restaurant sites don't work if your browser can't handle Flash.

The good news: after Dolphin, the stock browser, and many other Android browsers, the latest beta test version of Firefox does Flash too.

The bad news: the sidebars are gone. Maybe they looked to much like the Dolphin sidebars? Your tabs are now in a pulldown menu next to the address bar. A side effect of this is that the address bar is always visible, which is not a good idea for a browser that's meant to work on small screens where every pixel counts.

Text rendering sometimes goes wrong and the double tap to zoom option is erratic on many pages since the update from beta 13 to beta 14. Sometimes it works, but when it doesn't work pinch to zoom is the only way to resize. Doesn't sound like a big deal until you try to pinch while your other hand is busy holding your bag or your girlfriend. And your pinches don't hold: if you return to a resized page with the back button you'll have to resize it again. Firefox won't remember your zoom level, not even during a single browsing session.
Update: Most of these problems are fixed in Firefox Beta 15.

Firefox Beta 14 comes with a new start screen, which resembles the start screens of other mobile browsers. But where the default start screens of browsers like Dolphin are optional, the new Firefox start screen is not. Gone is the option of launching Firefox straight into your own custom homepage. The new Firefox always launches with its new start screen whether you like it or not.

Scrolling doesn't always work well, especially on pages with frames. If a page has iframes you won't be able to scroll outside the iframe, which makes large parts of the page totally inaccessible. Now don't counter that iframes are ancient history, because there's an entire internet full of interesting sites that still use them and many of them will never switch to style sheets.

There are lots of things to fix in the next beta. Flash in Beta 14 works pretty good, but I'll keep Firefox Beta 13 from my Titanium backup until the new bugs are dead (edit: many of them are fixed in Firefox Beta 15) and the forced start screen goes away. Not that I'm gonna miss much, because I usually surf with Dolphin HD. I only use Firefox for Android for its save to PDF feature, which works better than in any other Android browser. Firefox is my favourite browser on my notebooks and desktops, but its Android version is no match for Dolphin, Boat Browser, Maxthon, Opera, or even for the stock browser.

Bonus tip: if you use Flash in Firefox you may want to edit your Flash privacy and security settings.

• Firefox Beta
• Dolphin HD


tweet this reddit digg this StumbleUpon digg this digg this

Saturday, 14 April 2012

Dolphin browser gesture doesn't get it right



Update: you can move the gesture button to the other corner again.

The unique selling point of Dolphin Browser HD is the way it lets you make and use custom gestures to switch tabs, move around your sites, and much more.

The latest update changes the way gestures work, and I don't like it at all.

The old Dolphin would let me choose if I wanted my gesture button on the bottom left or bottom right of my screen. That's how it should be, because there are left- and right handed people out there and they all have their personal favorite position for the gesture button.

The new Dolphin forgot all about ergonomics. It added a "go to page top" button which is not only useless for most (we already had gestures for that, right?), but it sits on the bottom right corner of your screen by default.

That means that the gesture button now sits on the bottom left, and there's no way to move it anywhere else.

Update: you can move the gesture button to the other corner again.

Not much of a problem in portrait mode, but tilt your phone to landscape mode and you'll probably find that the gesture button is out of reach if you're right handed. Say goodbye to single handed browsing unless you switch back to portrait position.

The new gestures share a screen with the Sonar feature. Sonar is Dolphins voice input. You're probably not using it, which is why Dolphin decided to push its Sonar in your face. It's now a tab on the gesture screen, and for some inexplicable reason you have to enable the Sonar button or else you will have no gesture button at all.

The transparency of the new gesture overlay is almost zero, so you can no longer see the page that you're drawing gestures on.

There's one tiny little ray of light. If Dolphin doesn't understand your scribbled gesture it shows a "did you mean..." set of suggestions so you don't need to draw again.

Another nice touch: the add-on sidebar now shows names in addition to icons. Too bad Dolphin found it necessary to clutter up the sidebar with some more placeholders for add-ons you'll probably never use, and there's no way to delete them. The add-on set needs a bit of a spring cleaning anyway. Really, is anyone gonna download the 2010 World Cup add-on now?

Let's hope Dolphin cleans things up in its next update.

• Dolphin HD

tweet this reddit digg this StumbleUpon digg this digg this

Wednesday, 29 February 2012

Dolphin Browser HD listens, makes Webzine an optional plugin, and makes it easier to open links in a new tab



Dolphin Browser HD is probably the best web browser for Android. Its gesture control options are way better than what the competition has to offer, the bookmark sidebar works really well, and its extendability with plugins is pretty good too.

And the latest update makes it better.

The controversial Webzine feature has been pulled out of the main app, but if you really want to keep it you can add it back by installing the new Webzine add-on.

Two add-ons (the two most popular according to Dolphin) are now built into the browser, sort of. The web-to-PDF plugin and the screenshot add-on appear in the add-on sidebar, but you still have to download them if you want to use them. If you don't want them the placeholders stay in your add-on tab you're out of luck. There's no way to delete the dead shortcuts from your sidebar.

But maybe that will be fixed in a future update. After I complained about Dolphin's unencrypted backups they added encryption.

More good news: they finally got rid of the background tab popup. Now the menu that appears when you long-tap a link just gives you the two obvious choices (switch to new tab, or open it in the background) without the need for unchecking a "remember my choice" checkbox over and over again.

So yes, Dolphin listens.

It really listens now, because Dolphin added voice control too. You can navigate, search, and bookmark by shaking your phone and talking to your browser. It's an experimental feature that's really slow and fails often, but that may improve in future updates. If you don't want Dolphin to eavesdrop you can switch it off in the settings screen.

Minor annoyance fix: the sidebar sensitivity is reduced, so you no longer open them by accident when you just want to scroll horizontally in a web page.

Dolphin seems to learn from its mistakes, so I guess they managed to resist the temptation to reintroduce some sort of phone home behaviour. If not, I'm sure the Dolphin watchers in the xda forums will catch them soon enough.

• Dolphin HD (Android Market)
• Dolphin Mini (Android Market)


tweet this reddit digg this StumbleUpon digg this digg this

Monday, 12 December 2011

Flash updated, check your privacy and security settings again


iPhoners may believe that Flash is dead, but if you ever tried to book a table from a restaurant homepage or watch video on non-YouTube sites you know better. Without Flash you'll stay hungry and miss out on lots of content. Flash for mobile is slowly dying, but it's gonna stay a necessary evil for years to come.

Adobe released yet another update to squash bugs and patch security holes. Unfortunately you have to reapply privacy and security settings that you may have set before.

Since early October Flash adds an icon in your app drawer that takes you to its Flash player settings page. There are two things to play with: "Local Storage" lets you block Flash supercookies that are usually set by annoying advertisers to follow you around on the web. The "Peer-Assisted Networking" page lets you save mobile data by switching peer-assisted networking off.

If you disabled local storage and peer-assisted networking before you better hit the Flash settings again. When I updated Flash both features were automatically reset to allow all, so I had to tame Flash again.

Don't forget to fire up the settings manager in all your Flash-enabled browsers, because your Flash settings for the stock browser don't carry over to Dolphin or Skyfire, and vice versa.

A security update that undoes your security settings... don't do this again, Adobe. Next update I expect my settings to stay.

• Flash (Android Market)

Adobe pulled Flash out of the Android Market Google Play Store and doesn't maintain Flash for Android anymore. If your Flashless phone stumbles upon a website that requires Flash (plenty of them still do) you can install and run an archived copy of Flash.


tweet this reddit digg this StumbleUpon digg this digg this

Friday, 2 December 2011

Web browser Dolphin HD now encrypts your backups, adds off switch to webzine toggle, ditches exit menu


Dolphin HD is a strange animal. It has the best features of any Android web browser: well designed tabs, a very useful bookmark sidebar, and its highly customisable gesture controls leave the competition gasping for air.

But this marine mammal has a fishy side. You need a rooted phone and a bit of Android hosts file editing to stop it from calling the mothership, and its backup feature may put info out in the open on your SD card that should be locked.

Encrypted backups, finally!

The latter problem is fixed in the latest update. The old versions didn't encrypt their backups, but the latest version does. I guess a bit of complaining on blogs like this helps ;) Head to the settings and set a password to make sure nobody can grab login cookies and other sensitive data from Dolphins backup files on your memory card.

A bunch of off switches

More new stuff that puts you in control: get rid of the confirmation screen that pops up when you you exit Dolphin with the back button, dump the annoying "rate me" nag screen, and disable the webzine toggle. If you choose to keep webzine on Dolphin will send the URLs you visit to its webzine server, but if you opt out your surfing habits should remain private. If not, I'm sure the folks at the xda forums will find out real soon.

Links in new tab dialog still flawed

Something that didn't change: when you open a link in a new tab and choose between switching to the new tab or opening it in the background, the "remember my decision" checkbox is still checked by default. This doesn't make any sense. If the box was unchecked, you'd only have to check it once. But because it's checked by default you have to uncheck it over and over again. Even worse: if you allow Dolphin to remember your choice by accident it's really hard to make it forget again. Restoring your settings from a backup (if you have one) or resetting to default settings is the only way out.

• Dolphin Browser (Android Market)


tweet this reddit digg this StumbleUpon digg this digg this

Monday, 14 November 2011

Dolphin Browser phones home again, here's how to stop it


When Dolphin Browser was caught sending your entire surfing history to its webzine server they got so much bad publicity that they had to clean up their act real quick. You'd expect that they learned something from that fiasco, but they didn't.

Dolphin HD version 7.1.0 was caught spying on the same day that it was released.

The new Dolphin sends your Android ID (a number that stays with your phone forever), a Dolphin client ID, your carrier and phone specifications to https://tracken.dolphin-browser.com.

Well, at least they use encryption. And the information isn't really that sensitive. Still, they frequently grab usage statistics and information about your phone without letting you opt out.

Of course you can opt out yourself. The obvious method is to remove Dolphin from your phone, but then you miss out on all its features which leave the competition in the dust. A better way to stop Dolphin from phoning home is to block the target URL in your Android hosts file. This file is usually in /system/etc/hosts. You can edit it manually, or feed the offending domain names to the blocklist of AdAway. Either way, you'll need root access. The URL to block is tracken.dolphin-browser.com.

To cut the line between Dolphin and its maker add these three lines to your hosts file or block the domains with AdAway:

127.0.0.1 tracken.dolphin-browser.com
127.0.0.1 en.mywebzines.com
127.0.0.1 pnsen.dolphin-browser.com

The first line stops usage stats collection. The second line cuts off URL collection by the webzines server (Dolphin stopped sending it, but you never know if it comes back). The third line prevents the popup that begs you to rate Dolphin in the Android Market.

Phoning home is not the only new feature of version 7.1.0. The update allows importing bookmarks from Dolphin Mini, deleting bookmarks from the side bar, picking a different search engine if you don't like Google (you can choose Bing and Yahoo too), and some bug fixes under the hood. Too bad for Dolphin that its data grabbing will get much more attention than the bookmark and search improvements.

Dolphin still doesn't encrypt its backups, so if someone steals your phone they can pull all sorts of private info from your SD card, even if your phone is locked.

Update: Dolphin finally encrypts your backups!

Gesture commands, tabs, plugins, bookmarks sidebar etcetera make Dolphin an excellent mobile web browser, but the way it handles security and privacy is unacceptable. It shares its bad habits with plenty of other Android apps, so root your phone and protect it with electronic condoms like AdAway, DroidWall, and LBE Privacy Guard. Android and its apps need a permanent reminder that it's your phone and your data.

• Dolphin Browser HD


tweet this reddit digg this StumbleUpon digg this digg this

Sunday, 30 October 2011

Yet another Dolphin Browser security issue: think twice before backing up


Update: Dolphin finally encrypts your backups!

Dolphin Browser HD may be the Android browser with the most features of the pack, but it doesn't always behave well.

It used to send your entire surfing history to its webzine server. That got fixed in an update after the entire web screamed murder about it.

But there's another problem that remains unfixed, and this problem can cause a lot of trouble if exploited.

Dolphin has a backup feature that lets you backup all its browser settings, bookmarks, cookies, etcetera to your SD card. If you tell Dolphin to remember your logins and passwords they'll be included in the backup too.

It's your own choice to make backups or not, so what's the problem? The problem is that nobody expects their backups to be in a format that can easily be abused by anyone with access to the backup file. You'd expect the backup to be in a secure format, but unfortunately it's not. The backup is not encrypted, so anyone with access to your SD card can look into the backup file (sdcard/TunnyBrowser/backup/databases/webview.db) and read your stored passwords and login cookies.

Even if you sit on top of your phone 24/7 that doesn't mean your backup is safe. Any app with permission to read your memory card and go online (that means just about every app on the Android Market) could send the unencrypted backup file out and steal your passwords and login cookies. It only takes one evil programmer to release a bad app on the market to send your Dolphin backups out. Maybe those bad apps are already out there.

Any app that stores data on your memory card should consider the SD card of your phone an unsafe location that should only store sensitive data under lock and key. That's why backup app Titanium lets you encrypt its backups. The other big backup app out there does not. MyBackup should add encryption as soon as possible.

With all the recent fuzz about Dolphin you might think this web browser is a malicious app. It's probably not. The security issues are more likely a result of incompetence rather than evil intent. Of course that won't make any difference to you if your passwords get stolen, so if you keep surfing with Dolphin make sure you take your own measures to close the security holes.

My advice: do NOT use Dolphins built-in backup feature unless you've cleared your saved passwords and login cookies. If you want a backup with your login data included, just make an encrypted backup with Titanium.

Update: Dolphin finally encrypts your backups!


tweet this reddit digg this StumbleUpon digg this digg this

Saturday, 29 October 2011

Dolphin Browser clean after a bath and a shower


Dolphin HD is the most feature rich(tabs, gesture commands, bookmarks sidebar, and much more) web browser in the seas of Android , but the marine mammal was smelling like rotten fish lately.

Flipper was still unclean after a bath, but a post-tub shower washed away the dirt.

What gives? Three days ago Fnorder found out that Dolphin HD was sending all your surfing history, including searches and URLs with private information, back home to en.mywebzines.com, a server owned by Dolphin. He shared the info with the world through the xda forum, and then the waves got rough.

The reason? Since version 6 Dolphin ships with a "webzine" feature that lets you display sites in a kind of Google Reader style. To ease toggling between normal and webzine view Dolphin compares the page loaded on your phone with a list of webzine-enabled sites. It does so by sending the URL to its own server to look for a match.

Doesn't sound like a big deal, except that 1) Dolphin never told us about it until we found out ourselves, 2) some URLs can contain sensitive data, especially if they point to a private network or if they're of the http://site.com/?private.stuff type, and 3) the data is sent unencrypted, even for https sites (which opens the doors to hijacking and mutiny).

And then Dolphin released version 7.0.1 of their app and told us that the URL snooping was gone.

But...

Hi Android Underground. It has come to our attention that the hot fix update we pushed out last night on Android Market (7.0.1) did not fix the issue, thank you for noting this!

It has now been resolved and is live on the Android Market as Dolphin Browser HD v7.0.2. Again, user privacy is a huge priority for us and we thank you for your patience while this has been resolved.
Alex Molloy on the Dolphin blog

First things first. The first one to notice (and share) that the first update still fished for your URLs is xda member Keiji, and Fnorder was the first to confirm that v7.0.1 remained fishy. So Alex Molloys words of thanks belong to them.

The good news is that the latest update to version 7.0.2 really fixes the issue. Dolphin screwed up in their first attempt, but v7.0.2 is clean and shiny and doesn't send your browsing data home.

So if you haven't already done so, head for for the fish market and update your copy of Dolphin HD to keep your surfing safe.

Dolphin, take note: Wireshark is watching you, no matter how deep you dive.

• Dolphin Browser HD
• Dolphin caught in the nets of xda


tweet this reddit digg this StumbleUpon digg this digg this

Friday, 28 October 2011

Dolphin Browser washed, still dirty


Update: Dolphin clean after bath and shower

Androids most popular browser Dolphin HD got caught in the nets of those who fish in the deep waters of their phones. The update to version 7.0.0 added a Cloud To Device Messaging background service that kept swimming, even for those who have no use for it.

Todays update to version 7.0.1 fixes that. The C2DM service stays underwater if you don't sign up for Dolphins bookmark sync service.

But Dolphin has more dirt under its tail fin. It's fishing for your data! Dolphin HD 7.0.0 sends all visited URLs back home to Dolphin without asking for permission or even telling that it did so and why it did so. It's been doing so since version 6, when the webzine feature was added to the browser.

Dolphin responded on their site:
"Webzine simply performs an ancillary check if we can view current webpage in Webzine format . It is not critical and we have temporary removed this functionality in our latest update yesterday.

[...]

While it has been immediately disabled, we do think that the “Toggle Webzine” feature is a useful one for exploring the Web and will be adding an “opt-in” feature in forthcoming releases to enable this function. The code and URL-checking process will be made very clear to users, and will only be enabled if a user wishes.
Again, our update last night have temporary removed this functionality to avoid any confusion or concern you may have."
(source: Dolphin blog)

Sounds good, right? Wrong! When the folks at xda tested the update (version 7.0.1) it still shipped all your surfing habits to the mothership. Dolphin promised to play fair but lied about it! So if you told your Android hosts file to block all communication with en.mywebzine.com you better keep blocking it. If Dolphin doesn't swim back to clear waters it may be time to fish for another web browser.

Take home message: if you make a popular app anything your software does will be closely watched and made public. Apps that don't behave are fed to the sharks.

If you want to keep using Dolphin without sharing your browsing history, add these lines to your Android hosts file:

127.0.0.1 en.mywebzines.com
127.0.0.1 pnsen.dolphin-browser.com

The first line stops the URL phone home behaviour, the second line blocks the annoying "rate me on the market" popups.

You can add the entries to your hosts file (usually in /system/etc/hosts) with a text editor, but it's a lot easier to enter them in the blacklist of AdAway. No matter which method you use, you'll need root access for it.

• The pros and cons of Dolphin
• Dolphin caught in the nets of xda
• AdAway

Update: Dolphin clean after bath and shower


tweet this reddit digg this StumbleUpon digg this digg this

Wednesday, 26 October 2011

Dolphin Browser: spyware?


Update: Dolphin clean after bath and shower

Dolphin is probably the most popular web browser for Android. There's a good reason for that, because is has a couple of killer features: unlimited tabs, gesture controls, and much more.

The bad news: version 7.0.0 adds a cloud to device messaging service (Dolphin Connect) without an off switch. The next version better come with a toggle in the settings menu for those who don't want Dolphin Connect listening online when there's no need for it.

The really really really bad news: a couple of updates ago Dolphin added a feature called "Webzines," and it seems that this addition turned Dolphin into spyware.

According to Fnorder on the xda forum the new Dolphin sends the address of every site you visit, every link you tap, and every search query you enter to http://en.mywebzines.com. The domain mywebzines.com is probably owned by Dolphin itself.

Maybe your surfing trips are sent out to target advertising, maybe it's just an innocent way to collect anonymous browsing statistics. Either way, having all your URLs collected can be a real security issue because many sites generate URLs of the www.domain.com/?personal.data type. And let's not even think about URLs for pages on your internal network, or URLs along the lines of [password]:[username].site.com.

If you want to stop Dolphin from sending your browsing history to mywebzines.com, open your Android hosts file (usually in /system/etc/hosts) and add this line to it:

127.0.0.1 en.mywebzines.com mywebzines.com

If you don't want to edit your hosts file by hand, you can blacklist the domain en.mywebzines.com with AdAway.

Editing your hosts file or using AdAway requires root access, but if you know what's good for you and your phone you'll have rooted it anyway.

You can also patch the Dolphin app itself so it doesn't send your surfing secrets out. Fnorder posted instructions on taming Dolphin by killing the offending code with APKTool.

Keeping your browsing data away from mywebzines.com will break the Webzine part of Dolphin, but does anybody really use that anyway?

Of course you can just throw Dolphin back into the ocean and surf with another browser, but keep in mind that other web browsers may do the same evil thing. For example, Boat Browser phones home to www.umeng.com and Maxthon reports to mm.maxthon.com and stats-a.maxthon.com.

Open source browser Firefox for Android is probably clean. Unfortunately it's not ready for human consumption yet. The best Dolphin alternative is xScope, but it lacks many of the features that make Dolphin such a popular browser.

This fish marine mammal should clean up its act real quick, or else I'm gonna eat a lot of tuna.

• Dolphin
• AdAway
• The Dolphin is fishy thread on the xda forum
• xScope (Android Market)

Update: Dolphin clean after bath and shower


tweet this reddit digg this StumbleUpon digg this digg this