Tuesday, 29 April 2014

NFC apps: when are they gonna grow up?


If your phone is fairy recent (and it's not an iPhone), there's a good chance that it has a Near Field Communication chip. Your Android tablet probably has one too.

But is it good for anything else than reading public transport chipcards?

Things to scan that you already have

Your passport probably has an RFID chip in it. And your ATM card, your credit card, your drivers license. Grab NFC TagInfo from the Google Play Store, scan your cards, and see a bunch of numbers that don't make any sense to you. Get NFC Passport Reader and you can see what your passport is hiding in its chip.

That was useful, wasn't it?

Share your WiFi password, but not by NFC

An NFC sticker on your wireless router, or on the wall, and you don't have to tell your guests your WiFi password anymore, and they don't have to type it into their gadgets either. Just a tap on the NFC tag and they're connected. Cool, no?

There are plenty of apps out there to share your WiFi data. NFC Wifi, Instant NFC WiFi, NFC Wifi Reader, WifiTap WiFi NFC, InstaWifi, just to name a few. There are plenty of apps out there to share your router password to your visitors.

And that's where the trouble starts.

You can write an NFC tag with your WiFi details in it, but your friends can't read it unless they have the same app installed. If they have another app the tag pretends there's no app at all and pops a link to the Play Store where your guests can download the WiFi share app... after manually setting up the WiFi connection that they tried to set up automatically with your NFC tag.

There seems to be a universal format that should be independent of the app itself. Your tag writer should know about that universal format, and their tag reader should know it too. In real life you're better off dropping the data in a QR code. No matter what QR scanner your friends use, they'll be able to read your universally coded router credentials.

Hand out your contact info

How many business cards have you thrown away already? Put a few hundred people together in a meeting and they'll waste a tree on business cards alone.

Now here's where NFC could save the day (and the planet). Because there is a universal contact format called vCard. It's been doing the rounds since Fred Flintstone was a young boy and Dino was a puppy. Even my ancient Nokias could handle vCard, and that was way before the smartphone rage started. Every device with an address book in it can read it.

Again, plenty of apps out there to do the dirty work. NFC Business Card is one of them. Just make sure that you choose the universal vCard format, and not a proprietory knockoff layout.

Too bad you need an NFC tag with enough storage to hold your collection of middle names, phone numbers, emails, URLs, home address, business address, etc. The cheapest tags barely hold your name and email.

Keep it secret

An NFC tag can work like a key. For example, you could encrypt notes on your Android with a key stored in an NFC tag glued to your wallet.

Crypto NFC does just that.

It doesn't do it very well, though. The app is clearly a work in progress with a long way to go. You can write notes with it, and edit them later on, but you can't delete them. You can't back 'em up either. As for sharing them with other devices, maybe sometime in the future?

And the color scheme is terrible, with no way to change it.

But the number one reason for not using the app (yet): there's no fallback mechanism if your tag gets lost or damaged. No password you can enter just in case. The only way to protect yourself against tag loss is to make a bunch of key tags and hope that at least one of them survives your violence and sloppiness.

Wake up!

NFC Alarm Clock should get you out of bed like a bucket of cold water can. Write a tag, set an alarm with the app, and now it won't stop making noise until you tap your phone against the tag, which you glue to your coffee machine, bathroom door, or another strategic location far away from your bed.

Great idea, if it works. The app can be buggy, so check for missed alarms before you use it to wake up for your own wedding. It won't do repeat alarms. You can't even set your own alarm tone or alarm volume.

And it's too easy to cheat the alarm and stay in bed anyway. You can shut it up by switching off your phone, or rebooting it, or killing the app from Androids built-in app manager, or by long-pressing the back button if you're using the most popular custom ROM out there.

So have your mom keep that bucket of cold water ready anyway.

Or use Puzzle Alarm Clock. It comes with NFC tagging too (and QR codes), and is way more developed and way less buggy. And it's got recurring alarms too. The increasing alarm volume option alone makes it better than the alarm clock app with NFC in its name.

Get paid to tap

Billing your work by the hour? By the minute? No need to watch the clock because NFC Time Tracking does that for you. Just write NFC tags for your billable projects and tap your timesheet together.

Automate things

Silencing your phone or switching to airplane mode by tapping a tag on your desk is not useful. It's micromanaging to the extreme, because a long-press on your power button doesn't take much longer and you don't even have to be anywhere near your tag for that.

Come to think of it, most location-based actions are better done with Llama. No need for any tags at all, just set and forget and walk into the right place. Done.

The one useful static location tag is the sticker next to your bed that lets you tap silent mode on at night and off in the morning. Although the "off in the morning" part would be better suited for an NFC-less out-of-WiFi-range trigger so you can have your morning coffee without hearing your boss call to ask why you're late again.

It gets different for things that move around a lot, like your car, passport, shoes, or computer.

An NFC tag on the dashboard is a great way to autoswitch from WiFi to mobile data, turn on your GPS (if your phone is rooted), launch your navigation app, and fire up your music player all with a single click on the but... err I mean a single tap on your NFC sticker.

Tap your passport (if it has an RFID chip) and auto-launch your mobile boarding pass, turn up the brightness, and disable auto-rotation to speed you past the bagage dropoff machine, the security checkpoint, and the gate.

Tap the NFC tag on your sneakers and get your running tracker rolling.

Do you often tether your laptop or tablet to your phone? Stick a tag on your computer and one tap gets your phone hotspot running. It saves you a tap on your hotspot widget. Yep, that's not much, but with a rooted phone it can also save you the trouble of unlocking your phone and swiping to the screen with the hotspot widget. Oh wait, we're micromanaging the taps again.

Location-based If This Then That app Llama reads NFC tags too, but if you want a dedicated NFC task runner there are plenty of apps to choose from. Here they come:

NFC apps

General tag reader
NFC TagInfo

Passport reader
NFC Passport Reader

WiFi password taggers
Instant NFC WiFi
InstaWifi
NFC Wifi Reader (companion app: NFC Wifi Writer)
WifiTap WiFi NFC
They're not compatible with each other. Yes, that sucks!

vCard writer
NFC Business Card

Note encrypter
Crypto NFC

Alarm clock
Puzzle Alarm Clock
NFC Alarm Clock

Time tracker
NFC Time Tracking

If This Then That apps
Llama (cell location and NFC tags)
AnyTAG NFC Launcher
NFC Tasks and NFC Tools
Trigger
NFC Actions
NFC Tag Control
NFC TagWriter by NXP
NFC Smart Q

tweet this reddit digg this StumbleUpon digg this digg this

Wednesday, 2 April 2014

Freshly updated list of Android bloatware that's safe to delete, or not. You decide!



Your Android phone or tablet came with so many preloaded apps that you only get to use half of the advertised memory. And most of the junk starts up all by itself as soon as you think about looking at your phone.

If your Android is rooted, it's time to clean up the junk. And not only if you run a stock ROM, because custom ROMs come with lots of junk too. Yes, even CyanogenMod.

But what to zap and what to leave alone? You don't want to brick your phone, you don't want bootloops on your tablet, and you don't want to delete something that you can only get back aboard if you reflash your ROM. And the names of the bloatware apps are so cryptic that even Google doesn't know what they're doing. Yes, really. Google for "somecrypticjunk.apk" and you'll find it back in hundreds of "safe to remove" list just because removing it didn't kill the phone of someone out there. Needless to say, deleting it will turn your phone into a paperweight, but don't ask forums like xda what the app is for. If you do, you'll get one of two equally useless answers:
1) "Google it." [If Google knew I wouldn't be asking, duh!]
2) "Just delete it. I don't know what it does, but trust me, it's safe."

So here's a list of apps that are safe to remove. Or not. Only you can decide if your gadget needs it, so it's not just a list of apps, but also a list of what those apps do and what might break without them. Have a click:

The android underground Android system APK list

If you spot any errors or have something to add to the list please hit the contact link on the bottom of the page or leave a comment on this blog post.
tweet this reddit digg this StumbleUpon digg this digg this

Saturday, 15 March 2014

WhatsApp or Android, who's to blame for appgate?


Hang 'em high!

Scandal! Stop the presses! Any app on your Android phone can steal all your WhatsApp messages from your SD card. Facebook didn't have to waste 19 billion dollars to read your chats. They could just have made the Facebook app grab your WhatsApps off your card. Someone's gotta get fired over this, right?

But who?

Let's blame WhatsApp

WhatsApp stores its message database and nightly backups thereof in plain sight on your memory card, no matter if your memory is built-in or added on a microSD card. That's great if you want to mix'n'match your WhatsApps and SMSs with apps like Backup Text for WhatsApp and SMS to Text, but not so great if you want to keep nosy apps out of your texts. Anything with SD card access can read along.

WhatsApp could easily have prevented this by encrypting your messages. They gave it a shot after the shit hit the fan, but so far without success. That's because WhatsApp used the same key to encrypt all messages from everyone. Yep, that's almost impossible to believe, but they really used a skeleton key to lock up your private chats.

So here's what WhatsApp should do: use a proper full-blown encryption method to protect the database that holds your messages. While they're playing with encryption anyway, full end-to-end encryption to keep Facebook and the NSA out of our chats would be most welcome too.

Of course WhatsApp should provide a method to let other apps into your messages if you allow them to. I don't want to lose Backup Text for WhatsApp and SMS to Text, and the long overdue multi-network app that includes WhatsApp needs access to your WhatsApps too. To cut a long story short: WhatsApp should encrypt its database and let us decide for ourselves who gets the keys and who does not.

Let's blame Android

Android treats your memory card the same way your computer treats your hard drive. Apart from a tiny bit of protected storage (that mysterious ".android_secure" folder that tops the list in your file browser) anything on your card can be read, altered, deleted, stolen, smeared, raped, and tinkered with by any app that has the "storage" Android permission. Most apps have that permission, so anything on your memory card that is not encrypted is up for grabs. That includes all those naked selfies that you shot after emptying the final bottle.

But what about sandboxing? That works for the app-specific internal storage that you can only get at if you root your phone. It doesn't work for the storage that you can see on your computer when you hook it up with your phone's USB cable. If you give an app access to your memory card, it gets access to all of your memory card, including your private collection of wildlife movies.

But that's changing.

Let's blame Google

Recent editions of Android lock down your memory card, because Google hates microSD. They'd rather have you store all your data in their cloud services so their advertisers can take a peek. Starting with Android 4.4, apps can only read the "public" parts of your SD card, and they can't write anything outside their tiny little sandboxed piece of storage space.

That's good for privacy reaspons, and bad for other reasons.

The good news is that this could prevent future WhatsAppgates. The bad news is that it will break a lot of useful things too. Save your email attachments with your mail app and edit them with another app? Forget it. Delete a picture from an alternative gallery app like QuickPic? Forget it. Zap old Nandroid backups with ES File Explorer? Forget it. The sledgehammer approach to SD card security is a disaster for cross-app access to files and folders.

Now what?

Locking down your external storage is a bad idea. It breaks too much, and forces us to move our data to the cramped and expensive built-in storage, or send it to the cloud and burn up our data and battery for no good reason.

Keeping everything wide open is a bad idea, because I don't want Obama snooping around in my WhatsApps.

Solution? Fix the broken Android permission system so we can decide for ourselves what app can access what. The "external storage" permission should be split into two permissions: "access to folders created by my app" and "access to the rest of the memory card." Anything that's too sensitive for the second permission should be encrypted by the app that made it, and then the user should decide who gets the keys.

Until then, lets hope an Xposed module will fix what Android 4.4 broke.

Update: the Xposed module to fix external SD cards on KitKat is ready. It's called HandleExternalStorage. Grab your copy from the Xposed installer.

tweet this reddit digg this StumbleUpon digg this digg this

Sunday, 2 March 2014

Multi-network chat app imo commits suicide, Trillian is still alive



Remember back when you had to use a different app for each and every chat network? And then came apps like Trillian, Nimbuzz, fring, imo, etc. One app to talk to all your friends, even if they were scattered over different chat networks.

But multi-network chat apps are like lemmings. They bundle different chat networks, then they build their own, then they cut the other networks out, and then they die.

Nimbuzz dropped almost all third-party networks, and fring and eBuddy thought it was time to plug their own networks by yanking all the other chat networks out of their apps. Does anyone know if fring and Nimbuzz and eBuddy still exist?

And now imo decided to dig a grave for itself and jump right into it. There was a time back when imo connected to no less than 12 different networks, but I just received this farewell note from them:

Date: March 2, 2014
From: imo.im
Subject: imo discontinuing support for all third-party messaging networks
To: android underground

On March 3, 2014, we will start discontinuing support for all third-party instant messaging networks. We know change isn't always easy, but we hope our users will trust that this will make imo an even better service. You will be able to download your chat history on o.imo.im from third-party networks until March 7, 2014.

Yep, you read that right. I got a mail from imo late in the evening on March 2 telling me that the one and only reason why I use imo will be axed the next day. And I get less than a week to download a copy of my chat history. Guess what? When I tried to download my chats imo gave me an empty file!

First they rake in customers using Facebook, Google Talk, MSN/Windows Live/whatever M$ calls it now, VK, etc. as bait, then they spit out an app update that forces all users to make an imo chat account, and then they make that forced chat account the only network left in the app...

Bye imo.

They must be popping open the champagne at Trillian HQ now that their main competitor decided to kill itself.

Trillian
IM+

tweet this reddit digg this StumbleUpon digg this digg this