We have moved to a new Sailfish OS Forum. Please start new discussions there.
6

Is it safe to store sensitive information on internal storage? [answered]

asked 2015-10-17 13:34:34 +0300

Lojja gravatar image

updated 2015-10-17 13:35:26 +0300

Unfortunately right now Sailfish OS doesn't support any encryption of internal storage and external SD card. The only way to be safer is to store sensitive information on internal storage with phone PIN lock enabled. Because get the SD card from the phone and copy data from it is too easy for malicious man. So my question is how easy can malicious man get information from internal storage of locked with PIN phone? Is it possible without breaking hardware of the phone?

edit retag flag offensive reopen delete

The question has been closed for the following reason "the question is answered, an answer was accepted" by nthn
close date 2017-03-06 13:58:38.604928

Comments

1

@Lojja - I couldn't say for sure, how safe it is to store your sensitive data on internal storage, but you could give this a try; https://openrepos.net/sites/default/files/packages/500/truecrypt-7.1a-1.armv7hl.rpm - TrueCrypt is a software system for establishing and maintaining an on-the-fly-encrypted volume (data storage device).

This may not function correctly on SFOS 2.0 - if not, contact the developer directly - NielDK.

(Note* - this is CLI based, no UI).

Spam Hunter ( 2015-10-17 18:55:05 +0300 )edit

Thanks for comment and the link to the port of TrueCrypt! Hope in the future such functionality will be build into SFOS.

Lojja ( 2015-10-17 19:53:22 +0300 )edit
3

Don't want to play the bad guy but WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues - The development of TrueCrypt was ended in 5/2014(Source: http://truecrypt.sourceforge.net/ ).

For some weird reason SailfishOS contains the eCryptfs kernel module but not the userspace tools.

V10lator ( 2015-10-17 21:35:01 +0300 )edit

1 Answer

Sort by » oldest newest most voted
8

answered 2015-10-18 01:23:15 +0300

Philippe De Swert gravatar image

If you enable the DEVICE lock. So the lock code that is asked to unlock your phone and not the PIN code when you boot it, you should be reasonably safe. As the only way to get to your data at that point would have to go through exploiting some service that might be running on the phone over wlan/data network. Which most likely would expose your data anyway as you might have it available in decrypted form when the phone is running.

On the USB side no data will be exposed when the cable gets plugged in with a locked device. It will in that case show up as an empty mass-storage device to allow for charging, until you unlock manually.

Recovery mode and bootloader unlocking etc require the device lock code also.

And as already pointed out in the comments. There are some things on the phone already which you could use to set up some kind of encrypted storage on the phone if you can be bothered doing the work required.

In short your data may not be on the most secure/encrypted/anti-NSA device out there, but otoh there is no obvious easy way to get to it. So you should be relatively safe IF you enabled the device locking and don't store the sensitive data on the SD card ofc ;)

edit flag offensive delete publish link more

Comments

Thanks a lot for your detailed answer!

Lojja ( 2015-10-18 19:01:01 +0300 )edit

It would be perfect if it was possible to set a key to access to sd card, and this key was stored in memory device.

carmenfdezb ( 2015-10-25 19:57:52 +0300 )edit

Question tools

Follow
2 followers

Stats

Asked: 2015-10-17 13:34:34 +0300

Seen: 608 times

Last updated: Oct 18 '15