We have moved to a new Sailfish OS Forum. Please start new discussions there.
539

optional encryption of the device

Tracked by Jolla (In progress)

asked 2013-12-26 01:26:45 +0300

ortylp gravatar image

updated 2015-05-03 14:50:13 +0300

chemist gravatar image

Option for encryption of $HOME and Android directories containing user data is needed.

Use case: I do not want to worry about my data stored on the device (including various access tokens and keys) in case I loose the phone or it gets stolen.

edit retag flag offensive close delete

Comments

see also keychain linked to TOH & link all/previous changes to TOH

AL13N ( 2013-12-26 01:45:17 +0300 )edit
6

This should be fairly easy, as Linux already has all these LUKS/dmcrypt and eCryptFS stuff done. It might however need more CPU and thus consume battery. Maybe better put it as an option users can choose it they want to.

Please add tag 'securiity'

otto ( 2013-12-26 23:34:48 +0300 )edit
25

Besides home directory ecryption, also include option to encrypt SD card contents. That would be something that not even Android supports yet. And please use some standard Linux crypto so that the SD card can be mounted and opened without the original phone.

otto ( 2013-12-26 23:36:42 +0300 )edit
3

@otto this isn't as easy as one might think, because there's a lot of catch 22's here... order of services becomes important, etc... in theory all elements are available, but i can guarantee that alot of time will be spent in order to combine it into "1 feature"

AL13N ( 2013-12-26 23:38:28 +0300 )edit
13

Looking at the locked bootloader shitstorm today, we need encryption ASAP to allow the boot loader opened again: vote, vote, vote!

We must not loose any more developers!

ortylp ( 2013-12-28 13:25:13 +0300 )edit

14 Answers

Sort by » oldest newest most voted
14

answered 2014-02-08 18:29:58 +0300

Rolfa gravatar image

As an alternative, I suggest porting TrueCrypt to the Jolla phone (TrueCrypt runs very well on my N900).

edit flag offensive delete publish link more

Comments

3

Truecrypt is IMHO not a good fit here as it creates containers with a fixed size. Additionally there may be license issues as the Truecrypt license allows to view the source code but prohibits changing it.

schmittlauch ( 2014-03-16 20:29:20 +0300 )edit
9

"WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues" see: http://www.truecrypt.org/

utkiek ( 2014-05-29 18:13:01 +0300 )edit
2

@utkiek "...as any written software on the planet" :-)

simosagi ( 2014-06-07 10:53:12 +0300 )edit
2

@schmittlauch@utkiek TrueCrypt should work out as intended, audit came out clean. And there are optional forks, like VeraCrypt being actively developed - it supports TrueCrypt-containers too. While dm-crypt with luks might be the best option, having support for encrypted containers made with True/VeraCrypt would be really nice to have.

tuotantoarvio ( 2015-04-23 02:12:17 +0300 )edit
2

why use a non-free unsupported software, when there is a free and supported one (dm_crypt/luks) in linux?

fuckup23 ( 2015-10-28 21:14:31 +0300 )edit
41

answered 2014-01-12 18:15:14 +0300

rainisto gravatar image

Thanks for the input, we will look how to imprive the situation. Most likely some future kernel will have ecryptfs support added builtin. In a meanwhile you should enable devicelock code, as that will protect most of the use cases (not sd-card, and not people with access to hardware chip readers) against theft.

edit flag offensive delete publish link more

Comments

3

Any information if this full device encryption available on next (March) update?

jaekkay ( 2014-03-07 11:02:54 +0300 )edit

modprobe ecryptfs works. So people with developer mode can play with CLI.

rainisto ( 2014-03-17 12:51:05 +0300 )edit
5

Also add the ability of precting the sd card with a password in a future update please. :)

Alex ( 2014-04-18 16:53:02 +0300 )edit

any news on this? How high (or low) on the priority list is this?

velimir ( 2014-11-07 14:44:31 +0300 )edit
2

Is the full device encryption feature part of Sailfish OS 2?

bawaji ( 2014-11-20 07:46:20 +0300 )edit
9

answered 2014-01-08 14:30:43 +0300

chemist gravatar image

updated 2014-01-16 02:25:08 +0300

I know from @Aard that this is WIP/OnToDoList. This will take a while, crypt modules will get to the kernel soon but only for testing purpose for the mean time.

edit flag offensive delete publish link more

Comments

2

just repeating my comment from 26th Dec... WTF?

ortylp ( 2014-01-15 22:45:35 +0300 )edit

@ortylp Sry did not read the comments and this is a valid answer and not a comment! I talked to aard myself.

chemist ( 2014-01-16 02:23:54 +0300 )edit
49

answered 2013-12-26 01:34:02 +0300

Kondou gravatar image

I did spot a "jolla-devicelock-plugin-encpartition" package when rumaging through repositories, so it looks like jolla is working on something alike.

edit flag offensive delete publish link more

Comments

8

yes, I got some unofficial confirmation on IRC, but it has low priority at the moment, so vote it up

ortylp ( 2013-12-26 01:41:00 +0300 )edit
Login/Signup to Answer

Question tools

Follow
87 followers

Stats

Asked: 2013-12-26 01:26:45 +0300

Seen: 13,161 times

Last updated: Aug 18 '16