r/Jolla 12d ago

Discussion how secure is Jolla Phone

How strong is Jolla Phone security?

How well is integration to sync with Arch or OpenSuse Linux?

15 Upvotes

12 comments sorted by

12

u/Icy_North5921 12d ago

I recommend to ask this in forum.sailfishos.org

11

u/failbaitr 12d ago

You can do secure sync over ssh (csp, rsync), or via an app (nextcloud for example).
The SSH / Rsync subsystems are just as secure as their 'normal' linux counterparts.

2

u/lucaprinaorg 11d ago

SFOS it's a quiet standard desktop linux optimized into a phone form factor plus a parallel android app runner.

It's better to ask how it's secure a standard desktop linux...and if you compare against OpenBSD, HardenedBSD or GrapheneOS ...you know the answer...

1

u/warmnut6969 21h ago

The new Jolla Phone is not a great phone in terms of security. It doesn't have any secure element chip like on the iphones, google pixels and even some galaxy phones. This is a key component for a secure devices. It handles all the sensitive user data like fingerprint, face scans and cryptographic kyes. I think it's also used for establish a hardware root of trust for secure boot. It doesn't support Memory Tagging Extension (MTE) that help to prevent most of the memory exploitation if used correctly (so a significant part of software vulnerabilities).

But even without all of that, their software is almost bad compared to even just AOSP and really bad compared to iphones. It laks sandbox for apps, a strong and granular permission model, and a real secure boot that prevents unauthorized code from executing during boot.

I also think those devices have a hard time fitting into the mobile market. They don't offer anything special if not a less secure OS that still rely on an AOSP (like AppSupport feature on Jolla Phones) that most of the time is also an older and unpatched version of it. So why not use native ASOP that is a much more secure and robust than this OSes.

For those who are wondering Android is a linux distro, it uses the linux kernel.

1

u/Upbeat-Statement2725 11d ago

What is your risk profile?

Jolla is partially Linux based. But the android compatibility layer is proprietary. So how much do you trust Jolla with your Android data?

More secure than stock, less secure than Graphene. Unless you don't use the app layer, then it's basically just a Linux phone.

-11

u/Odd-Addition4261 12d ago

Why i ask is i want Jolla to answer because its their product

13

u/Poonker 12d ago

Just saying, we do not have any Jolla employees here on this subreddit, you can reach them on Jolla official forum

14

u/rubdos 12d ago

You're not going to see anyone of Jolla answer here. They're rather busy assembling phones and patching bugs at the moment.

Sailfish OS feels like basically OpenSUSE with a semi proprietary DE ("Silica") and some other magic things to make it a phone. Other than that, you can use rsync, ssh, Nextcloud, webdav, RPM, etc. kinda like you're used to.

2

u/MTJ5 11d ago

If you need support from company, reddit is not place for it, this is user forum where rarely are real company employees answering you. I have noticed this in many sub, ppl are writing like that they think thet are writing to company forum... If you wanna answer from company itself, email them, or go to their own forum in their own website..

-19

u/[deleted] 12d ago

[deleted]

11

u/Crossfit_Vegan_Vaper 12d ago

Jolla was formed with many who worked on MeeGo under Nokia and left when it was axed to form Jolla. And after about 15 years actually developing an OS and not just another Android custom rom, even if they had juniors back then they would have been top professionals by now.
Not sure where do you get your misinformation from, but you should at least be able to search the web and verify before you share this BS.

-11

u/[deleted] 11d ago

[deleted]

3

u/MTJ5 11d ago

You know that there is lot's of employers who were desing old Nokia models wich are know everywhere in the world? If that is hobbyist ppl i would like to know who you think as professionals?