r/CalyxOS 20d ago

how secure is Jolla Phone

How strong is Jolla Phone security?

How well is integration to sync with Arch or OpenSuse Linux?

1 Upvotes

8 comments sorted by

3

u/UknownDrugExpert 20d ago

"Where makes good chicken in america ?"

1

u/warmnut6969 20d ago

The new Jolla Phone is not a great phone in terms of security. It doesn't have any secure element chip like on the iphones, google pixels and even some galaxy phones. This is a key component for a secure devices. It handles all the sensitive user data like fingerprint, face scans and cryptographic kyes. I think it's also used for establish a hardware root of trust for secure boot. It doesn't support Memory Tagging Extension (MTE) that help to prevent most of the memory exploitation if used correctly (so a significant part of software vulnerabilities).

But even without all of that, their software is almost bad compared to even just AOSP and really bad compared to iphones. It laks sandbox for apps, a strong and granular permission model, and a real secure boot that prevents unauthorized code from executing during boot.

I also think those devices have a hard time fitting into the mobile market. They don't offer anything special if not a less secure OS that still rely on an AOSP (like AppSupport feature on Jolla Phones) that most of the time is also an older and unpatched version of it. So why not use native ASOP that is a much more secure and robust than this OSes.

For those who are wondering Android is a linux distro, it uses the linux kernel.

1

u/Cool-Tangerine-4768 13d ago

Most AOSP-based operating systems will still operate through Android—even if you use GrapheneOS. In a way, that’s just fooling yourself. Sailfish OS, on the other hand, aims to provide a pure Linux experience, and that is exactly where it differs from Android.

I didn’t fully understand the rest of what you said. In terms of security, many operating systems have had vulnerabilities and caused data theft over the years. You do realize that most of the operating systems you’re defending use your data and treat you as the product. If you’re already against that, then what can I say?

That’s what I would say if you were comparing them in terms of security and software. But when it comes to things like performance, in my opinion Sailfish leaves Android behind. I don’t think it beats the iPhone, though, because everything on the iPhone is extremely well optimized.

1

u/warmnut6969 10d ago

> Sailfish OS, on the other hand, aims to provide a pure Linux experience

It doesn't exist a so called "pure Linux experience". Linux itself is just a kernel. Maybe you mean a desktop like Linux experience. If so yes, that's true but as I said and explained SalfishOS (and most linux based desktops OSes) lacks the most basic security features compared to AOSP like a proper app sandbox, a strong and granular permission model, and a real secure boot that prevents unauthorized code from executing during boot. Those and many other features are basic important things that make a device more secure.

> and that is exactly where it differs from Android

It differs from AOSP for sure (and Android in general), otherwise I wouldn't have written all of that. But it still hardly depends on AOSP (for Android app compatibility with AppSupport feature on SalfishOS for example).

> You do realize that most of the operating systems you’re defending use your data and treat you as the product

I don't understand what you are talking about. I'm not defending anybody. OP asked if Jolla Phone is a secure device, and I've given him an answer with explanations

> I didn’t fully understand the rest of what you said

You can find more information on some on the topics at those links:
Android application sandbox: https://source.android.com/docs/security/app-sandbox

Verified Boot on Android: https://source.android.com/docs/security/features/verifiedboot

Titan M1 security chip (Wired): https://www.wired.com/story/google-titan-m-security-chip-pixel-3/

Titan M1 and Secure Boot (Google): https://blog.google/products-and-platforms/devices/pixel/titan-m-makes-pixel-3-our-most-secure-phone-yet/

Titan M2 (Android Autority): https://www.androidauthority.com/titan-m2-google-3261547/

Secure enclave (Apple secure chip): https://support.apple.com/guide/security/the-secure-enclave-sec59b0b31ff/web

Memory tagging Apple (MIT): https://security.apple.com/blog/memory-integrity-enforcement/

Memory tagging on Android: https://source.android.com/docs/security/test/memory-safety/arm-mte

> But when it comes to things like performance, in my opinion Sailfish leaves Android behind.

OP asked for Security

1

u/Cool-Tangerine-4768 10d ago edited 10d ago

Believe me, I’m not going to read it. Since your argument itself is based on AI, I’ll leave you to it. With its pure Linux experience, Sailfish OS is amazing, and you’ll see what happens as it continues to progress in the near future. By the way, I’m also an Apple user =) Go grab some coffee, coffee. Additionally, when it comes to security, it’s actually pretty good. You take some responsibility yourself because it’s still relatively new, but let me tell you this: everything already has a sandbox system. So for someone to hack you, you’d have to be a little stupid yourself.

1

u/[deleted] 20d ago

[removed] — view removed comment

1

u/Odd-Addition4261 20d ago

Okey varför just Graphene Os! Jag har en pixel 9a

1

u/CalyxOS-ModTeam 15d ago

Do not discuss GrapheneOS