When you run an android phone with an unlocked bootloader one of your main security concerns has to be physical device security.

Even while your data is encrypted, on Android your OS is not and therefore someone with physical access to your device can trivially inject malware that runs with system permissions.

Same is true for the kernel of your notebook and desktop computer when it doesn't run "secureboot" or a comparable security measure.

#infosec #android #bootloader #secureboot

Follow

@sheogorath

Unfortunately, on some phones you can lock bootloader after flashing a custom ROM (Google) while on some you can't (OnePlus)

Β· Β· 1 Β· 0 Β· 0

@kravietz

I've been researching / documenting devices that support verified boot with alternative operating system. Also operating systems that implement this.

Its looking like #Oneplus & Google may be the only vendors to offer support on all their devices

hub.libranet.de/wiki/and-priv-

#android #AOSP #Pixel

@sheogorath

@nurinoas

@dazinism

OnePlus? I recently switched to OnePlus 6T (fajita) with LineageOS but when I tried to lock the bootloader I ended up with soft-bricked device. On the other hand this worked with Pixel 3a.

@sheogorath @nurinoas

@dazinism

Ah, reading your page I guess maybe it was because the ROM I used did *not* support it...

@sheogorath @nurinoas

@kravietz

Think you can possibly do it with most ROMs?

Although I've never tried and havent spent the time trying to understand all the implementation details as I'm unlikely to ever do this myself.

Think the link from the wiki to the details of the Oneplus 5/5t may be the most helpful for what you were trying?

@sheogorath @nurinoas

@dazinism All of them are extremely helpful and provide exactly the type of details I need! @sheogorath @nurinoas

Sign in to participate in the conversation
Mastodon πŸ” privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!