Reply
Thread Tools
Guest | Posts: n/a | Thanked: 0 times | Joined on
#111
Originally Posted by djselbeck View Post
I would like to not flash my bootloader. This is the riskiest operation I could imagine.

I'm at the point where my loyalty for your platform comes to an end.

If you write openess on your flags you should deliver it.

I don't see why this bootloader update today was necessary.

Anyone who depends on data security for this BETA PLATFORM at the moment is mentally not clear.

My jolla goes in to the bay on sunday. If someone wants to make a good offer go ahead and PM me
+1

10 freakin locked chars
 

The Following 3 Users Say Thank You to For This Useful Post:
Posts: 1,067 | Thanked: 2,383 times | Joined on Jan 2012 @ Finland
#112
One of the rationales was that you have setup devicelock code with immediate lock, have company emails setup in your device, your company policy forces lockcode to protect company secrets.

"oem boot" allowed you to copy whole root partition without asking the lockcode. With this change copying root partition is only allowed after you have entered the devicelock code.

So hypotically if someone has option to follow mail for exchange security policy vs remove whole mfe support in future updates, which one has valid businesscase? Or if hypotically you can skip devicelock code query without any effort, would you trust your device any more?

You can say that you dont use mfe and dont care if people can steal your data easily, thats why there is still option to flash old bootloader back to device (or just make custom recovery image). But personally I use devicelock code on my device and have updated to latest bootloader and recovery partition (as I can always use recovery partition to get my device to match my latest rdiff backup that I have in a cloud).
__________________
IRC: jonni@freenode
Sailfish: ¤ Qt5 SailfishTouchExample ¤ Qt5 MultiPointTouchArea Example ¤ ipaddress ¤ stoken ¤ Sailbox (Dropbox client) ¤
Harmattan: ¤ Presence VNC for Harmattan ¤ Live-F1 ¤ BTinput-terminal ¤ BabyLock ¤ BabyLock Trial ¤ QML TextTV ¤
Disclaimer: all my posts in this forum are personal trolling and I never post in any official capacity on behalf of any company.

Last edited by rainisto; 2013-12-27 at 22:00.
 

The Following 11 Users Say Thank You to rainisto For This Useful Post:
Posts: 113 | Thanked: 303 times | Joined on Dec 2013 @ Germany
#113
As an owner of an Xperia Z from Sony I know how it could be done so don't give me wrong facts.

fastboot oem unlock 0xKEY would've been the perfect way. This would've given the geeks around here the possibility to do what they want. Now we can't do this.

If you were unable to implement this in time, you should provide the bootloader image yourself. Also a way you've not taken.

From an open company I expect this.

I'm done. I'm writing developer care right now to pull my app from your store and sell my device.

Good luck satisfying your MFE customers
 

The Following 7 Users Say Thank You to djselbeck For This Useful Post:
Guest | Posts: n/a | Thanked: 0 times | Joined on
#114
Originally Posted by rainisto View Post
One of the rationales was that you have setup devicelock code with immediate lock, have company emails setup in your device, your company policy forces lockcode to protect company secrets.

"oem boot" allowed you to copy whole root partition without asking the lockcode. With this change copying root partition is only allowed after you have entered the devicelock code.

So hypotically if someone has option to follow mail for exchange security policy vs remove whole mfe support in future updates, which one has valid businesscase? Or if hypotically you can skip devicelock code query without any effort, would you trust your device any more?

You can say that you dont use mfe and dont care if people can steal your data easily, thats why there is still option to flash old bootloader back to device (or just make custom recovery image). But personally I use devicelock code on my device and have updated to latest bootloader and revocery partition.
Then I guess Jolla made a decision when it comes to openess and a development friendly community device versus a closed, secure device.
Goodbye Jolla from me
 

The Following 5 Users Say Thank You to For This Useful Post:
Posts: 1,067 | Thanked: 2,383 times | Joined on Jan 2012 @ Finland
#115
Originally Posted by djselbeck View Post
As an owner of an Xperia Z from Sony I know how it could be done so don't give me wrong facts.

fastboot oem unlock 0xKEY would've been the perfect way. This would've given the geeks around here the possibility to do what they want. Now we can't do this.

If you were unable to implement this in time, you should provide the bootloader image yourself. Also a way you've not taken.

From an open company I expect this.

I'm done. I'm writing developer care right now to pull my app from your store and sell my device.

Good luck satisfying your MFE customers
Like I said we are working on possibility of allowing "fastboot oem unlock 0xKEY" but updates take time to implement. I did not say that you never will be able unlock your fastboot. And this change was not done because of MFE, you should have read 'hypotically' part.
__________________
IRC: jonni@freenode
Sailfish: ¤ Qt5 SailfishTouchExample ¤ Qt5 MultiPointTouchArea Example ¤ ipaddress ¤ stoken ¤ Sailbox (Dropbox client) ¤
Harmattan: ¤ Presence VNC for Harmattan ¤ Live-F1 ¤ BTinput-terminal ¤ BabyLock ¤ BabyLock Trial ¤ QML TextTV ¤
Disclaimer: all my posts in this forum are personal trolling and I never post in any official capacity on behalf of any company.
 

The Following 9 Users Say Thank You to rainisto For This Useful Post:
Posts: 25 | Thanked: 99 times | Joined on Apr 2013
#116
This is disappointing.

On the one hand Jolla encourages hacking of the device to developers (which are probably the sole user base at the moment?). On the other hand they now want to secure the device for the normal user and take away functionality we saw as a feature. I understand the security concerns here. However, without any way to easily reset the device by flashing an image, this makes me more cautious with any experiments…

At least it seems like the old mmcblk0p17 seems to be the same for everyone – the checksums published earlier in this thread matched.
 

The Following 4 Users Say Thank You to Raim For This Useful Post:
Posts: 113 | Thanked: 303 times | Joined on Dec 2013 @ Germany
#117
Maybe updates take their time. But I'm not DDing my bootloader. No way.

Also I don't want to wait until the device is worthless on ebay. So goodbye jolla community for now.

SMPC will be pulled from harbour, development stopped.
MTBtracker development stopped.

This will be my last post. Goodbye everyone, this has been a great experience the last few weeks. Also a much better community than XDA for example.
 

The Following User Says Thank You to djselbeck For This Useful Post:
Posts: 1,067 | Thanked: 2,383 times | Joined on Jan 2012 @ Finland
#118
Originally Posted by Raim View Post
This is disappointing.

On the one hand Jolla encourages hacking of the device to developers (which are probably the sole user base at the moment?). On the other hand they now want to secure the device for the normal user and take away functionality we saw as a feature. I understand the security concerns here. However, without any way to easily reset the device by flashing an image, this makes me more cautious with any experiments…

At least it seems like the old mmcblk0p17 seems to be the same for everyone – the checksums published earlier in this thread matched.
This update also included recovery image (power+volumedown), which allows to factory reset your btrfs back out of box state. Which should make your experiments a bit safer. As you can use recovery image to get into bootable state, and you can use root-shell to recover for example your latest rdiff-backup to your device.
__________________
IRC: jonni@freenode
Sailfish: ¤ Qt5 SailfishTouchExample ¤ Qt5 MultiPointTouchArea Example ¤ ipaddress ¤ stoken ¤ Sailbox (Dropbox client) ¤
Harmattan: ¤ Presence VNC for Harmattan ¤ Live-F1 ¤ BTinput-terminal ¤ BabyLock ¤ BabyLock Trial ¤ QML TextTV ¤
Disclaimer: all my posts in this forum are personal trolling and I never post in any official capacity on behalf of any company.
 

The Following 6 Users Say Thank You to rainisto For This Useful Post:
Guest | Posts: n/a | Thanked: 0 times | Joined on
#119
Originally Posted by djselbeck View Post
Maybe updates take their time. But I'm not DDing my bootloader. No way.

Also I don't want to wait until the device is worthless on ebay. So goodbye jolla community for now.

SMPC will be pulled from harbour, development stopped.
MTBtracker development stopped.

This will be my last post. Goodbye everyone, this has been a great experience the last few weeks. Also a much better community than XDA for example.
While I will stop my Jolla adventure. I will not stop on this community.
I will, hopefully, achieve my own goals with N9xx, or neo900 or ... But here, in this community is plenty of talents to support. Just wish Jolla would have acknowledged that
 

The Following 4 Users Say Thank You to For This Useful Post:
Guest | Posts: n/a | Thanked: 0 times | Joined on
#120
Originally Posted by rainisto View Post
This update also included recovery image (power+volumedown), which allows to factory reset your btrfs back out of box state. Which should make your experiments a bit safer. As you can use recovery image to get into bootable state, and you can use root-shell to recover for example your latest rdiff-backup to your device.
You clearly dont understand the needs that some developers have. This is fine, but not for me.
 

The Following 3 Users Say Thank You to For This Useful Post:
Reply


 
Forum Jump


All times are GMT. The time now is 10:19.