Upcoming Jolla Phone bootloader locking and flashability

Bootloader locked or unlocked? Will it be user flashable?

I have preordered but this really worries me. Jolla 1 had locked bootloader and required sending it to Jolla for a fee if the passcode is forgotten. That is unacceptable from longevity, repairability and openness standpoints. Hugh Jeffreys’ video on that: https://www.youtube.com/watch?v=HzCMKbhK-EY

3 Likes

As far as I remember the bootloader unlocking was patched later to the JP-1301. The video is produced after the support for the device was discontinued, so why would Jolla have to offer free services when they are not officially offered anymore?

Oh, so there was an official method to unlock it? Well, that’s better than nothing, how was it patched? With a software update and could you request an unlock code as long as device was in official support period? My point is that these decisions should be made so that devices aren’t permanently stuck in a locked bootloader when official support ends, so that they can still be made useful with things like PostmarketOS: Making sure you're not a bot!

Also, flashing with what?are you buying a sailfish phone to flash something else on it?

1 Like

Not while Sailfish on it is supported, but that won’t be forever, so after that i probably will be interested in flashing something else. And if a device is marketed with openness and longevity as selling points, it should BY DEFAULT remain usable and open even when official support ends. If opening the bootloader requires you to have requested the unlock code within official support period, that is a form of planned obsolescence. Then you will be out of luck if you buy the device after end of support period (and the previous owner never unlocked it), like Hugh Jeffreys did.

3 Likes

The device Hugh got is a device from 2013.
With Jolla supporting devices 7+ years, do you think that support would be an issue?
Most of the stuff you would want to run in the next decade either they will run just as good, or the hardware will be obsolete.

1 Like

What happened here is that the device was stolen, the thief couldn’t get in because he didn’t have the passcode (and didn’t have adequate tools to crack it) so he put it on eBay, then the guy on YouTube bought a stolen phone and complained he couldn’t get in because it had a password.

3 Likes

The hardware won’t be obsolete after 7 years, hardware-wise phones can last and perform well enough longer and longer (especially if spare batteries are available) but software (fragmentation is a problem in android and mobile Linux) and software locks (like locked bootloader) are the bottlenecks that keep the lifecycle short and repairing and buying used unviable.

2 Likes

Cool. What would you be flashing on your J2 assuming bootloader can unlock and it’s 2034?

2 Likes

They prepared images in order for people to flash their C2 at home.

Where are you getting the information that the phone was stolen? Are you assuming by default a stolen device whenever the passcode is not known? That can happen in so many other ways. It is not sustainable to leave perfectly working devices locked just because there is a chance they may be stolen.

1 Like

I’ll know in 2034 :slight_smile: Maybe PMOS if it’s good then and can be ported to J2. Maybe something else.

Yes, i just reflashed XA2 Plus and noticed Jolla C2 image in Sailfish X downloads :slight_smile:
Then i found this other (earlier?) thread about C2 flashing which was only possible because of a vulnerability in the device as i understand? However we should not have to hope for a vulnerability to be found in order to be able to flash. Flashing the Jolla C2

1 Like

They added extra option to the recovery menu to unlock/lock the boot loader.

JP-1301 was updated to user being able to unlock boot loader, as far as I know, Jolla C and JT-1501 didn’t even have their boot loaders locked (someone will shortly correct me, if I’m wrong) and Jolla C2 can be flashed by the users, so why are you so worried about the locked boot loader if you look at Jolla’s track record?

The code used to unlock the locked phone and/or boot loader was your phones security code, so you should know it unless you stole someones phone…

This is what I assume happened too.

1 Like

Of course, people can forget their passcode. They don’t tend to sell those devices, though.

Oh, that’s nice to know that the J1 Bootloader unlock code was the lockscreen code, not like on Xperia where you have to request from Sony, or Huawei who had a similar process but then completely stopped sending unlock codes… Will have to look into the J1/Jolla C situation. I may have a working J1 somewhere, don’t have C, just an Intex Aqua Fish with no working battery. Tablet probably not locked because it’s pretty much a generic X86 device hardware-wise. I think there is a flasher for the tablet, but no idea if “leaked“ or officially released.

”The code used to unlock the locked phone and/or boot loader was your phones security code, so you should know it unless you stole someones phone…”

I am in very strong disagreement with this thinking.

We on this forum are a bit of a niche demographic, but if you think about the average person, how many people do you know who always remove their passcodes and properly reset their devices when they stop using them? In my experience people almost always just leave old devices lying around somewhere, no time to go through contents, reset, and sell/give to someone else to use. Then after a year or two they may want to sell/use the device but don’t remember the passcode. Or maybe it was used by a child who changed the passcode. Or maybe the screen broke so they can’t reset it but they want to still sell it to someone who can fix it, who will after screen replacement see that it’s locked and useless. If we think about this on a bigger scale, how difficult does it make running a repair business when you always have to fight with different software locks?

In my opinion the current implementation of Android FRP and Apple Icloud locking are horribly unsustainable anti-consumer practises that Jolla should not copy (and i don’t think they will, just to clarify my point). These deeply unhealthy industry standards are sold to us as “security“ features, but actually they just move control of the device away from the “owner“ and to Google/Apple.

In my opinion, you should always be able to reset the device. Of course, when resetting it should erase itself and reset encryption keys so that previous data is gone.

What makes you think they don’t sell those devices? Of course they do, average person will just think that maybe someone can “fix“ it, and it’s their device, they have the right to sell it for someone to try to reset, and it’s the responsible thing to do rather than throwing it away. While setting up the phone and entering the lock code, average person won’t understand that this code will be needed if the phone is to be reset at some point.

1 Like

None, but everyone of those who have sold their old device has done so before handing over the device, and those who don’t have the skills to do it themselves, have asked for someone else to do it.

Every single person I have talked about lock codes, tell they use something really easy to remember, like the same digit code they have used on everything since the 90s (not a good practice, but at least you don’t forget it), so the chance of them completely forgetting it is the same as a chance for a brain damage.

Sounds like in this case you still remember the code and you can easily reset the lock code or factory reset the whole phone through recovery menu? Or if you can’t follow Jolla’s instructions, just tell the code to the next buyer?

In my experience it’s very common that people forget lock codes, especially in cases when a child has changed it. And i’m talking about cases where i 100% know they haven’t stolen the device.

“Sounds like in this case you still remember the code and you can easily reset the lock code or factory reset the whole phone through recovery menu? Or if you can’t follow Jolla’s instructions, just tell the code to the next buyer?”

You are correct in that if everyone always thought of these things when selling the device, and never forgot their passcodes, in that perfect world requiring passcode for resetting/flashing/unlocking would only help prevent theft and we could always presume locked devices stolen.

However, in the real world, people don’t always remember their passcodes and don’t do transfers of ownership (selling the device) correctly, so we can’t presume locked devices stolen by default and doing so is an unsustainable practice. Of course some locked devices are stolen, but in my opinion it’s worse to software-lock perfectly working non-stolen devices than it is to allow some stolen devices to be reused (after being reset).

In Hugh Jeffreys’ repair videos, he has to constantly go hunting for the passcodes with creative methods, usually he reaches the owner and they tell the code. People do sell their phones without even checking what state they are in, and sometimes it turns out that they tossed the phone in a dumpster, someone dumpster-dived it and sold. Way more complicated than “it is stolen“. I repair phones too and have the same experience, software locks are a nightmare and especially an “open device” shouldn’t lock resetting behind a passcode.

Oh and i am talking about this as an industry-wide problem, not only specifically Jolla 1. This problem is worst with cheap (80€) Androids that are bought for children, if that kind of cheap phone gets locked and passcode forgotten, people often just throw it away and get a new one, even if the device could be recovered through Google account, because people’s time is so expensive compared to a new device. This same problem is relevant with more expensive devices too at some point later, when their value in money falls but they are still useful. This is why i am advocating for an easily accessible reset functionality that doesn’t ask passcodes, just erases and resets the phone, even if it means no theft-prevention.

Oh and sorry to everyone who doesn’t care about this discussion for derailing the thread :slightly_smiling_face:

1 Like

It’s not really theft prevention, it’s at best a deterrent. And even that only works if a thief assumes the phone is locked and can’t be unlocked/flashed easily.
If 90% of the phones in the area can be unlocked without much effort or simply salvaged for parts, the deterrence effect largely evaporates, even if your individual phone is very secure. They won’t give it back to you after discovering it’s useless.

1 Like