Securing / Hardening The PinePhone
#1
I'd love to know what people are doing as far as security tweaks for the pinephone. Not that I need anything like CalyxOS or Graphene type of phone, but I'd like to put a little VPN on it as it can only be used for a pocket linux. I don't have the skill set to really work on the phone like others, but maybe one day I will.
#2
I haven't done much, but I put some iptables rules on mine as a bare minimum.
#3
(11-24-2020, 06:59 PM)NobodyNew1 Wrote: I'd love to know what people are doing as far as security tweaks for the pinephone. Not that I need anything like CalyxOS or Graphene type of phone, but I'd like to put a little VPN on it as it can only be used for a pocket linux. I don't have the skill set to really work on the phone like others, but maybe one day I will.


You could take a look at Firejail, application sandboxing (in case of vulnerability prevents access outside program need).
On Mobian I have Firetools, Firejail configuration Wizard and it loads for easy configuration of programs you want to safely sandbox.

I use ssh to make Pinephone administration/commandline tasks from the computer quick/convenient. To make it more secure/inaccessible to outsiders I made my Pinephone ssh server Tor hidden service .onion access only https://forum.pine64.org/showthread.php?tid=11925
- RTP

"In the beginner's mind there are many possibilities, in the expert's mind there are few." -Shunryu Suzuki


[ Pinephone Original | Pinetab v1 / v2 Enjoyer ]


Linux Device Privacy / Security Playlist



#4
The Mobian wiki has a security page that covers most of the above and more. No mention of Wireguard on there yet - I suppose I should try it and see if it works.
https://wiki.mobian-project.org/doku.php?id=security
#5
@wibble Wireguard works perfectly out of the box. You can enable a systemd service using configuration files.
#6
The most important thing to me is to have full disk encryption. As of today IIRC only PostmarketOS includes it out of the box and Mobian using some scripting as well.
My two cents.

Enviado desde mi ONEPLUS A5010 mediante Tapatalk
#7
(11-26-2020, 02:19 PM)RTP Wrote:
(11-24-2020, 06:59 PM)NobodyNew1 Wrote: I'd love to know what people are doing as far as security tweaks for the pinephone. Not that I need anything like CalyxOS or Graphene type of phone, but I'd like to put a little VPN on it as it can only be used for a pocket linux. I don't have the skill set to really work on the phone like others, but maybe one day I will.


You could take a look at Firejail, application sandboxing (in case of vulnerability prevents access outside program need).
On Mobian I have Firetools, Firejail configuration Wizard and it loads for easy configuration of programs you want to safely sandbox.

I use ssh to make Pinephone administration/commandline tasks from the computer quick/convenient. To make it more secure/inaccessible to outsiders I made my Pinephone ssh server Tor hidden service .onion access only https://forum.pine64.org/showthread.php?tid=11925
That's amazing !! I'll look into all of that.
#8
Another good thing to do is set your ssh port to something nonstandard and only permit key-based logins. In /etc/ssh/sshd_config:

Code:
Port 12345
PasswordAuthentication no
PubkeyAuthentication yes


Possibly Related Threads…
Thread Author Replies Views Last Post
  Pinephone visibly losing power while plugged in Hiraghm 2 750 05-23-2025, 12:30 PM
Last Post: Kevin Kofler
  Pinephone Pro Neural Processing Unit biketool 0 724 03-26-2025, 11:01 AM
Last Post: biketool
  contact sales pinephone janjansen1312 2 1,106 03-17-2025, 07:29 PM
Last Post: tllim
  PinePhone Pro P. Siera 4 2,514 03-14-2025, 07:00 PM
Last Post: Kevin Kofler
  [Article] PR Test Bot for PinePhone (Avaota-A1 SBC / Apache NuttX RTOS) lupyuen 0 716 03-08-2025, 02:43 PM
Last Post: lupyuen
Star Selling my Pinephone Pro Explorer Edition zheyon 0 1,182 01-31-2025, 02:27 PM
Last Post: zheyon
  PinePhone earpiece too quiet Waffelo 3 1,506 01-01-2025, 09:41 PM
Last Post: Kevin Kofler
Question WhatsApp & Pinephone - What are the alternatives for collaborative comms? danimations 15 22,592 12-27-2024, 03:02 AM
Last Post: biketool
  eSIM on PinePhone just_a_q 9 8,013 12-25-2024, 04:16 AM
Last Post: zetabeta
  US Mobile, via T-Mobile, won't support Pinephone Pro - SOLVED, SIMPLY jovval 13 10,628 12-05-2024, 04:38 PM
Last Post: tllim

Forum Jump:


Users browsing this thread: 1 Guest(s)