How To Lock Unlocked Bootloader

0 views
Skip to first unread message

Klaudia Aricas

unread,
Aug 3, 2024, 5:20:46 PM8/3/24
to backtenstitu

I installed /e/ on my Pixel 3a and relocked the bootloader after installation. Unfortunately, it wiped out the OS and I had to reinstall it and leave the bootloader unlocked lol. But, it would be pretty cool if they could add relocking the bootloader to the phones that are capable.

I locked the boot loader on my FP3+ after manually installing /e/OS. It is perfectly working !
My guess is : it depends on your device. For the Fairphone, locking the boot loader is even included in the install instructions.

Android is carefully built and secured to do all the consumer facing jobs which Google can say are secure enough for a bank or any secure organisation to be able to assume the person typing on the keyboard is their customer without a doubt.

One reason the answer is not sounding quite straight is that different manufacturers implement the Android security features slightly differently. When you ask the OP question of one particular device you can get a more well defined answer!

This article was co-authored by wikiHow staff writer, Travis Boylls. Travis Boylls is a Technology Writer and Editor for wikiHow. Travis has experience writing technology-related articles, providing software customer service, and in graphic design. He specializes in Windows, macOS, Android, iOS, and Linux platforms. He studied graphic design at Pikes Peak Community College.

This article has been fact-checked, ensuring the accuracy of any cited facts and confirming the authority of its sources.

This article has been viewed 232,891 times.

Learn more...

This wikiHow teaches you how to use Android Debug Bridge (ADB) to lock the bootloader on your Android device. Warning: This will likely format your device. Please backup first! You should also be aware that not every Android device has a lockable or unlockable bootloader.

can you do this whilst keeping the Sailfish operating system? Getting rid of the boot unlock message at start up.
I have read elsewhere in the forum that it cannot be done. But on YouTube there is a video of doing it.

So after running IodOS for a while I wanted to return to the stock ROM.
I Installed it per official install script, so far so good.
Now I wanted to relock the bootloader and read about the bricked phones after relocking.
I prevented (manually) the phone from rebooting after flashing so fastboot flashing get_unlock_ability returned 1.
I proceeded with fastboot flashing lock_critical and it locked the critical partitions.
Now fastboot flashing get_unlock_ability returns 0 and the bootloader is still unlocked.

I see here that rooting the phone and manually changing the toggle of OEM unlocking could be a possibility to, at least, unlock the ciritcal partitions again. But I would rather not go down that route if there are more convenient options available. However I have found none.

I guess because the bootloader is still unlocked I need to sideload it? Do you know if that is possible with the critical partitions locked?
And after the OTA is installed I should be able to lock my bootloader again without risk of bricking, right?

As Iode is not that fast in providing security patches I assume the security patch level you had is not higher, latest FPOS is on, so overall probably quite safw to not brick, however no one can ever give you a 100% guarantee

My advice, ask in the iodOS channels what security patch level they ship in 4.10 for the FP5 and compare it to the patch level shown in the FPOS release notes for the latest factory images available, which is the latest release anyway at the moment.

i do not want tot complain too much, one needs to be careful. but this phenomenon would be totally avoidable imho by a better warning on the page - maybe fairphone team can improve this? even the official android documentation (did read it later, after the incident) explains it better.

You can lock the bootloader with the phone in Fastboot mode, the manual install guide has this after flashing the OS, with either fastboot flashing lock or fastboot oem lock, depending on the version of the fastboot command you use on your computer.

The user data is encrypted by default. Once you set up a screen lock, this will serve as the necessary decryption method on the phone. Without knowing it, nobody will have access to your data when the screen is locked.
As far as I know, simple loss or theft of the phone with the screen locked will not expose your data, as only a factory reset via recovery mode would make the phone usable again, with your data then safely gone.
A remaining risk is somebody targeting you specifically. They could take your phone unnoticed by you, boot something custom to install some malware, return the phone still unnoticed by you, and then just wait for you to unlock it to either grab your decryption method and/or do whatever with your data afterwards. You have to assess that risk for yourself depending on your circumstances.

I used Chrome/Brave/Chromium on PopOS to flash my 6a. Unlocking the booloader wasn't a problem, obtaining factory images and flashing factory images were also no problem. But looking the bootloader doesn't work, it says:

The description of steps you followed is unclear. Using an unsupported browser or OS can result in random parts of the process working and random parts failing, which could brick your device. It is important to follow all directions carefully and to stop and ask for help at the first sign of trouble (don't press on hoping it will work out OK).

Regenbunt You haven't completed the installation process. You need to boot it back to fastboot mode and flash it completely. You've currently done an incomplete partial installation. You need to finish flashing and then lock the device. It sounds like you interrupted the flashing process by booting from fastboot mode or fastbootd mode. Don't use the menus until it fully finishes flashing, and if it stalls waiting for it to reboot that's not finished but rather your USB connection isn't working after reboot and you need to plug it in again to continue.

If you are sure, that the system is correctly flashed, than you need to get to bootloader interface and
just type "fastboot flashing lock".
Did you reconnect the cable, or describe what exactly did you do?

GrapheneOS
Good day!
I have a similar problem. The installation process of Graphene OS "hangs" and the bootloader does not lock.
About me: Windows 10 and Pixel 7a
There may be some additional settings to complete the installation successfully.
Thanks in advance!

Thank you for responding!
Unfortunately no! Is it fundamentally important?
But did zagruzka download the release?! And the computer "sees" the phone.
"Hanged" before blocking...
Is there anything I can do besides buy the original cord?

Vadimov You don't necessarily need the original cable, that one is just known to be high quality enough to support the installation process. Also the port you are connecting to may be at fault here too so go ahead and try out a few different cables/ports. Remember you will need to redo the flashing since it didn't complete successfully.

spring-onion
Thanks for the question!
Yes, I have already made more than ten attempts to reach the blocking point. Windows update, Android drivers, Webloader settings and everything else I found in manual and forums... But to no avail.
:( Already started collecting information on how to restore standard Android...

Mobile phone makers always lock their device's bootloader - that is, they prevent you from getting root access to your device, or uninstalling the default operating system and installing something else. There are ways to unlock the bootloader, but you have to jump through hoops to get it done (difficulty varies by brand, up to being impossible).

Meanwhile, the bootloader of a PC always come unlocked. You can insert a USB stick into a brand new device (no extra steps required) and install whatever you want. I do not own Mac devices so I may be wrong, but I heard that Mac bootloaders aren't locked either; that's why Asahi Linux is possible.

It makes every sense for PC makers (and Mac if I'm correct?) to lock the bootloader just as phone makers do, i.e., to control what softwares could be run on their devices thus maintain market share. Why don't they? It makes even less sense when many PC brands also make phones, but their PC comes with the bootloader unlocked while the phone is locked. Why is there this disparity?

When using devices which needs to be accredited to security standards, due to the sensitivity of the data being processed, there are guidance documents about how to apply device security (aka locking down the device). As well as the Secure Boot in the other answer, you may need to also consider TPM and DMA protection. E.g. the UK NCSC Device Security Guidance - Choosing devices includes:

Devices that are Modern Standby certified must meet all the requirements for UEFI secure boot and ship with it enabled. They should not have ports that allow DMA access and will have TPM 2.0 or later.

A TPM is a separate cryptographic co-processor that provides hardware-backed security features. These significantly improve the physical security of the device, and are required for the use of data at rest encryption in its most secure configuration. Devices that include a TPM 2.0 should be preferred where possible.

Since some device lockdown is operating system dependent, e.g. to support data at rest encryption Bitlocker is used for Windows .vs. UKS/dm-crypt disk encryption for Ubuntu, can understand why the PC manufacturer supplies unlocked devices.

There are many different levels of "why". From a practical perspective, your phone is in your pocket or purse and is unlikely to acquire any peripherals. In other words, it has poor physical security and won't need to power anything new on boot. Since every decision about security is also a decision about user convenience, tight security on the phone's boot loader makes a lot of sense.

c80f0f1006
Reply all
Reply to author
Forward
0 new messages