How to Connect To Android via USB

I have used two approaches: one for using USB MTP (via sys‑usb) and one for accessing Android devices via FTP/SFTP over tethering.

Security Considerations:

  • When using USB MTP, disconnect unnecessary USB devices before connecting your phone, then restart sys‑usb afterward to ensure a clean state.
  • For FTP/SFTP, running the file access in a dedicated, isolated qube keeps any potential network-based risks away from your core systems.

Choosing Between Methods:

  • USB MTP: May offer faster speeds and direct file system access—but can be finicky in Qubes due to USB passthrough issues.
  • FTP/SFTP: Provides an alternative that uses the phone’s network interface; though speeds are typically lower (especially if tethering via 2.4 GHz), it benefits from the isolation of using a dedicated qube.

Method 1: Using USB MTP via sys‑usb

Overview:
The goal is to have your Android device (in MTP mode) work reliably through the sys‑usb qube. This method requires that your sys‑usb’s disposable VM (DVM) template has the proper MTP support packages installed.

IMPORTANT PREPARATION (for security):

  • Disconnect Extra USB Devices:
    To reduce potential conflicts and minimize the attack surface, disconnect any nonessential USB devices (e.g. wireless mice, extra peripherals) before connecting your Android device.
  • Restart sys‑usb After the Operation:
    Once you’ve finished transferring files, restart sys‑usb to revert any temporary USB assignments.

Step 1. Determine Your Template Type

  • Fedora‑based DVM Template?
    If sys‑usb’s DVM is based on Fedora (for example, a Fedora disposable template), then proceed with Fedora instructions.

  • Debian‑based DVM Template?
    If it’s based on Debian, use the Debian instructions.


Step 2. Install MTP Support Packages in the Template

For Fedora‑based Templates

Open a terminal in your Fedora template (or update it via dom0) and install:

sudo dnf install gvfs-mtp libmtp

Note: Fedora repositories do not provide a separate “mtp-tools” package. The combination above enables MTP support in file managers (such as Thunar, which is used in Qubes OS).

For Debian‑based Templates

Open a terminal in your Debian template and run:

sudo apt update
sudo apt install gvfs-backends mtp-tools

Note: In Debian, these packages add MTP support so that file managers can mount and browse your Android device.


Step 3. Restart the Template and sys‑usb

After installing the packages, shut down the template and restart sys‑usb so that the changes take effect:

qvm-shutdown sys-usb && qvm-start sys-usb

Step 4. Connect and Use Your Android Device

  1. On Your Android Device:

    • Enable USB file transfer (MTP).
    • Make sure the device is unlocked.
  2. Physically Connect the Device:

    • Plug it into your computer’s USB port.
    • (Remember: disconnect other USB devices first for safety.)
  3. Verify in sys‑usb:

    • Open a terminal or Thunar file manager in sys‑usb.
    • Run lsusb (or check Thunar’s Devices list) to ensure the Android device appears.
    • You should now be able to browse the phone’s storage via MTP.
  4. After You’re Done:

    • Restart sys‑usb to reset the USB state:
      qvm-shutdown sys-usb && qvm-start sys-usb
      

Method 2: Accessing the Android Device via FTP/SFTP Over Tethering

Overview:
If MTP remains unreliable or you prefer an alternative, you can run an FTP (or SFTP) server on your Android device. By enabling tethering (hotspot) on the phone, you can connect from a dedicated qube (not sys‑usb) and use Thunar to browse files over the network.


Step 1. Set Up an FTP/SFTP Server on the Android Device

  1. Install an FTP/SFTP Server App:
  2. Enable Tethering:
    • Activate the phone’s hotspot/tethering feature so that your computer can join its network.
  3. Configure the Server:
    • Follow the app’s instructions to start the server (note the IP address and port it uses).

Step 2. Prepare Your Dedicated Qube for Network File Access

Use a dedicated qube (separate from sys‑usb) that will access the phone via its hotspot.

For Fedora‑based Dedicated Qubes

Open a terminal in the Fedora template used by the dedicated qube and install:

sudo dnf install gvfs gvfs-ftp

Note: The “gvfs-ftp” package (or FTP backend integrated with gvfs) allows Thunar to access FTP URLs.

For Debian‑based Dedicated Qubes

Open a terminal in the Debian template for your dedicated qube and run:

sudo apt update
sudo apt install gvfs-backends

This package includes support for FTP/SFTP access in file managers.


Step 3. Connect to Your Android Device Over FTP/SFTP

  1. Join the Hotspot:
    • On the dedicated qube, connect to the Android phone’s hotspot.
  2. Access the FTP/SFTP Server:
    • Open Thunar.
    • In the location bar, enter the server address. For FTP it might be:
      ftp://<phone_ip>:<port>/
      
      For SFTP, use:
      sftp://<phone_ip>:<port>/
      
  3. Browse and Transfer Files:
    • Once connected, you should be able to view and transfer files as needed.
5 Likes

Happy to see a guide for this. Following a community member’s suggestion, I have moved this into its own guide.

2 Likes

Method 1 did not work for me. I am using Debian for my system. Installing the gvfs-backends and mtp-tools made sys-usb recognize my Samsung Galaxy however the switch to the internal storage and sd-card did not work. (Honestly could be just me).

However I found a different solution:
I created a fedora based sys-usb as my default sys-usb following the official documentation: USB qubes — Qubes OS Documentation (scroll down to ‘How to create a USB qube’). I added an extra step to make it a named disposable. Then made all the same settings like my original sys-usb, When I ran into an issue that the pci_usb device could not start I configured it as strict reset (button on the bottom of the settings/devices window).
Then everything worked fine. No additional software needed.

I prefer to use “android-file-transfer” no need to set anything up and a lot more stable with lots of files and files with bigger sizes. Not to mention quite a lot faster

My workaround has been to simply plug a thumb drive into my phone, transfer stuff, then read off the thumb drive.

1 Like

Me old school too, except I’m using sd card for it via sdcard2usb adapter to connect it to a phone, then connecting sd card via internal sd card reader on a laptop to a desired qube. Not to mention that by not mounting phone’s or USB storage to any (sys-usb) qube potentially spares USB controller from poisoning by Android or USB flash.

The workflow that worked on Qubes OS 4.2 (mounting an Android device via MTP inside sys-usb) may no longer work reliably on Qubes OS 4.3. In some installations, sys-usb is unable to mount USB storage and MTP devices because the required PolicyKit authentication is unavailable, and MTP devices may also be claimed by sys-usb before another qube can access them properly.

A reliable workaround is to use a dedicated USB qube for Android devices instead of sys-usb.

In my case:

* I created a dedicated USB qube based on a Fedora template (using a Disposable Template, just like sys-usb).
* I persistently assigned a USB controller (PCI device) to that qube, rather than relying on USB device attachment.
* I connect the Android phone only to the USB port served by that controller.

The workflow is then:

  1. Start the dedicated Android USB qube.
  2. Connect the phone to the assigned USB port.
  3. Open the file manager inside the qube.
  4. The phone appears normally via MTP and files can be copied in both directions.
  5. After finishing, disconnect the phone and simply shut down (or restart) the qube. Since it is disposable, each session starts from a clean state.

This approach completely bypasses the MTP-related issues encountered with sys-usb on Qubes 4.3 and has proven reliable in practice.

Accessing phone’s storage was never issue per se as I see it. It was about what’s the least unsecure way to do it.

Yes. Accessing the phone’s storage was not the only issue. The real question was how to do it in the least insecure way. A dedicated disposable AppVM with no network and a persistently assigned USB controller looks like a reasonable compromise. It keeps the phone isolated to one qube during the session, does not involve dom0 or other qubes, and can be discarded afterwards. Wireless alternatives may be more convenient, but they add dependence on the network path and on the trustworthiness of the app and protocol being used. So for wired file transfer, this approach seems acceptable and more controlled than handling MTP in sys-usb.

True but I am using a disposable qube anyway.

For the controller (its firmware), it doesn’t matter if it’s disposable qube or not, when using it to mount USB device

I think that’s right about the controller itself: a disposable qube doesn’t make the USB controller or its firmware safer. The same general USB-level risk exists whenever a device is connected through that controller, regardless of whether the target qube is disposable.

The disposable qube mainly limits persistence and keeps the activity isolated from dom0 and other qubes. Assigning a dedicated controller also prevents interference with sys-usb and other USB devices.

So the strictest security answer is indeed “connect nothing”. But for a reasonably trusted phone, a dedicated disposable, networkless qube seems like a reasonable practical compromise. Wireless transfer isn’t automatically safer either; it shifts the trust boundary to the network path and the software/protocol used.

USB debugging does it work with this or with some other method in Qubes? Or does it always end in an I/O error?

I haven’t tried USB debugging in Qubes myself yet, so I can’t speak from experience. My understanding is that it should work when the phone is attached exclusively to the target qube and USB debugging is enabled and authorized on the phone. I don’t think it necessarily ends in an I/O error every time. Please feel free to try.

Hello all !
For mtp work properly for me, i am require to use jmtpfs, my phone is not automatically mounted…

I have no other solution, and for you mtp work properly ?

For workaround, i have made a script for mounting :

[user@sys-usb ~]$ cat mtp-mount.sh
mkdir ~/phone
fusermount -u ~/phone 2>/dev/null
jmtpfs ~/phone && ls ~/phone