Jump to content

Lock screen flaw found in Android

ETRJ

A security flaw in Android that lets people bypass the lock screen on a mobile device has been discovered by researchers at the University of Texas.

They found that trying to unlock the phone or tablet with an abnormally long password caused the lock screen to crash in certain conditions.

The flaw was limited to Android Lollipop, the most recent version of the mobile operating system.

Google issued a patch for its Nexus devices on Wednesday.

About 21% of Android users run affected versions of the operating system.

After crashing the lock screen, the researchers were able to access the phone's data and apps.

The vulnerability could not be exploited if people had chosen a lock pattern or Pin code instead of a password.

While Google is rolling out its fix for Nexus, other phone manufacturers are responsible for distributing the software to their own handsets.

Source: http://www.bbc.co.uk/news/technology-34268050

Link to comment
Share on other sites

Link to post
Share on other sites

Does anyone actually use a "password" instead of a PIN or Pattern?

 

I'm not a fan of Password, too much of a pain, but I don't like Pattern's either, I find them too easy to break, just by watching someone once, or even just checking the finger grease lines on the screen. - I've always used a PIN. Easiest to enter (for me anyway) and I feel it's secure (enough).

 

p.s. Follow your own post. ;)

 

<snipperino>

Link to comment
Share on other sites

Link to post
Share on other sites

To be fair, my phone doesnt really have that much stuff on it, so usually pattern is fine. But after i got my S6, i use fingerprint, which is fast and safe. I dont think fingerprint should be affected by this exploit, unless it also impacts the backup passwords

How many computer programmers does it take to change a light bulb?


None, that's a hardware problem.  :D

Link to comment
Share on other sites

Link to post
Share on other sites

To be fair, my phone doesnt really have that much stuff on it, so usually pattern is fine. But after i got my S6, i use fingerprint, which is fast and safe. I dont think fingerprint should be affected by this exploit, unless it also impacts the backup passwords

 

Yeah, fingerprint is usually a good way to go.

 

As long as it can't be tricked too easily with a piece of thin plastic that is!

 

(I think I remember a video getting past the iPhone 5s finger print sensor with paper or something) - But I could be wrong and the newer version is probably better anyway.

Link to comment
Share on other sites

Link to post
Share on other sites

Glad I switched back to CM11 monday

Why is SpongeBob the main character when Patrick is the star?

Link to comment
Share on other sites

Link to post
Share on other sites

Worked on my Z3. It just crashed but restarted pretty much instantly so I couldn't actually use the phone at all. I think there is a way to interrupt the restart though, I'll keep messing around with it.

 

Edit: Yep, got it to crash and can now fully use the phone. gg

Link to comment
Share on other sites

Link to post
Share on other sites

I don't see the problem. Just buy a brand new device with the latest version of Android to get the problem fixed ...

THIS SIGNATURE INTENTIONALLY LEFT BLANK

Link to comment
Share on other sites

Link to post
Share on other sites

I don't see the problem. Just buy a brand new device with the latest version of Android to get the problem fixed ...

it isn't Apple man, you can just install a new ROM on the Phone..

"When you're in high school you should be doing things, about which you could never tell your parents!"

Link to comment
Share on other sites

Link to post
Share on other sites

While still a problem, it's not really that huge since people would need to have physical access to the device and also we're not sure how many people use passwords instead of PINs and patterns. Hopefully all devices get patched for this, you never know if anything's safe these days   :ph34r:

Link to comment
Share on other sites

Link to post
Share on other sites

And there's the flaw of Android: Not the FACT that there's bugs, but the fact that once a bug is discovered it's gonna be months before the fix actually trickles down through the manufacturers and carriers.

Fortunately, I don't use a password so no harm to me.

Link to comment
Share on other sites

Link to post
Share on other sites

Just tested this on an iPhone to see if I could replicate it on iOS (iOS 9 GM seed). After several thousands of letters typed, the entire phone crashed... Though, I guess that's better than having everything about you (in the phone) to be revealed if someone would steal your phone.

Spoiler

System:

i5 3570k @ 4.4 GHz, MSI Z77A-G43, Dominator Platinum 1600MHz 16GB (2x8GB), EVGA GTX 980ti 6GB, CM HAF XM, Samsung 850 Pro 256GB + Some WD Red HDD, Corsair RM850 80+ Gold, Asus Xonar Essence STX, Windows 10 Pro 64bit

PCPP:

http://pcpartpicker.com/p/znZqcf

 

Link to comment
Share on other sites

Link to post
Share on other sites

I still can't understand how they can't give an option to disable swipe before pattern and implement dark theme. So lame.

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

Knock code ftw.

i5 4670k @ 4.2GHz (Coolermaster Hyper 212 Evo); ASrock Z87 EXTREME4; 8GB Kingston HyperX Beast DDR3 RAM @ 2133MHz; Asus DirectCU GTX 560; Super Flower Golden King 550 Platinum PSU;1TB Seagate Barracuda;Corsair 200r case. 

Link to comment
Share on other sites

Link to post
Share on other sites

one of the biggest issues i have with android. the fact that important updates can take weeks or months to drop....they need to sort that out

"if nothing is impossible, try slamming a revolving door....." - unknown

my new rig bob https://uk.pcpartpicker.com/b/sGRG3C#cx710255

Kumaresh - "Judging whether something is alive by it's capability to live is one of the most idiotic arguments I've ever seen." - jan 2017

Link to comment
Share on other sites

Link to post
Share on other sites

Guest
This topic is now closed to further replies.

×