[Security] Can easily bypass pincode

Bug #1395075 reported by Omer Akram
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Canonical System Image
Fix Released
High
Canonical Devices Products
unity8 (Ubuntu)
Fix Released
Critical
Michael Terry
unity8 (Ubuntu RTM)
Fix Released
Critical
Michał Sawicz

Bug Description

rtm image 166

1. reboot the phone
2. As soon as the greeter is show, try to swipe it away.

What happens:
In some attempts we don't see the pincode screen rather 'Scopes' is seen with a spinner and there you are unlocked.

Tags: ota-1

Related branches

Revision history for this message
kevin gunn (kgunn72) wrote :

does it remain unlocked & completely interactive ?

Michael Terry (mterry)
Changed in unity8 (Ubuntu):
assignee: nobody → Michael Terry (mterry)
status: New → Confirmed
Revision history for this message
Michael Terry (mterry) wrote :

Just a heads up, to reproduce this, I have to continually swipe the screen while the spinning logo is shown. Eventually the greeter will appear and be swiped away. But it's hard for me to reproduce this bug if I simply wait for the greeter to start being visible.

Revision history for this message
Michael Terry (mterry) wrote :

@kgunn, yes it remains unlocked and completely interactive.

Changed in unity8 (Ubuntu):
status: Confirmed → In Progress
Omer Akram (om26er)
Changed in unity8 (Ubuntu RTM):
importance: Undecided → Critical
status: New → Confirmed
information type: Public → Public Security
tags: added: ota-1
kevin gunn (kgunn72)
Changed in unity8 (Ubuntu RTM):
assignee: nobody → Michael Terry (mterry)
Olli Ries (ories)
Changed in canonical-devices-system-image:
assignee: nobody → Canonical Devices Products (canonical-devices-products-team)
importance: Undecided → High
milestone: none → r1
status: New → Confirmed
Michał Sawicz (saviq)
Changed in unity8 (Ubuntu):
importance: Undecided → Critical
Changed in unity8 (Ubuntu RTM):
milestone: none → 14.09-ota-1
Michał Sawicz (saviq)
Changed in unity8 (Ubuntu RTM):
status: Confirmed → Triaged
Revision history for this message
Michael Terry (mterry) wrote :

This bug was fixed in the package unity8 - 8.01+15.04.20141202-0ubuntu1

---------------
unity8 (8.01+15.04.20141202-0ubuntu1) vivid; urgency=low

  [ Michael Terry ]
  * Make sure that there is no window of opportunity for swiping away
    greeter before the lockscreen appears.

Changed in unity8 (Ubuntu):
status: In Progress → Fix Released
Michał Sawicz (saviq)
Changed in unity8 (Ubuntu RTM):
status: Triaged → In Progress
assignee: Michael Terry (mterry) → Michał Sawicz (saviq)
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package unity8 - 8.01.1+15.04.20141208~rtm-0ubuntu1

---------------
unity8 (8.01.1+15.04.20141208~rtm-0ubuntu1) 14.09; urgency=medium

  [ Michael Terry ]
  * Make sure that there is no window of opportunity for swiping away
    greeter before the lockscreen appears. (LP: #1395075)

  [ Michael Zanetti ]
  * Keep applications suspended while lockscreen is shown (LP: #1378126)

  [ Mirco Müller ]
  * Make sure non-square icons are not cropped. (LP: #1378417)
 -- Ubuntu daily release <email address hidden> Mon, 08 Dec 2014 09:31:49 +0000

Changed in unity8 (Ubuntu RTM):
status: In Progress → Fix Released
Changed in canonical-devices-system-image:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.