Potential security bug in Samsung's new Good Lock screen lock - Samsung Galaxy S7 Guides, News, & Discussion

I had tried Samsung's new Good Lock today, and discovered what I consider a severe security flaw. From the Good Lock's lock screen, the app tray can be edited without unlocking the phone. And in doing so, all user installed apps can be seen. You must still unlock the phone to access apps, but I believe that allowing the installed apps to be seen with the phone still locked can lead to other vulnerability's.
I have tried to contact Samsung about this, but they have not replied, of just don't care.

Related

[Q] Lock Screen after Stock Upgrade

tl;dr: lock function no longer working after upgrade from official 1.6 to 2.1
I know this is a duplicate post from two others, but they never got any replies, I'm just trying my luck here.
New phone, preloaded with 1.6, no third party apps other than carriers bloat. Lock screen functions just fine on 1.6 and I have never attempted any "rooting" to this device.
Once I perform the official update with Samsung Kies Mini, the lock screen never shows up. It boots right to the home screen and the lock button now only turns off the back-light.
Tried enabling pattern lock, but it never shows. Performed system reset back to 1.6 and the lock screen returns. My carrier, Rogers (Canada), has never heard of this and is going to exchange my phone. However I want to find out if anyone else has a cure for this weird bug before my replacement arrives Friday (Nov 5).
Try changing backlight timeout in settings- on 2.1 screen is locked when light goes off. Maybe somehow system is set to "never"

Stock Froyo Pin lock causes boot problems

Using Froyo, when setting a PIN lock (now required for exchange) boots take a *very* long time... sometimes 10 minutes or more. Watching the status bar at boot it seems to "restart" at a certain point in the boot process many times. I've captured a log with ADP and I see a number of fatal errors, but nothing I can relate directly to the pin lock.
I confirmed the same problem on my wife's Vibrant (pretty much straight stock w/o a lot of apps).
Pattern lock works fine. (but not allowed by exchange). Password lock behaves the same way.
I posted on the T-Mobile forums and others there confirmed the problem but no solution. I don't think T-Mobile will be fixing this anytime soon... do other ROMs have the same issue? Is there a simple fix?
Robert
I had the same problem using the pin lock. When I rebooted it got stuck in the "media scanner" loop with random vibrating from the phone. I had to format my sd card to get back on, on the third time it did this it forced me to factory reset just so I could use the damn phone again. I got so fed up I decided to look into rooting my phone. I was able to root it and haven't looked back since. If samsung ever decides to send out more updates I'll never do it until team whiskey takes a look at it and makes it better . I went back to 2.1.1 eclair stock, cuz I wasn't able to do it with 2.2 froyo (cuz I'm new). I'm now using bionix v1.2.1, its pretty awesome. I had used the pin lock with this rom and it works just fine, haven't tried the pattern lock or other password lock. I don't use it anymore but it has nothing to do with it being unstable, just personal. Anyway, if you're looking into rooting I highly recommend bionix-v. Good luck with your phone
I am rooted, but you're talking about running a non-stock ROM. I don't feel the need for it (yet).
stock Exchange email forced the use of a pattern or password lock. I've started using touchdown and it just requires the pin lock in the touchdown app, not the whole phone. I'll probably stick with the stock ROM and Touchdown.
I find it strange that something like a screen lock would cause so much trouble.
Robert

PIN locking problem

Is anyone else experiencing this issue. The device was locked with a PIN and fingerprint recognition. During extensive use last weekend the lock would disengage meaning the device could be opened by merely swiping. I therefore removed the fingerprint recognition and reverted to PIN only. However again after extensive use the lock was bypassed.
When you switched on the phone the screen showed "Swipe screen to unlock" If the padlock was below this phrase it was open and no PIN was required. You could however press the padlock and it would jump to be above the phrase and then required the PIN to unlock. However after switching off the phone it would often revert to be "open".
I can't seem to find anything about this by googling so would welcome suggestions.
Thanks,
Brian
PS If the phone is only used lightly during the day the device remains secure.
That sounds weird. Upon a restart the phone will always ask for the alternative method of unlocking (pin or password for example) rather than simply unlocking with fingerprint. But after that first time it should work fine. Personally, I have mine to set to unlock with only a fingerprint. Perhaps the fact you use both at all times could be causing the issue?
Are you on vanilla stock the phone came with? Have you tried updating it?
Beefheart said:
That sounds weird. Upon a restart the phone will always ask for the alternative method of unlocking (pin or password for example) rather than simply unlocking with fingerprint. But after that first time it should work fine. Personally, I have mine to set to unlock with only a fingerprint. Perhaps the fact you use both at all times could be causing the issue?
Are you on vanilla stock the phone came with? Have you tried updating it?
Click to expand...
Click to collapse
Thanks for the response.
I thought it was weird as well as the S5 never had this problem but of course it did not have fingerprint unlocking.
Yes it is Marshmallow straight out of the box and has had one update so is now running 6.0.1
I did sometimes have a problem with the fingerprint recognition so I would be reluctant not to retain the PIN!!!
S5 did have fingerprint unlocking, it was simply not as good as you had to slide your finger down the button. It did work though.
I recommend an update. Or, if you don't mind tripping knox, install one of the custom roms on this site or one of the other roms off site (like the one listed in my signature). Each new release of these custom roms are normally built on the latest base that is out there so you would hope any bugs like this would be fixed, assuming it is a bug.
Thanks, I'll give it a go. After the Lollipop upgrade bricked my Asus Nexus 7 I have been reluctant to do upgrades unless absolutely necessary.

Pattern security lock screen being bypassed!!

I'm using pattern as my security lock screen and have been on all my previous Notes. For about 5 months now the lock screen intermittently fails i.e. does not appear and is bypassed and I've full access to my phone!
This is really annoying and means someone could effectively have full access. When I got the phone I'd tried the fingerprint security but very quickly reverted back, had I not the phone would most likely have ended up in pieces out of sheer frustration (Amazing how companies release features which simply aren't worth the paper they are written on). This issue has endured even though there has been subsequent sizeable system updates since, and yes my OS is up to date.
Any ideas on how I can resolve this?

Somebody else having problems with their fingerprint reader?

Hi, first of all I apologise if this question has been asked but I don't know how to search just this place.
I'm using everything stock, no root, stock launcher.
I have my phone set up to ask for the password on reboot. I have my fingerprint reader set up to unlock my phone. I also have the fingerprint reader set up to wake the screen.
However under certain circumstances the fingerprint reader does not unlock the phone. The most reliable way to trigger this behavior is to plug the phone in to charge.
I exclusively lock the screen with the power button.
The fingerprint reader is still responsive and it still wakes the screen but there's no vibration feedback and it does not unlock. After I unlocked the phone with my password and lock it again the reader works again.
So what's going on here? How should I debug this?
After reboot it is normal to ask for password first time. Sometimes i have also seen this but when i unlock with pattern (my backup way) and lock again it works fine. I can not trace this to be related with charging or something else and it happens rarely but i have seen it also. Maybe a software bug.
Looking back to the days when i have LG V10 i remember that i had the same problem with fingerprint sensor not working sometimes. It was more frequently related to heat buildup as it was hot phone anyway.
I had the same problem these days, I think the fingerprint reader won't work if your hands are really cold.
Hmm I don't think my U Ultra is getting particularly hot and, no, my hands are certainly not very cold either. This behavior happens indoors.
It's just extra security plan and simple
Sometimes, not very often though, my fingerprint reader refuses to respond. Not even a misread where you get haptic feedback and not a lot else.
Just using the power button and entering my back up security (pattern in my case) and it comes back to life.
I don't particularly worry about it, but I suppose it's nice to see that it's not just me
Will see if the upgrade to 8.0 fixes it.
I met this problem.The solution was very interesting.I use Yandex.disk app.This problem did occur after the Yandex.disk app is update.I hard reset my phone.The problem was not in my phone.But I setup Yandex.Disk app the problem repeat occur.İf you installed Yandex.Disk, uninstall the application.if you don't use Yandex.Disk,The last apps update uninstall to try.
Good Lord I have so many apps installed though...
Then go to a full factory reset and see if it helps, thats the 1st thing you do when you have problem.
After a bit of experimentation this behavior seems to have stopped after I disabled/removed all Smart Lock Trusted Places -- a feature that is already known to be buggy.
I have it too, once a day it puts me to enter the password, its a security or a bug idk.
No more, no less, every time when its charging. I installed some 3rd party apps, its possible that they are to blame.
We will see when 8.o strikes and i will hard reset.
Garkan said:
I have it too, once a day it puts me to enter the password, its a security or a bug idk.
No more, no less, every time when its charging. I installed some 3rd party apps, its possible that they are to blame.
We will see when 8.o strikes and i will hard reset.
Click to expand...
Click to collapse
8 fixed this bug for me but i found more bugs in oreo so i am thinking to roll back to 7.0 and meet fingerprint sensor bug again because oreo problems are disgusting - car bluetooth does not works as it should - i can't read addressbook in my car head unit - it shows error. i found that is some bluetooth software parts was not included in 8.0 but successfully fixed in 8.1. and i'am pretty sure we will never receive 8.1 for u ultra.
in russian 4pda forum i found some reports (unconfirmed yet) that fingerprint bug disappeared. maybe somebody here can confirmed it?
No i have android 8 and issue still occurs sadly did not found a fix.
I've suddenly had this issue a couple of days ago a couple of times. I didn't do anything (except a couple of reboots) and it was fixed again.
Now after updating to Oreo and again using leedroids ROM, i didn't experience theissue again..
I talked to a htc representative and said to clear credentials from security/encryption and credentials seems to be a conflict in security certificates. For the moment it works.

Categories

Resources