SunilProgramer / secrets-for-android

Automatically exported from code.google.com/p/secrets-for-android
0 stars 0 forks source link

Secrets revealed without password after phone wake-up #119

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
What steps will reproduce the problem?
1.Install Secrets from Google Play on Galaxy Nexus
2.Open secrets app and unlock with password
3.Press power button to put phone to sleep
4.Press power button to wake phone up

What is the expected output? What do you see instead?
On my Nexus One phone, Secrets would require a password to access secret 
information again, and I expected this same behaviour on my new Galaxy Nexus.  
Upon waking up my Galaxy Nexus, I was surprised to see my secrets app opened 
without requiring a password.

What version of the product are you using? On what operating system?
2.1 (c) 2011 Google Inc.
Android 4.1 Jelly Bean

Please provide any additional information below.
This seems like a significant problem, as access to my secrets should require 
knowledge of my secret passphrase instead of just my phone's unlock code.

Original issue reported on code.google.com by bigend...@gmail.com on 18 Aug 2012 at 7:06

GoogleCodeExporter commented 9 years ago
I am not able to reproduce this problem on my devices: Galaxy Nexus and 
Motorola Xoom.

How much time elapsed between steps 3 and 4?

Original comment by ro...@tawacentral.net on 22 Aug 2012 at 12:16

GoogleCodeExporter commented 9 years ago
What type of screen lock do you use?  PIN number?  Pattern?  None?

Original comment by ro...@tawacentral.net on 22 Aug 2012 at 12:17

GoogleCodeExporter commented 9 years ago
I can reproduce this with just a few seconds or several minutes between turning 
off the phone and turning it back on.  In fact, I have not observed a password 
prompt after the phone goes to sleep after timeout or having the power button 
pressed.

I can also repro with different screen locks (pattern and PIN) as well as no 
screen lock.  Each time, I'm dropped directly back into Secrets without a 
password challenge.

Is there any debug information I could gather?

Original comment by bigend...@gmail.com on 23 Aug 2012 at 7:32

GoogleCodeExporter commented 9 years ago
Issue 92 has been merged into this issue.

Original comment by ro...@tawacentral.net on 31 Aug 2012 at 1:16

GoogleCodeExporter commented 9 years ago
I have been able to reproduce this problem with my Xoom running jellybean.

Fixed with http://code.google.com/p/secrets-for-android/source/detail?r=237

Original comment by ro...@tawacentral.net on 9 Sep 2012 at 1:50

GoogleCodeExporter commented 9 years ago
Fix http://code.google.com/p/secrets-for-android/source/detail?r=241 also 
applies to this bug: waking up from the history activity.

Original comment by ro...@tawacentral.net on 9 Sep 2012 at 3:15

GoogleCodeExporter commented 9 years ago
Yay!  The latest update from Google Play fixed this issue.

The only issue I see now--and this may be nitpicking--is that upon wake up, 
there is a screen effect where the previously-displayed screen shrinks very 
quickly before the login page appears.  If I could slow down the screen or take 
a picture just after unlocking the screen, I feel like Icould get a glimpse of 
the secret information.

Original comment by bigend...@gmail.com on 11 Sep 2012 at 2:14