hawknetwork / sealnote-plus

Android app for keeping encrypted notes
Other
1 stars 0 forks source link

Settings screen is not hidden if password expires #34

Open ajburley opened 5 years ago

ajburley commented 5 years ago

If you are on the Settings screen, lock the device, then wait until the password expires, then unlock the device, the Settings screen appears without any password prompt. This may cause a backup to be performed, so an attacker can obtain the encrypted data and take it somewhere else for a brute force attack etc. They can also do other things like change the password timeout, etc.