0
Security Issue in OOS 3.5.6

  1. saahill
    Gingerbread Mar 10, 2017

    saahill , Mar 10, 2017 :
    I have recently set up Smart Lock in my OP2, It unlocks the phone when it's connected to my fitness band.
    The issue here is, if the band is in the room, and somebody switches on the Bluetooth in my phone from the notification panel, even when the phone is locked, the phone unlocks itself after connecting with the band.
    Which means that if anyone wants to access my phone, all the person has to do is switch on the Bluetooth, when my band is around.

    Similarly, the Now we can toggle location even if the phone is locked (We could toggle location only if the device was unlocked in OOS 3.1.0), this is a security threat as anyone can turn off the location if the phone is misplaced.
    Not everyone can Factory reset a fone or boot into recovery, but anybody can toggle the location which will make it difficult to locate the phone from Android device manager!

    THESE ARE POTENTIAL SECURITY THREATS IN MY OPINION! WHICH SHOULD BE FIXED IN THE COMING UPDATE!

    Just removing the Bluetooth and the location buttons from the notification panel when the phone is locked should do the trick!
     

    #1
  2. toastytoast1234
    Marshmallow Mar 10, 2017

    toastytoast1234 , Mar 10, 2017 :
    "I'm using automatic unlock based on proximity to another gadget because I'm a lazy ***, and it turns out that this makes my phone easy to unlock".

    I feel your pain.
     

    #2
    saahill likes this.
  3. saahill
    Gingerbread Mar 11, 2017

    saahill , Mar 11, 2017 :
    I have also submitted a bug report on this.
     

    #3
  4. n.manivel
    Cupcake Mar 11, 2017


    #4