Introducing XDA:DevCon – A Conference For Developers By Developers
XDA Developers Android and Mobile Development Forum
Forgot your password?
 
Post Reply+
Tip us?
 
jeremiasw
Old
#1  
Junior Member - OP
Thanks Meter 0
Posts: 4
Join Date: Sep 2010
Default critical security bug

Hi,

i've found a critical security bug in your CM9 Alpha image for the desire s.

If the phone is locked with a pattern and you plugin your usb data connect cable. The android will now ask, if you want to enable the usb storage.
so i have the full access to the sd memory card, while the phone is locked
 
ben_pyett
Old
(Last edited by ben_pyett; 13th April 2012 at 05:55 PM.)
#2  
ben_pyett's Avatar
Recognized Contributor
Thanks Meter 1567
Posts: 4,163
Join Date: Oct 2006
Location: London, Colchester, Wivenhoe
Quote:
Originally Posted by jeremiasw View Post
Hi,

i've found a critical security bug in your CM9 Alpha image for the desire s.

If the phone is locked with a pattern and you plugin your usb data connect cable. The android will now ask, if you want to enable the usb storage.
so i have the full access to the sd memory card, while the phone is locked
I do hear what you're saying and appreciate you raising the concern, but, that's not really a critical issue is it? as if you locked your phone and I picked it up I could easily remove the SD completely and gain total access to it, unless you previously enabled encryption on the SD card.
Nexus 4 : mako RMA #1
Rom (Kernel): AOKP_ROM [#AOKP_unofficial_PUB-21-05-2013 by bigxie] (Franco [#r139]) Gapps: [#20130301]
Retired - HTC Desire S, HTC Touch Diamond 2, HTC Dual Touch, HTC TyTN, Innumerable NOKIAs
Look in the N4 FAQ/Android 101, N4 Guides Index , N4 Dev Directory or DS INDEX
Look in the N4 OFF-TOPIC or DS OFF-TOPIC & SANCTUARY
 
Ziplock9000
Old
#3  
Ziplock9000's Avatar
Member
Thanks Meter 8
Posts: 95
Join Date: Jun 2011
Location: Hebburn
Quote:
Originally Posted by ben_pyett View Post
I do hear what you're saying and appreciate you raising the concern, but, that's not really a critical issue is it? as if you locked your phone and I picked it up I could easily remove the SD completely and gain total access to it, unless you previously enabled encryption on the SD card.
I agree. Closing the barn door after the horse is bolted.
 
Post Reply+
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Go to top of page...