Join now - be part of our community!

Request for PIN without reboot

Korben-Dallas
Visitor

Request for PIN without reboot

I notice that my phone occasionally forces me to unlock it with my PIN, despite fingerprint unlock being set up and functional. The PIN screen says that in is necessary for additional security. (I know that PIN is required after reboot, but no reboot is involved in cases I'm referring to)

I presume this is a normal Android security feature. But when does it occur? What is the trigger for the mandatory PIN unlock? A certain number of unlocks? A certain period of time? Some event, like NFC payment? Something else?
3 REPLIES 3
profile.country.GB.title
Uliwooly
Expert

after multiple failed attempts it will request that you enter the PIN

Korben-Dallas
Visitor


@uliwooly wrote:

after multiple failed attempts it will request that you enter the PIN


That is true, but that is a differerent story. If I deliberately do "failed attempts", it will tell me at the bottom of lock screeen "Too many attempts. Try again later". If I swipe to the PIN screen after that, it will just say "Enter PIN". Also, if I let it "cool down" for a minute instead of trying to force my way in, it will let me log in with my finger without the PIN.

The situation I describe is different. No "failed attempts" take place. PIN screen appears rigth away. The PIN screen says "PIN required for additional security". This specific prompt mentioning "additional security" is already an indication of something special going on. And there's no "cool down" period. It will continue to insist on my PIN untill I enter it.

I see it widely reported on the Net. People say that using a third-party app to lock the screen will trigger this situation on the next unlock. However, I don't use any third-party app to lock the screen. So I wonder what triggers it in my case...

Also, this piece of Android source code (found through Reddit link)

https://github.com/android/platform_frameworks_base/commit/25b4d4b280c6aa07656328bd9dd90977781d00e1#...

seems to imply that Android is hardcoded to ask for "strong authentication method" every 3 days. Apparently this is the explanation for what I'm seeing.

profile.country.RO.title
_alexdon_
Expert

@Korben-Dallas I think not using the device for a longer period of time could trigger this as I noticed this on a Z5c, after several days it will ask me for PIN anyways.

alexdon