Join now - be part of our community!

Lockscreen - Massive Security issue when device is locked !

KillerForce
Visitor

Lockscreen - Massive Security issue when device is locked !

Hello everybody,

since I am struggling with my lockscreen security, i would like to ask if somebody knows how to disable the drag down of the status bar. Lets assume my device gets stolen and the thief drags down the status bar on my lockscreen and IS ABLE to deactivate my mobile communication or deactivating the WLAN etc. , by just clicking on the icon at the dragged down status bar. 

I really googled  and couldnt find anything to close that security gap.

Does anybody knows how to deal with this issue ?

Thanks in advance

6 REPLIES 6
KillerForce
Visitor

Hey guys,

i tested it some more.

WLAN can be activated or deactivated over the statusbar while the device is locked

Bluetooth can be activated or deactivated over the statusbar while the device is locked

LTE can be activated or deactivated over the statusbar while the device is locked

Flashlight can be activated or deactivated over the statusbar while the device is locked

Other options like "mobile data" can not be accessed without unlocking the device, which is good.

Is there any possibility to disable the access to WLAN, Bluetooth, LTE and Flashlight when the device is locked ??

Or does Sony still has to address this security issue ?

It would be great if someone from the offical Sony staff can help out and share some information about this issue.

I tested it on a Samsung S8  with Android 8.0 and all options are not accessible via the statusbar when the device is locked.

 

profile.country.NL.title
Strampke
Expert

That is an interesting finding @KillerForce

However one cannot dive deeper into settings to activate USB debugging or connect the device and download files even if USB configuration is set to MTP (Media Transfer Protocol)

KillerForce
Visitor

Update:

Flightmode can be activated or deactivated over the statusbar while the device is locked !

This is crucial imho. When your device gets stolen and the thief is simply able to put the device into the flightmode without unlocking the device, all other anti theft services are useless because the device is not able to send any data in flightmode.

saurus3009
Visitor

@KillerForce

Thanks for investigating.

I noticed this first time i used the device and i thought it was just a bug in my device and FW update will fix it but guess not.

Sony needs to address this ASAP.

KillerForce
Visitor

I have tested it with a Huawei Mate 10 and a LG V30, which doesn't have this security issue.

Sony must really take care of that.

KillerForce
Visitor

I took my time and contacted the Official Sony Support via Chatsupport (germanyn AND USA) at the beginning of february and described everything in depth.

They told me that they will forward this information to the responsible department.

Well, I didn't get any further response and still dont know IF the next update will fix this massive security issue and IF sony is even aware of that. Its like always... such information has to go "public" via an article where this security issue gets pointed out, until a big company like Sony will respond to this.

It is really a shame, frustrating and demotivating. You take your time to point it out and try to force an official respond from sony and you get NOTHING.

Thanks for nothing Sony...