[bug] [security] Notification banner visible in locked phone [1.1.9.28] [duplicate]

asked 2015-09-22 16:58:25 +0300

MMx gravatar image

updated 2015-09-23 13:14:59 +0300

chemist gravatar image

I am running 1.1.9.28 on the Jolla phone. The phone was locked, and I received a SMS containing a mTAN, and the first line of this SMS was readable in the notification banner which showed up although the phone was locked. If the actual mTAN would have been in the first line, any attacker to my account having my (locked) phone would have been able to make transactions.

Expected result: No notification banner as long as phone is locked, or just minimal "1 new message" or something like that. It should neither contain the sender nor any part of the content.

This should be fixed for final 2.0.

edit retag flag offensive reopen delete

The question has been closed for the following reason "duplicate question" by jiit
close date 2015-09-23 11:48:40.583773

Comments

1

I don't agree that this elaborate report should be marked duplicate of this quite simple statement. I would not have filed it if above ticket would have been easy to find with the search function, which I actually used before filing my report.

MMx ( 2015-09-22 22:29:44 +0300 )edit

@MMx: It's still a duplicate. If everyone would go about and start new threads because the existing thread(s) were too sparse there would be too much noise for the community to handle. You should rather add your information to the original thread and re-tag it if appropriate (make it findable to those who do the same searches as you).

In some specific cases, where a later post has attracted more votes and/or comments, one might reconsider which thread to close

Mohjive ( 2015-09-23 10:02:30 +0300 )edit

@Mohjive, I agree, this is still a duplicate. The idea is to add to existing topics and not to create three thousand five hundred and one new ones. So still closing this as a duplicate, @MMx, please add your description to the older topic.

raketti ( 2015-09-23 10:21:18 +0300 )edit

Both are duplicates of each other. As this one has a much better description and more votes, I've closed the other one. There's nothing to see here, move along and be friendly and productive.

tbr ( 2015-09-23 10:45:34 +0300 )edit