We have moved to a new Sailfish OS Forum. Please start new discussions there.

Revision history [back]

click to hide/show revision 1
initial version

posted 2019-07-21 03:49:09 +0200

fingerprint reader unlimited retries when display is off

On the Sony XA2 in SFOS 3.1.0.11, when using the fingerprint reader to unlock the device, you can use a registered finger to activate the device (i.e. turn on the screen), and then tap the fingerprint reader again to actually unlock it. When the display is on, either by fingerprint reader or power button, you have 5 tries to use a registered print to unlock the device. After that, you can't use the fingerprint reader and have to enter the security code. This is a good security practice.

When the display is off and tap the reader with an unregistered finger, the display will remain off. Only a registered finger will activate the display. However, you get unlimited retries while the display is off! The limit of 5 unrecognized scans does not apply. This weakens the security of the device.

fingerprint reader unlimited retries when display is off

On the Sony XA2 in SFOS 3.1.0.11, when using the fingerprint reader to unlock the device, you can use a registered finger to activate the device (i.e. turn on the screen), and then tap the fingerprint reader again to actually unlock it. When the display is on, either by fingerprint reader or power button, you have 5 tries to use a registered print to unlock the device. After that, you can't use the fingerprint reader and have to enter the security code. This is a good security practice.

When the display is off and tap the reader with an unregistered finger, the display will remain off. Only a registered finger will activate the display. However, you get unlimited retries while the display is off! The limit of 5 unrecognized scans does not apply. This weakens the security of the device.

[edit] When the limit of 5 retries is reached and you have to unlock the device by security code, you can still wake the device when using a registered finger, but not when using an unregistered finger. Thus, even when security locked, you can have unlimited retries to find a registered finger.