Football Fans: Download the 2012 Schedule App from Google Play!


Go Back   Android Forums > Android Discussion > Android Applications

Android Applications All the information you could ever want about Android Applications. Learn about apps and get help with them... all here! New apps can be found and announced in the Applications Announcements forum linked below.



Reply
 
LinkBack Thread Tools
Old November 21st, 2009, 10:36 AM   #1 (permalink)
New Member
 
Join Date: Nov 2009
Posts: 1
 
Device(s):
Thanks: 0
Thanked 0 Times in 0 Posts
Default Rather large security hole in Touchdown?

I think I stumbled upon a rather large security hole in Touchdown and its pin entry.

I have a myTouch with the latest apps and patches on it. Nothing fancy, not rooted.

If, when you get to the pin entry dialog in Touchdown, you simply switch to the phone app, then use the Back button (or Home, then Back...haven't done extensive testing), you're presented your Touchdown home - no pin entry blocking you, even after a fresh powerup.

Is this sort of a known hack around these pin-style apps? Or is this a problem with the way Touchdown's pin entry works?

Either way, a note to the developers is probably warranted? These days, IT depts are getting more and more secure-conscious with powerful phones like this, and may be upset to know that emails and contacts are as insecure as this. It was suggested by my IT dept that I purchase Touchdown a few months ago, and it works great, but this makes me worry.

magnavita is offline  
Reply With Quote
Sponsors
Old April 1st, 2011, 04:55 PM   #2 (permalink)
New Member
 
Join Date: Feb 2010
Location: Outside of Seattle, WA USA
Posts: 4
 
Device(s): Too many to list. All Android.
Thanks: 0
Thanked 0 Times in 0 Posts
Exclamation Is this consistently reproducable?

can this be reproed over and over?

We've tried this on a couple devices and haven't been able to make this happen.

this is a stock ROM, not rooted device, correct?

Would you please send a mail to support@nitrodesk.com so our support folks can walk you through generating a diagnostics log so that we can see what's happening on your device.

Thanks!

Ron
Rongo is offline  
Reply With Quote
Old April 1st, 2011, 05:04 PM   #3 (permalink)
Member
 
Join Date: Nov 2009
Location: Austin, TX
Posts: 211
 
Device(s): droid
Thanks: 1
Thanked 11 Times in 10 Posts
Send a message via Skype™ to stevenlong
Default

I can't get this to happen on my dell streak.

I have noticed that the pin is cached, or there is some time out value associated with when you enter the pin so that if I return to touchdown with a short period of time I will not get the prompt for a pin.
stevenlong is offline  
Reply With Quote
Old April 1st, 2011, 05:08 PM   #4 (permalink)
New Member
 
Join Date: Feb 2010
Location: Outside of Seattle, WA USA
Posts: 4
 
Device(s): Too many to list. All Android.
Thanks: 0
Thanked 0 Times in 0 Posts
Default

right....that's a "time-out" setting that's pushed form Exchange. they admin can say that it will only require the PIN if it's been more than 2 minutes since the data was last accessed, etc.

if anyone else can test the above scenario and report back, please do and let me know what type of device and what version of Android.


Thanks!
Rongo is offline  
Reply With Quote
Old April 1st, 2011, 05:12 PM   #5 (permalink)
Senior Member
 
Join Date: Jan 2011
Location: SoCal
Posts: 902
 
Device(s): Droid X2
Thanks: 57
Thanked 82 Times in 75 Posts
Send a message via ICQ to AngryHatter
Default

Quote:
Originally Posted by Rongo View Post
can this be reproed over and over?

We've tried this on a couple devices and haven't been able to make this happen.

this is a stock ROM, not rooted device, correct?

Would you please send a mail to support@nitrodesk.com so our support folks can walk you through generating a diagnostics log so that we can see what's happening on your device.

Thanks!

Ron
The post is 2 years old?
AngryHatter is offline  
Reply With Quote
Old April 1st, 2011, 05:45 PM   #6 (permalink)
Usually off topic
 
Yeahha's Avatar
 
Join Date: Jul 2010
Location: FG
Posts: 10,223
 
Device(s): VZW Galaxy Nexus*, HTC TB*, D2G*, Cowon D3*, Kindle Fire *Rooted
Thanks: 2,068
Thanked 4,678 Times in 3,164 Posts
Default

Quote:
Originally Posted by AngryHatter View Post
The post is 2 years old?

We know the devs over at touchdown are on top of their game scouring forums feedback on their app
Yeahha is online now  
Reply With Quote
Old April 1st, 2011, 06:04 PM   #7 (permalink)
New Member
 
Join Date: Feb 2010
Location: Outside of Seattle, WA USA
Posts: 4
 
Device(s): Too many to list. All Android.
Thanks: 0
Thanked 0 Times in 0 Posts
Default

yes, it is old, but we had another user report the issue today and referenced this article.

It's been fixed long ago but we just want to be sure. too many folks are relying on TouchDown to leave anything to chance.
Rongo is offline  
Reply With Quote
Reply

Bookmarks

Tags
exchange, hack, mytouch, pin, security, touchdown


Go Back   Android Forums > Android Discussion > Android Applications User CP
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Hole In The Wall goranr Android Games 1 June 11th, 2010 09:13 AM
WaveSecure Mobile Security: security app that protects phone, data & privacy. Plasmadragon007 Application Reviews 0 June 8th, 2010 08:19 AM
HTC is going to dig themselves into yet another deep hole roflcopterrr Android Lounge 10 February 19th, 2010 01:54 AM
pin hole? Madhouse HTC Hero 9 September 23rd, 2009 05:21 PM
face in hole TateWatkins The Lounge 7 November 13th, 2008 12:52 PM



All times are GMT -5. The time now is 04:46 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Custom vBulletin Skins by: Relivo