Lock screen grace period is *very* confusing and insecure #2011
Labels
A-App-Lock
O-Occasional
Affects or can be seen by some users regularly or most users rarely
S-Minor
Impairs non-critical functionality or suitable workarounds exist
T-Defect
Steps to reproduce
Outcome
What did you expect?
I'd expect the PIN to be prompted for every single time you foreground the app, at least by default, otherwise its security is very questionable indeed. I'd also expect the UI of the app to be hidden as soon as it gets backgrounded, to avoid people shouldersurfing the task switcher (or iOS from caching sensitive content for the task switcher sprites)
Critically, the app should behave like WhatsApp or banking apps which default to having no grace period.
What happened instead?
A confusing setup where some of the time you get prompted for PINs by the app, and sometimes you don't, and the user doesn't know when they're protected or not.
Your phone model
No response
Operating system version
No response
Application version
424
Homeserver
No response
Will you send logs?
No
The text was updated successfully, but these errors were encountered: