[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] Pattern lock bypass on SE X10 with Android 1.6
From:       Josh Bressers <bressers () redhat ! com>
Date:       2011-02-24 13:56:57
Message-ID: 1464523319.203145.1298555817595.JavaMail.root () zmail01 ! collab ! prod ! int ! phx2 ! redhat ! com
[Download RAW message or body]



----- Original Message -----
> Would something like http://www.nth-dimension.org.uk/blog.php?id=89
> qualify for a CVE? I didn't really consider it when I published it
> because I was working on the principal that it required physical access
> and you could therefore argue that all bets are off but I was was
> wondering in the light of the recent discussions about auto mounting bugs
> which share a similar quality.
> 

I'll leave this up to MITRE, but in my opinion, phones are a different
story. The whole reason I lock my phone is because it's so easy for an
attacker to get access to it. The thoughts of someone grabbing your desktop
and running down the street with it is laughable, but I suspect this
happens with phones many times every single day.

I'm expecting the whole mobile security paradigm to change quite a lot in
the near future as people start to focus there. There's a lot of low
hanging fruit.

Thanks.

-- 
    JB
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic