[Touch-packages] [Bug 1543070] Re: Security breach: bubble displays message preview when screen is unlocked
** Changed in: messaging-app (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to messaging-app in Ubuntu. https://bugs.launchpad.net/bugs/1543070 Title: Security breach: bubble displays message preview when screen is unlocked Status in messaging-app package in Ubuntu: Triaged Bug description: This is not a proper bug in the software behaviour, but an important functional security breach. Nowadays we use the phone to validate our bank transactions, to double step login, etc. We receive a secret code in the phone so we can authenticate the transaction, or validate ourselves as the right person using it. But when doing a bank transference or any other secure operation that requires my phone to validate it, surprisingly, anyone holding my phone in the moment the message is received, can see the secret code, and then do a fraudulent operation with my phone without even unlocking the screen. Thanks. Device: Smartphone BQ Aquaris 4.5E O.S.: Ubuntu Phone phablet@ubuntu-phablet:~$ lsb_release -rd Description:Ubuntu 15.04 Release:15.04 phablet@ubuntu-phablet:~$ To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/messaging-app/+bug/1543070/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1543070] Re: Security breach: bubble displays message preview when screen is unlocked
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to messaging-app in Ubuntu. https://bugs.launchpad.net/bugs/1543070 Title: Security breach: bubble displays message preview when screen is unlocked Status in messaging-app package in Ubuntu: New Bug description: This is not a proper bug in the software behaviour, but an important functional security breach. Nowadays we use the phone to validate our bank transactions, to double step login, etc. We receive a secret code in the phone so we can authenticate the transaction, or validate ourselves as the right person using it. But when doing a bank transference or any other secure operation that requires my phone to validate it, surprisingly, anyone holding my phone in the moment the message is received, can see the secret code, and then do a fraudulent operation with my phone without even unlocking the screen. Thanks. Device: Smartphone BQ Aquaris 4.5E O.S.: Ubuntu Phone phablet@ubuntu-phablet:~$ lsb_release -rd Description:Ubuntu 15.04 Release:15.04 phablet@ubuntu-phablet:~$ To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/messaging-app/+bug/1543070/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp