It is possible to activate a system profile from the lock screen with pincode without pincode.
- /e/ version: 0.9-p-2020051454091-dev-FP3
- Device model: FP3
- When it started to occur: From start
- Reproducible with the last /e/ version: Yes
- Reproducible with LineageOS: ??
Summary
-
The device is unusable -
The bug is the source of a data loss or a big waste of time -
The bug concerns a third-party application -
The bug concerns security -
The bug concerns privacy
The problem
Steps to reproduce
See this Video:
Create a system profile (maybe name: athome) without pin code. Triggered by connect to a specific wifi network
Set the default system profile with pin code. Triggered by dissconnect to the specific network
What is the current behavior?
When I activate Wifi from the lock screen with pincode, the profile with lock screen without pincode is activated.
What is the expected correct behavior?
It must not be possible to change the system profile without properly unlocking the device to ensure that the owner unlocks the device.
Technical informations
Relevant logs (adb logcat
)
Relevant screenshots
Solutions
Workaround
I dont know
Possible fixes
I am no programmer.