Android 4.2 lock screen widget is pretty interesting. It has a serious flaw. It allows me add Gmail widget to the lock screen and anybody can read my email without unlocking my tablet. Well that's not a problem if that's what I want. It is even worse, it allows me to add Gmail widget to the lock screen without any authentication at all.
That's pretty interesting. Let's say I do not have my Gmail widget on the lock screen, and now if I lost tablet any body can add Gmail widget to the lock screen and read my emails. He or she does not have to go through any authentication at all. This is very interesting. How come they miss such a big security flaw. I don't mind if they show my email on the lock screen if that's what I want. But allowing anybody to add Gmail widget is a real stupid things to do. I thing some widget should pass authentication before they are added to the lock screen.
No comments:
Post a Comment
Please, no abusive word, no spam.