Samsung Galaxy S III bug lets anyone bypass password-protected lockscreen

[email protected] (Anupam Saxena)
March 8, 2013

Samsung_Galaxy_S_III

A user has discovered a security flaw in the Samsung Galaxy S III that allows anyone to bypass the lock screen of the phone by following a few simple steps.

Sean McMillan has posted a method to access the lock screen of the Galaxy S II on a mailing list. According to him the bug can be reproduced by following these steps:

1) On the code entry screen (of the lock screen) press Emergency Call

2) Then press Emergency Contacts

3) Press the Home button once

4) Just after pressing the Home button, press the power button quickly

5) If successful, pressing the power button again will bring you to the S3's home screen

McMillan mentions that it might take a few attempts to get the hack working and that sometimes the method works in one go while at others, it can take more than 20 attempts. He also adds that the method seems to work better when the mobile has auto rotation turned on. McMillan claims to have tested the method on three Galaxy S III devices.

We tried unlocking the screen of a Samsung Galaxy S III(GT-I9300 running Android 4.1.2) using the same method but weren't successful.

However, ZDNET says they were able to replicate the hack after a few attempts. The site states that the timing to replicate the issue is very small and that it is difficult to replicate it in the first attempt. But after bypassing the screen once, the bug stays on the device even when the phone's screen is turned back off and the phone stops asking the user for their PIN, password or pattern.

Just a few days back, another user, Terence Eden, had discovered a security flaw in the Samsung Galaxy Note II that allowed anyone to bypass the lock screen and take a look at the home screen app icons by following similar steps. But the hack didn't allow the hacker to use any of the apps.

Last month, a similar vulnerability was discovered in Apple iOS 6.1, allowing users to bypass the lock screen, following which Apple had acknowledged the issue and promised a fix.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 4,2020

Twitter has joined efforts to do away with racially loaded terms such as master, slave and blacklist from its coding language in the wake of the death of African-American George Floyd and ensuing Black Lives Matter protests.

The project started even before the current movement for racial justice escalated following the death of 46-year-old George Floyd in police custody in May.

The use of terms such as "master" and "slave" in programming language originated decades ago. While "master" is used to refer to the primary version of a code, "slave" refers to the replicas. Similarly, the term "Blacklist" is used to refer to items which are meant to be automatically denied.

The efforts to change these terms in favour of more inclusive language at Twitter were initiated by Regynald Augustin and Kevin Oliver and the microblogging platform is now backing their efforts.

"Inclusive language plays a critical role in fostering an environment where everyone belongs. At Twitter, the language we have been using in our code does not reflect our values as a company or represent the people we serve. We want to change that. #WordsMatter," Twitter's engineering team said in a post on Thursday.

As per the recommendations from the team, the term "whitelist" could be replaced by "allowlist" and "blacklist" by "denylist".

Similarly, "master/slave" could be replaced by "leader/follower", "primary/replica" or "primary/standby".

Twitter, however, is not the first to start a project to bring inclusivity in programming language.

According to a report in CNET, the team behind the Drupal online publishing software started using "primary/replica" in place of "master/slave" as early as in 2014.

The use of the terms "master/slave" was also dropped by developers of the Python programming language in 2018.

Now similar efforts are underway at Microsoft's Github and LinkedIn divisions as well, said the report.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 14,2020

Social media platform WhatsApp assured the Supreme Court on Wednesday that it will not roll out its payment services without complying with all payment regulations and norms in the country.

A bench headed by Chief Justice S.A. Bobde and comprising Justices Indu Malhotra and Hrishikesh Roy took up the matter through video conferencing. Senior advocate Kapil Sibal, representing the social media platform, said "WhatsApp Inc makes a statement on behalf of his client that they will not go ahead with the payments' scheme without complying with all the regulations in force."

The statement was made during the hearing of a petition seeking a ban on payment through WhatsApp, as it does not conform to the data localization norms. The top court took the assurance made by WhatsApp on record.

WhatsApp made the statement during the hearing of a plea seeking a ban on its payment service, for not being in line with data localization norms.

In 2018, WhatsApp was granted a beta licence to launch its payment service, but a dedicated and separate app is yet to be launched. A petition was moved in the apex court that WhatsApp's existing model for its payments service should be declared inconsistent with the Unified Payment Interface (UPI) Scheme, as a separate dedicated app has not been offered by the company.

The petitioner NGO, Good Governance Chambers, argued that the National Payments Corporation of India (NPCI) and the Reserve Bank of India (RBI) must change its model on the lines of the UPI payment scheme, and its operations may be suspended until these conditions are met.

The apex court today asked the Centre, Facebook and WhatsApp to file their replies within three weeks and it will take up the matter thereafter. The court noted that the government may process the applications filed by WhatsApp in accordance with the law and there is no stay on the same. Facebook was represented by senior advocate Arvind Datar.

The petitioner argued that lapses have been found in relation to WhatsApp's claims of having a secure and safe technological interface for securing sensitive user data.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 6,2020

Hyderabad, May 6: Away from city lights, two hours before Sunrise, people in India and across the world can witness Annual Meteor Shower called Eta Aquarids till May 28.

Observed since time immemorial, Meteor shower are commonly known as shooting stars which are nothing but dust flakes of comet/asteroid entering earth atmosphere.

This Annual Eta Aquarids Meteor Shower peaked on Wednesday at 02.30 am on Wednesday whereas presence of Full Moon was an obstacle outshining bright streaks of lights of this meteor shower zipping across the South Eastern sky.

As this meteor shower is active till May 28, people can still watch this celestial spectacle in early morning every day, Planetary Society of India (PSI) Director N Sri Raghunandan Kumar interacting with UNI said.

As per International Meteor Organization (IMO), 50 meteors per hour are expected to be seen on day of peak today. And this number would vary as days pass on till May 28 while earth passes through dust cloud of comet debris in its orbit.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.