Hack pin verification idea - Security Discussion

Hi,
If I'm using an smartphone with the bootloader unlocked, is it possible to flash a custom rom with the pin verification disabled (bypass the verification or remove the functionality from the code) ?
No bad intentions here, just a question to worry about the security of an unlocked phone.
Sent from my Nexus 4 using XDA Free mobile app

malukiz said:
Hi,
If I'm using an smartphone with the bootloader unlocked, is it possible to flash a custom rom with the pin verification disabled (bypass the verification or remove the functionality from the code) ?
No bad intentions here, just a question to worry about the security of an unlocked phone.
Sent from my Nexus 4 using XDA Free mobile app
Click to expand...
Click to collapse
Please, illegal options no.

malukiz said:
Hi,
If I'm using an smartphone with the bootloader unlocked, is it possible to flash a custom rom with the pin verification disabled (bypass the verification or remove the functionality from the code) ?
No bad intentions here, just a question to worry about the security of an unlocked phone.
Sent from my Nexus 4 using XDA Free mobile app
Click to expand...
Click to collapse
I think your saying can someone flash a rom over your rom, on which you have security lock, and then gain access by having the lock removed?
Let's say it's good practice to wipe before you flash and if one did that then there wouldn't much point of flashing a rom with security lock removed. Otherwise one would do a dirty flash and most likely end up in boot loop.
I would hope it should not be possible to remove that security feature without wiping the phone and making such and endevour useless to begin with.

MunkinDrunky said:
I think your saying can someone flash a rom over your rom, on which you have security lock, and then gain access by having the lock removed?
Let's say it's good practice to wipe before you flash and if one did that then there wouldn't much point of flashing a rom with security lock removed. Otherwise one would do a dirty flash and most likely end up in boot loop.
I would hope it should not be possible to remove that security feature without wiping the phone and making such and endevour useless to begin with.
Click to expand...
Click to collapse
Thx MunkinDrunky for explanation.
http://www.groovypost.com/howto/android-disable-change-pin-code/
Yeah but the guy can easy change the pin code and do what he want with your phone number even if he wipe the phone.

malukiz said:
Hi,
If I'm using an smartphone with the bootloader unlocked, is it possible to flash a custom rom with the pin verification disabled (bypass the verification or remove the functionality from the code) ?
No bad intentions here, just a question to worry about the security of an unlocked phone.
Sent from my Nexus 4 using XDA Free mobile app
Click to expand...
Click to collapse
no

malukiz said:
Thx MunkinDrunky for explanation.
http://www.groovypost.com/howto/android-disable-change-pin-code/
Yeah but the guy can easy change the pin code and do what he want with your phone number even if he wipe the phone.
Click to expand...
Click to collapse
That is totally different that what I thought you were talking about (lock screen security) plus that walk through requires you know your old pin to change It.

Related

Unlock question

Hello everyone i need some help. I got verizon s3 from ebay and when i turn it on theres opened lock shows on screen with the word unlocked on the bottom. What is it stands for and how can i get rid of it? Everytime i search on google i get discussions about bootloader. Is that what it is? Thanks up front for any info.
Sent from my SAMSUNG-SGH-I317 using xda premium
Leo2005 said:
Hello everyone i need some help. I got verizon s3 from ebay and when i turn it on theres opened lock shows on screen with the word unlocked on the bottom. What is it stands for and how can i get rid of it? Everytime i search on google i get discussions about bootloader. Is that what it is? Thanks up front for any info.
Sent from my SAMSUNG-SGH-I317 using xda premium
Click to expand...
Click to collapse
Try to reboot couple times, make sure the message is legit. If it is, unlock means your phone is unlock (bootloader unlocked), which means you could flash custom rom/kernel etc... It's a good thing for people who like to play with custom rom.
Well...thats for my girl who doesnt want any custom rom and dont want to have any extra signs. My note 2 from att has a custom rom and doesnt show any signs on boot. Is this lock for verizon only? Thanks for reply.
Sent from my SAMSUNG-SGH-I317 using xda premium
buhohitr said:
Try to reboot couple times, make sure the message is legit. If it is, unlock means your phone is unlock (bootloader unlocked), which means you could flash custom rom/kernel etc... It's a good thing for people who like to play with custom rom.
Click to expand...
Click to collapse
Of the bootloader is unlocked then the screen week quickly flash. Not show unlocked I would guess it means dim unlocked.
Sent from my SCH-I535 using xda app-developers app
bootloader
The unlocked icon means that the boot loader is unlocked. This is what show up on all Verizon smartphones that have the boot loader unblocked. This is actually a good thing as it will allow you to use a custom ROM, set root privileges, and delete the garbarge-ware that is included on you phone that you probably will never use.
1seniorgeek said:
The unlocked icon means that the boot loader is unlocked. This is what show up on all Verizon smartphones that have the boot loader unblocked. This is actually a good thing as it will allow you to use a custom ROM, set root privileges, and delete the garbarge-ware that is included on you phone that you probably will never use.
Click to expand...
Click to collapse
No on the s3 if the boot loader is unlocked the initial screen with only Samsung will flash very quickly.
If it boots and the Samsung shows and has an unlocked lock that says custom under it, then you have a modified system WITH A LOCKED BOOT LOADER. By unlocking the boot loader this will go away.
I have no idea what the lock with unlocked under it means; however if you're sortied about it OP go into the development thread and follow droidstyle's guide to restore it back to bone stock.
Sent from my SCH-I535 using xda app-developers app
Sounds more likely about sim card. I flashed the phone back to stock because it was freezing all the time then did factory reset and its asking for activation. Tried to activate at the store and it doesnt activate...freezing up after couple min. So i guess it is something to do with sim unlock?
Sent from my SAMSUNG-SGH-I317 using xda premium
It means there is custom software on the phone, but the bootloader is NOT unlocked.
The custom software could be as simple as having Root access, or it could be a full custom ROM. You have two options to make it go away:
1) Unlock your Bootloader
2) Return to fully stock. http://forum.xda-developers.com/showthread.php?t=1867253

[Q]unlock bootloader in status "not allowed"

Hi there... I have some questions about the boatloader, My phone is already yet roted by a apk named "framaroot" but if I want to flash a kernel o a new room I need to get a recovery menu.
In sample words how I can fully unlock my phone, I read something about a "TA " for to not void the warranty.
please tell whith full details, what I neeed to do.
Thanks
Sent from my C2104 using XDA Premium 4 mobile app
If it says not allowed ,you can't unlocked them and can't flash a custom kernel right now and your sort of stuck. Maybe in the future, there will be a recovery kernel for our phones but some of the devs have tried and ran into problems, so you might not either.
Depends on the carrier you bought it from if they allow bootloader unlock or not. Yours doesn't.
getochkn said:
If it says not allowed ,you can't unlocked them and can't flash a custom kernel right now and your sort of stuck. Maybe in the future, there will be a recovery kernel for our phones but some of the devs have tried and ran into problems, so you might not either.
Depends on the carrier you bought it from if they allow bootloader unlock or not. Yours doesn't.
Click to expand...
Click to collapse
If we pay to the carrier to remove the sim lock the bootloader will pass to allowed?
My phone is free, not have SIM lock
Sent from my C2104 using XDA Premium 4 mobile app
Have you tried flashing another ftf file from another country? (backup TA first) then try unlocking
Sent from my C2105 using xda premium
Non, i only try root with successfully result.

In what cases do i lose ota featured??

Does unlock bootloder or root or installing custom recovery make me lose cm ota updates???
Sent from my GT-I9082 using XDA Premium 4 mobile app
No they don't. Cm can reinstall its recovery and you'll just lose root when you OTA.
if you can i want to root my opo without unlocking bootloadre and i'm on 30o update and nothing seem to work , can you tell me what to do?
m.omdaa said:
if you can i want to root my opo without unlocking bootloadre and i'm on 30o update and nothing seem to work , can you tell me what to do?
Click to expand...
Click to collapse
See http://forum.xda-developers.com/oneplus-one/help/root-unlocking-bootloader-t2820628
But on XNPH30O it is not achievable (unless something else was changed). I recommend just unlocking your bootloader, it does no harm unlocking it and having your bootloader unlocked. I've used this analogy in other threads and I'll say it again,
On a OPO (or Nexus Device or HTC), we have a way of unlocking our bootloaders without the need of a exploit to gain root access (e.g. Samsung, LG, etc). Think of it this way, since we have a OPO... you're pretty much given a key (fastboot oem unlock) to unlock the doors to your house. Don't make it difficult on yourself and break into your house through your windows when you can just unlock the door with the key you have.
Just unlock the bootloader, flash custom recovery, flash SuperSU.
You can flash OTA updates through a custom recovery of your choice.
Thanks I just rooted my opo ....thanks again
Sent from my A0001 using XDA Premium 4 mobile app
I heard somewhere that if you run ART runtime, you won't get the OTA's. Any truth to this?
Dan37tz said:
I heard somewhere that if you run ART runtime, you won't get the OTA's. Any truth to this?
Click to expand...
Click to collapse
Not to my knowledge. And even if it is, you can just switch it back to dalvik. Only takes 1 minute to switch between run times.

[Q] Should I root and/or lock my bootloader

I have a nexus 5. The bootloader is unlocked. It has stock OTA lollipop.
I have a few questions about this device. I have read this device is special in that unlocking the bootloader does not wipe the phone. Is that true? My impression is that locking the bootloader does NOT wipe the device (true for many device), correct?
My dilemma is this. I have read it is good to have a locked bootloader, but I don't want to then later unlock it if it wipes my device. I could root and lock, but I think I lose root when the next OTA update comes. I will hence be in locked without root state.
Anyway, my question is, do I need to lock it? Should I root it first? What do I do when I lose root next OTA and the bootloader is locked? This isn't a problem if unlocking the loader doesn't wipe the device.
juniper1982 said:
I have a nexus 5. The bootloader is unlocked. It has stock OTA lollipop.
I have a few questions about this device. I have read this device is special in that unlocking the bootloader does not wipe the phone. Is that true? My impression is that locking the bootloader does NOT wipe the device (true for many device), correct?
My dilemma is this. I have read it is good to have a locked bootloader, but I don't want to then later unlock it if it wipes my device. I could root and lock, but I think I lose root when the next OTA update comes. I will hence be in locked without root state.
Anyway, my question is, do I need to lock it? Should I root it first? What do I do when I lose root next OTA and the bootloader is locked? This isn't a problem if unlocking the loader doesn't wipe the device.
Click to expand...
Click to collapse
Unlocking the bootloader will wipe your device, unless you're rooted and use bootunlocker. Personally I leave my bootloader unlocked. You do loose some security though by doing this
Sent from my Nexus 9 using XDA Free mobile app
jd1639 said:
Unlocking the bootloader will wipe your device, unless you're rooted and use bootunlocker. Personally I leave my bootloader unlocked. You do loose some security though by doing this
Sent from my Nexus 9 using XDA Free mobile app
Click to expand...
Click to collapse
I guess it would help to know the security risks.
I only install apps from the play store, and usually only ones with a huge amount of traffic.
juniper1982 said:
I guess it would help to know the security risks.
I only install apps from the play store, and usually only ones with a huge amount of traffic.
Click to expand...
Click to collapse
The security risk is if you lost your phone or it's stolen. With an unlocked bootloader it's easier to get to the contents of your phone. But if you don't use a pin or pattern lock it wouldn't make a difference.
Sent from my Nexus 9 using XDA Free mobile app
jd1639 said:
The security risk is if you lost your phone or it's stolen. With an unlocked bootloader it's easier to get to the contents of your phone. But if you don't use a pin or pattern lock it wouldn't make a difference.
Sent from my Nexus 9 using XDA Free mobile app
Click to expand...
Click to collapse
ah right. I was thinking that if someone physically got their hands on my they could just unlock and have access to it. but of course unlock wipes it!
Ok. thanks. I get it now.

[Q] Unlock bootloader without wipe.

Hello xda friends.
How would you welcome the possibility to unlock the bootloader without wipe?
I have found two ways to do that a while ago, but first I want to ask you what do you feel about it?
I dont want to anybody to feel uncomfortable that even locked bootloader means no security to your userdata at all.
There is a reason why google implemented a full wipe after you do the fastboot oem unlock, to prevent thieves to get your data and personal infos by flashing a custom recovery then adb pulling the userdata partition.
So tell me your opinion. Depending on the feedback I decide to keep the secret or expose it to public.
You will need a windows pc to do it.
bitdomo said:
Hello xda friends.
How would you welcome the possibility to unlock the bootloader without wipe?
I have found two ways to do that a while ago, but first I want to ask you what do you feel about it?
I dont want to anybody to feel uncomfortable that even locked bootloader means no security to your userdata at all.
There is a reason why google implemented a full wipe after you do the fastboot oem unlock, to prevent thieves to get your data and personal infos by flashing a custom recovery then adb pulling the userdata partition.
So tell me your opinion. Depending on the feedback I decide to keep the secret or expose it to public.
You will need a windows pc to do it.
Click to expand...
Click to collapse
It doesn't matter for me.
It doesn't matter to me either.
Sent from my iPhone using Tapatalk
bitdomo said:
Hello xda friends.
How would you welcome the possibility to unlock the bootloader without wipe?
I have found two ways to do that a while ago, but first I want to ask you what do you feel about it?
I dont want to anybody to feel uncomfortable that even locked bootloader means no security to your userdata at all.
There is a reason why google implemented a full wipe after you do the fastboot oem unlock, to prevent thieves to get your data and personal infos by flashing a custom recovery then adb pulling the userdata partition.
So tell me your opinion. Depending on the feedback I decide to keep the secret or expose it to public.
You will need a windows pc to do it.
Click to expand...
Click to collapse
Apps for that have existed for years.
bitdomo said:
Hello xda friends.
So tell me your opinion. Depending on the feedback I decide to keep the secret or expose it to public.
You will need a windows pc to do it.
Click to expand...
Click to collapse
Release it. If the mods decide it's somehow illegal and or a serious security breach they'll let you know. It boils down to how you use the tool. Take a screwdriver. It's a perfectly legal thing to own and incredibly handy in it's intended use. Use that same screwdriver to break into some ones house and it's evidence.
Security through obscurity? No, thank you!
Expose it to us, please.
https://en.wikipedia.org/wiki/Security_through_obscurity
anyway if you can flash twrp with boarddiag tool when bootloader is still locked, then bootloder lock is nothing
RolF2 said:
anyway if you can flash twrp with boarddiag tool when bootloader is still locked, then bootloder lock is nothing
Click to expand...
Click to collapse
psst... that is secret
I say expose it. It will put pressure to have the hole closed.
the people have the "right" to know xD
well, those who want to know anyways
@bitdomo what happened with this? haha

Categories

Resources