Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <1464523319.203145.1298555817595.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Thu, 24 Feb 2011 08:56:57 -0500 (EST)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: coley <coley@...re.org>
Subject: Re: Pattern lock bypass on SE X10 with Android 1.6



----- Original Message -----
> Would something like http://www.nth-dimension.org.uk/blog.php?id=89
> qualify for a CVE? I didn't really consider it when I published it
> because I was working on the principal that it required physical access
> and you could therefore argue that all bets are off but I was was
> wondering in the light of the recent discussions about auto mounting bugs
> which share a similar quality.
> 

I'll leave this up to MITRE, but in my opinion, phones are a different
story. The whole reason I lock my phone is because it's so easy for an
attacker to get access to it. The thoughts of someone grabbing your desktop
and running down the street with it is laughable, but I suspect this
happens with phones many times every single day.

I'm expecting the whole mobile security paradigm to change quite a lot in
the near future as people start to focus there. There's a lot of low
hanging fruit.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.