Bypass Password through Persistent Notification #620

Closed
opened 2025-11-26 22:23:47 -06:00 by GiteaMirror · 16 comments
Owner

Originally created by @ghost on GitHub (Jul 15, 2018).

If I double tap on the persistent notification for autofilling, I am able to access all my stored details without needing my password.

I'm using a Pixel running Android 8.1.0

Originally created by @ghost on GitHub (Jul 15, 2018). If I double tap on the persistent notification for autofilling, I am able to access all my stored details without needing my password. I'm using a Pixel running Android 8.1.0
Author
Owner

@kspearrin commented on GitHub (Jul 15, 2018):

Hi,
I tried reproducing this and was not successful. What is your lock option set to?

@kspearrin commented on GitHub (Jul 15, 2018): Hi, I tried reproducing this and was not successful. What is your lock option set to?
Author
Owner

@ghost commented on GitHub (Jul 15, 2018):

Lock after 1 minute, using my full password and not a pin, and the persist notification.

@ghost commented on GitHub (Jul 15, 2018): Lock after 1 minute, using my full password and not a pin, and the persist notification.
Author
Owner

@mesarth commented on GitHub (Jul 16, 2018):

I can reproduce this issue on my device with Android 8.1.0, persistent notification, lock after 15 minutes and fingerprint.

@mesarth commented on GitHub (Jul 16, 2018): I can reproduce this issue on my device with Android 8.1.0, persistent notification, lock after 15 minutes and fingerprint.
Author
Owner

@kspearrin commented on GitHub (Jul 16, 2018):

I was able to reproduce it with password and PIN. looking into a fix.

@kspearrin commented on GitHub (Jul 16, 2018): I was able to reproduce it with password and PIN. looking into a fix.
Author
Owner

@kspearrin commented on GitHub (Jul 16, 2018):

Can you try the latest beta on google play (1.17.2) for a possible fix. I block spam clicking the notification now. https://play.google.com/apps/testing/com.x8bit.bitwarden

@kspearrin commented on GitHub (Jul 16, 2018): Can you try the latest beta on google play (1.17.2) for a possible fix. I block spam clicking the notification now. https://play.google.com/apps/testing/com.x8bit.bitwarden
Author
Owner

@mesarth commented on GitHub (Jul 16, 2018):

Still works with the latest beta 1.17.2

@mesarth commented on GitHub (Jul 16, 2018): Still works with the latest beta 1.17.2
Author
Owner

@kspearrin commented on GitHub (Jul 16, 2018):

@Tobirexy You probably don't have the latest beta. I literally just published it so it takes a bit to roll out. It should be build number 1479

@kspearrin commented on GitHub (Jul 16, 2018): @Tobirexy You probably don't have the latest beta. I literally just published it so it takes a bit to roll out. It should be build number 1479
Author
Owner

@kspearrin commented on GitHub (Jul 16, 2018):

Could also download the raw APK from here if you want to test: https://ci.appveyor.com/project/bitwarden/mobile/build/artifacts

@kspearrin commented on GitHub (Jul 16, 2018): Could also download the raw APK from here if you want to test: https://ci.appveyor.com/project/bitwarden/mobile/build/artifacts
Author
Owner

@mesarth commented on GitHub (Jul 16, 2018):

Just tested again. Still works with build number 1479.

@mesarth commented on GitHub (Jul 16, 2018): Just tested again. Still works with build number 1479.
Author
Owner

@mesarth commented on GitHub (Jul 16, 2018):

I tested it with fingerprint.

@mesarth commented on GitHub (Jul 16, 2018): I tested it with fingerprint.
Author
Owner

@ghost commented on GitHub (Jul 17, 2018):

Tested on build number 1479, the bug still remains for me

@ghost commented on GitHub (Jul 17, 2018): Tested on build number 1479, the bug still remains for me
Author
Owner

@ghost commented on GitHub (Jul 17, 2018):

Bug also works after restarting my device without having unlocked Bitwarden yet in the session (both on beta and stable builds), concerning that it can acccess my logins without a password (I thought they'd be encrypted locally as well)

@ghost commented on GitHub (Jul 17, 2018): Bug also works after restarting my device without having unlocked Bitwarden yet in the session (both on beta and stable builds), concerning that it can acccess my logins without a password (I thought they'd be encrypted locally as well)
Author
Owner

@kspearrin commented on GitHub (Jul 17, 2018):

Can you try 1480 for another possible fix?

@xHippoCrit On Android your key is stored in the Android Keystore, so it is not required to be entered to decrypt data like in other apps without protected storage.

@kspearrin commented on GitHub (Jul 17, 2018): Can you try 1480 for another possible fix? @xHippoCrit On Android your key is stored in the Android Keystore, so it is not required to be entered to decrypt data like in other apps without protected storage.
Author
Owner

@ghost commented on GitHub (Jul 17, 2018):

Build 1480 appears to fix it for me.
@kspearrin Thanks for the explanation, it's reassuring

@ghost commented on GitHub (Jul 17, 2018): Build 1480 appears to fix it for me. @kspearrin Thanks for the explanation, it's reassuring
Author
Owner

@mesarth commented on GitHub (Jul 17, 2018):

Build 1480 fixed the issue for me too

@mesarth commented on GitHub (Jul 17, 2018): Build 1480 fixed the issue for me too
Author
Owner

@kspearrin commented on GitHub (Jul 17, 2018):

Thanks all.

@kspearrin commented on GitHub (Jul 17, 2018): Thanks all.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#620