1. gizmo21's Avatar
    I got tipped again to a phenomenon I've seen before by the post in this BlackBerry PasswordKeeper thread which originally had another topic: /blackberry-android-os-f456/password-keeper-disabling-password-startup-1103341-post12811804/

    I've seen same behaviour on other security apps, that usually blank out their minimised view in launcher, but don't when being focused open at time of display idle timeout.

    Happens for me in KeePass and Threema (and BlackBerry PasswordKeeper for others as I don't use it) which all correctly blank the minimised view in recent appview if you:

    1. manually minimise

    2. have at display timeout another app active in focus

    But if once the app is active at idle timeout it does not blank and so can possibly leak sensitive information to a third person. You even can't get this state reverted after manually *minimising it afterwards. It even shows then an old snapshot of the app content if you navigate elsewhere in the app.

    All this leads me to BlackBerry Launcher being the buggy app here, which at least is not acceptable for a company that also sees a market by releasing Privacy Shade to prevent data leakage on screen.

    It could also be Android itself, but I guess google would have fixed it by now, perhaps someone with other launcher can crosscheck:

    Open one of the mentioned apps above set in android Pref display idle timeout to 15sec. Set the security app in fullscreen with sensitive information open an wait 15sec. After that active recent app view and see if information is displayed there or a blank screen is shown.

    Data for @LiamQ , @mrbbsecurity , @Ken Wallis to reproduce:

    STV100-4 6.0.1 July secPatch QWERTZ/DE
    BlackBerry Launcher 1.1.4.7160 latest non beta

    BB Launcher possible information leak after idle timeout-1503289748587.jpg
    Last edited by gizmo21; 08-22-17 at 12:02 AM.
    Event4izon likes this.
    08-20-17 11:30 PM
  2. mrbbsecurity's Avatar
    I've seen this one reported a lot. I believe this is a core Android issue and not something Password Keeper (or even launcher) can fix. I think it's fixed on Android N.
    08-21-17 08:48 AM
  3. gizmo21's Avatar
    Sorry couldn't find anything Android specific on it via web search. Could you pass me some buzzwords to search for?

    Tried to reproduce on Nexus 5 6.0.1 with Threema and there everything is working as it should on the rollodex recent apps of vanilla android, so no info leak when the right option in threema is set and idle timeout kicks in while active.

    I'm not convinced of the core android theory, but am accepting if I'm shown otherwise.




    . I think it's fixed on Android N.
    Update: oh was that a hint that legacy devices will get N ;D
    Last edited by gizmo21; 08-21-17 at 10:22 AM.
    08-21-17 10:10 AM
  4. thurask's Avatar
    On a DTEK60, I open Password Keeper (or Lastpass), leave it open on the sensitive page, wait 15 seconds for the screen to shut off, tap the screen back on, and then go to the recent apps list (Tiles). Both Password Keeper and Lastpass blank, although this is with BB Launcher 1.1.5 if it matters. Nova Launcher 5.4 beta 3 also does the same thing.

    https://imgur.com/yHJUT1Y
    08-21-17 11:21 AM
  5. gizmo21's Avatar
    AFAIK are the DTEKs also M, so general android prob here.
    08-21-17 02:58 PM
  6. thurask's Avatar
    AFAIK are the DTEKs also M, so general android prob here.
    Have you tried another launcher?
    08-21-17 03:19 PM
  7. erose75's Avatar
    When it happens to me, it is like this: open password keeper, enter main password, go into password that I want. Leave PK open on that password screen. Screen times out. Double tap screen and PK is at main screen asking for main password, but don't enter main password. Hit the square button to minimize...that is when the last password I was in is exposed on the minimized tile.
    08-21-17 09:17 PM
  8. gizmo21's Avatar
    @erose75 Priv or DTEK? And which version of Launcher?
    08-21-17 11:47 PM
  9. erose75's Avatar
    @erose75 Priv or DTEK? And which version of Launcher?
    Apologies, I meant to include that. Factory unlocked priv on BlackBerry launcher 1.1.4.7160
    08-22-17 12:07 AM
  10. gizmo21's Avatar
    Thx, OK now we need another Priv user with beta 1.1.5 launcher that tell us no info leak and can be sure it's fixed in next release version.
    08-22-17 12:10 AM
  11. thurask's Avatar
    I can't get it to not blank using Launcher 1.1.4 on DTEK60 either.

    Maybe it's your OS build?
    08-22-17 12:15 AM
  12. erose75's Avatar
    this has not been fixed on my priv with the 1.1.5 launcher. I did a 32 second reboot after all the BlackBerry apps updated today as well.
    gizmo21 likes this.
    08-25-17 11:57 AM
  13. mrbbsecurity's Avatar
    Sorry couldn't find anything Android specific on it via web search. Could you pass me some buzzwords to search for?

    Tried to reproduce on Nexus 5 6.0.1 with Threema and there everything is working as it should on the rollodex recent apps of vanilla android, so no info leak when the right option in threema is set and idle timeout kicks in while active.

    I'm not convinced of the core android theory, but am accepting if I'm shown otherwise.
    https://issuetracker.google.com/issues/37058396
    "The issue has been fixed in latest n release"
    09-05-17 02:55 PM
  14. gizmo21's Avatar
    Thx for the info, but then there is no chance for PRIV and DTEKs?
    09-05-17 03:01 PM

Similar Threads

  1. BB Apps for Android help needed
    By EndRacism in forum General BlackBerry News, Discussion & Rumors
    Replies: 5
    Last Post: 08-27-17, 04:05 PM
  2. BB PRIV - new update failed on Aug 18, 2017
    By eranimila in forum BlackBerry Priv
    Replies: 2
    Last Post: 08-24-17, 03:50 AM
  3. Replies: 26
    Last Post: 08-22-17, 03:15 PM
  4. Replies: 1
    Last Post: 08-21-17, 03:45 PM
  5. Nova Launcher
    By Mercuryuser in forum BlackBerry KEYone
    Replies: 11
    Last Post: 08-21-17, 01:52 AM
LINK TO POST COPIED TO CLIPBOARD