Log in

View Full Version : Security vulnerability with BatteryPack 2003


hshortt
08-26-2003, 11:28 AM
Hi guys,

Anyone using a 54xx series device with PPC2003, with fingerprint or pin authentication required AND Battery Pack version 5.x to 5.1 inclusive will have this vulnerability.

At power on, the battery pack close (x) button will be present and be pressed to bypass the authentication (tap, wait 3 seconds!), anything on the today screen can be accessed, including any programs on the program menu (if enabled).

I have reported this bug some time ago and it has yet to be fixed. This poses a fairly serious threat to devices in use with a corporate environment.

Anyone else notice this?

Thanks
Howard

Johan
09-30-2003, 05:31 PM
Anyone else notice this?

Thanks
Howard


Yes, I was just about to post about it, seriuos bug that they authors should report about! This software has a lot of nice stuff but I'm begiing to wonder if I should delete it permanetly. To many bugs.

darrylb
09-30-2003, 09:00 PM
I switched to Pocket Plus because I noticed performance degradation (of the device) with Battery Pack installed. It may have been fixed since, but I think it was something to do with the way Battery Pack queries the memory and battery.

Any who, Pocket Plus does not exibit the same behaviour, so I have switched and am quite happy.