Android Security Flaw Unlocks Phone

by Rod on January 25, 2010

I never fully understood the importance of the GMail account configured on your Android phone until I was talking to my friend at a party saturday night. His daughter was playing with his DROID connecting the dots on the home screen. He was unaware she had the phone and was continuously submitting bad passwords at the lock screen. When he picked up the phone sometime later it said please enter you GMail account name and password. He was a bit alarmed because as many Android users, he was not originally a GMail customer. In fact, when the phone was setup, the Verizon rep forced him into creating a GMail account (which is not required) but never explained the importance of the account.

Locked and GMail is the Key

Needless to say he was presented with a screen to unlock his phone.  While he knew what the password for the account would be he had no clue what the GMail account username was as he only set it up to start using the phone and the account name as suggested as his desired account name was taken. The only option presented by Verizon was to erase all data, which of course was not a valid option. Who wants to lose all there data?  Verizon did suggest Google could help if he knew the “Linked Account” for his Gmail account. Again he was confused as he did not understand what a “Linked Account” was. Verizon explained “the linked account” is the alternate email account you have linked to your GMail account” in the event you forgot your password. Well great except fot the fact that the linked/alternate email account can only be set in the GMail interface which he had never used. It was at this time that hoplessness started to set in. He felt he was screwed. He got the phone on December 15, set it all up, and in less than 2 weeks he was totally hosed.

Hope in a Security Flaw

While he could answer incoming calls, he thought he had no access to his phone. This is one time that it is great Google’s Phone Lock security is as flawed as the iPhone security in general. As most people should know, there is a flaw in the Phone lock on Android that allows you to gain full access to a locked phone by just knowing the phone number. All he had to do was :

1. Call the phone

2. Click the back button

3. Full Phone Access

No GMail Account Required

I am sure Google will consider this a flaw as there is no way this working “as designed”.  Anyone concerned with security should hope they fix this gaping hole. As far as my friend was concerned it was a great relief for him. He was able to fully navigate the phone and find the GMail account name and unlock his phone. All I can say is if you do not understand how important the GMail account is associated with your Android Phone please take this as a warning and make sure you remember this process should you ever run into this emergency situation. More importantly anyone considering getting a DROID you do not have to use a GMail account!  There are countless benefits of using a GMail account and I suggest you create on and document the account.  That said if Verizon actually let the customer go through the setup screens you would quickly see that the prompt for a GMail account allows you to skip this section.  I guess forcing the 250,000 Droid user to create GMail accounts is Verizons way of helping GMail gain new users.

{ 1 trackback }

Nexus One Gets Updated Droid Remains Buggy | Simple Mobile Review
February 3, 2010 at 7:34 am

{ 2 comments… read them below or add one }

Thomas Martin January 25, 2010 at 6:25 am

You had to bring up that old iPhone flaw. It is amazing how a simple big like this gets out. I am sure Google will say it was an IE bug.

Reply

Chris January 25, 2010 at 9:32 am

Now that’s funny!!

Reply

Leave a Comment

Previous post:

Next post: