New issue
Advanced search Search tips

Issue 756620 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: iOS
Pri: 2
Type: Bug



Sign in to add a comment

Disabled timer should be reset when the User force quit the app

Project Member Reported by jdhakshinamoor@chromium.org, Aug 17 2017

Issue description

App Version:  62.0.3187.0 canary
iOS Version:   11, 10.3.3, 9.3.5
Device:  iPad  
URL:  NA

Precondition:
Set the pass code on the device


 Steps to reproduce:
  1. Launch the app
  2.  Tap on Menu>Settings> Save Passwords
  3. Tap on the Show link
  4. Notice , it will ask to enter the pass code
  5. Type the wrong the pass code
  6. The device is disabled for 1 min
  7.  Close all tabs & Force quit the app
  8. Relaunch the app
  9.  Tap on Menu> Settings> Save Passwords
  10. Tap on Show link
    
Observed results:
Notice that User gets Disabled password screen even after the User force quit the app

Expected results:
User should not get Disabled password screen even after the User force quit the app
 
Number of times you were able to reproduce:5/5
Bug reproducible after clean install: Yes
Bug reproducible after clearing cache and cookies: Yes
Bug reproducible on Chrome Mobile on Android: NA
Bug reproducible on Safari/Firefox: Firefox:  no, Safari:  no
Bug reproducible on current stable build (App Version, iOS Version): M60 ,  NA ( New Feature)
Bug reproducible on the current beta channel build (App Version, iOS Version): M61, NA (New Feature)
Bug reproducible on Chrome desktop?  No


Link to video/image:
https://drive.google.com/a/google.com/file/d/0BwSBFDzHIX-mbVd4NVluaGQ0R2s/view

 

Comment 1 by battre@chromium.org, Aug 18 2017

Cc: vasi...@chromium.org privard@chromium.org mard...@chromium.org pschaffner@chromium.org
I think that this is working as expected. Otherwise, you can work around a security mechanism by force quitting the app. What do others think?
Seems to be working as intended to me. +Václav, just out of curiosity, is the wrong passcode "lockout" configurable (i.e. can we choose how many failed attempts before lockout occurs and/or can we configure the duration of lockout)? I'm assuming there are no APIs for this.

Comment 3 by jif@chromium.org, Aug 18 2017

Status: WontFix (was: Untriaged)
It's working as intended.
https://developer.apple.com/documentation/localauthentication/lapolicy/lapolicydeviceownerauthentication?language=objc says that there are 6 attempts and the delay between them is automatically increased. Thus, it's not configurable.
Thanks for the clarifications.

Sign in to add a comment