← Back to team overview

touch-packages team mailing list archive

[Bug 1347907] Re: create a delay for password failure attempts

 

Per design:
https://docs.google.com/a/canonical.com/document/d/1VajNkWbBH61iVixXJAmOvNGiG__GWQTMXGNOZijXWJw/edit#heading=h.6zhf6wqejmh6
(search for "passcode incorrect")

They want us to factory-reset the phone after 10 failed entries.  While
this isn't a delay, it solves the same security problem of trying to
brute force the password.

** Summary changed:

- create a delay for password failure attempts
+ Factory-reset the phone after  enough failure attempts

** Branch linked: lp:~mterry/unity8/reset-after-failed-logins

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to unity8 in Ubuntu.
https://bugs.launchpad.net/bugs/1347907

Title:
  Factory-reset the phone after  enough failure attempts

Status in Ubuntu UX bugs:
  New
Status in The Unity 8 shell:
  New
Status in “unity8” package in Ubuntu:
  New

Bug description:
  capturing the desire from our security team to add in a delay for the ability to attempt unlocks on the greeter.
  unless design provides some other specification choose 5 potential failed attmepts, upon which the greeter will not unlock or allow a password entry attempt for 1 hour.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu-ux/+bug/1347907/+subscriptions