Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Widgets] Possible to see any note content with passcode active #1445

Open
pachlava opened this issue Sep 22, 2021 · 5 comments
Open

[Widgets] Possible to see any note content with passcode active #1445

pachlava opened this issue Sep 22, 2021 · 5 comments
Labels
bug Something isn't working. [feature] Widgets

Comments

@pachlava
Copy link
Contributor

I'm not exactly sure this is a bug. By adding widgets, the user already takes a step back from their notes privacy.

Expected

Again, it's hard to say it's definitely expected. This is something that wasn't an option before.

If the user has a passcode active, previously it meant that notes can't be viewed without knowing the password. Now it's possible with widgets.

Observed

Note widget will allow to change the note selected for display without asking for passcode (first seconds are just showing the app has a passcode active):

IMG_3626.MP4

Reproduced

  1. Activate passcode in the app
  2. Add a Note widget
  3. Kill the app to make sure passcode will be required from now on
  4. You can change the note selected for display in Note widget (and see the note), which bypasses the need to enter a passcode to see the note.
Make Model iOS Version App Version
iPhone XR 14.7.1 4.45.0.0
@pachlava pachlava added bug Something isn't working. [feature] Widgets labels Sep 22, 2021
@jleandroperez
Copy link
Contributor

@pachlava (Hey there sir!!). I'm not sure there's anything we should do on this one, since we can't add a passcode to the widget, and the user has to willingly set it up first.

IMHO we should probably close this one, WDYT?

@pachlava
Copy link
Contributor Author

@jleandroperez Hey! 👋 I agree this is an edge case, and I'm good with having it closed, just wanted to communicate about this case and be sure it's not something critical. Thanks!

@jleandroperez
Copy link
Contributor

Thank you sir!!

@adamjohndaly
Copy link

An important point about widgets:

When this was discussed before it was closed on the basis that having the widget is optional and the user is accepting the security bypass. However, despite access to Widgets being switched off in my iOS settings for Simplenote, on my MacBook, in Edit Widgets, all of the Simplenote widgets appear, complete with note text for the most recent note, and the names of the last 8 notes! This is BEFORE choosing to add the widget. That is therefore NOT a user-selected feature and I cannot stop it happening. I am using Sonoma 14.1. What can be done to prevent this?

https://forums.simplenote.com/forums/topic/security-flaw-in-widgets/?view=all#post-1440

@adamjohndaly adamjohndaly reopened this Nov 23, 2023
@jimlearning
Copy link

jimlearning commented Jun 28, 2024

Can we add a "Not displayed in Widgets" switch to every note settings? In this way, the notes that we don't want to show can be filtered out.

Or can we make the widget shown like before login? If the app has set password, just show the text "Tap in to see your notes".

The last method is much easier than the first.

I think it's very important. If password-protected notes can be seen, then the password feature will be meaningless.

IMG_7579
IMG_7580
IMG_7581

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working. [feature] Widgets
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants