Skip to main content

Trying to hack an Android? Just keep typing random letters

Gigaset Android phones
Andy Boxall/Digital Trends
To the average, untrained, movie-watching layman, the process of hacking into a phone or computer system may just seem like a lot of rapid and random typing, with hopes of accidentally cracking some secret code. Unfortunately, when it comes to the Android Lollipop operating system, that’s actually all it takes to bypass the lockscreen — just keep entering random letters, and eventually, you’ll overload the phone and proudly label yourself a successful cellphone hacker.

“By manipulating a sufficiently large string in the password field when the camera app is active, ” John Gordon of the University of Texas at Austin said, “An attacker is able to destabilize the lockscreen, causing it to crash to the home screen.” Yikes.

This rather alarming vulnerability, recently discovered by researchers at the University of Texas in Austin, is said to affect around 21 percent of phones, but only those running Lollipop, and only those with a text password. Users who employed PINs or pattern locks did not face the same issue (though these sorts of passwords certainly come with issues of their own).

Gordon told Slate that he discovered the vulnerability by complete accident while playing with his phone during a lengthy road trip. “I’m sitting in the passenger seat, bored, with no signal on my phone, so I start poking around and seeing what unexpected behavior I can cause,” he said. “A few idle hours of tapping every conceivable combination of elements on the screen can do wonders for finding bugs.”

Happily, Google has already rolled out a patch for affected devices, including the Nexus 4, 5, 6, 7, 9, and 10. Still, other phone makers will need to distribute the appropriate software to their own devices to ensure a complete fix to the issue.

The problem, while not particularly widespread, certainly seems like a significant cause for concern, as one would hope that today’s phones are sophisticated enough to withstand “attacks” that are little more than a system overload generated by, well, lots of letters. After hacking into the phones, researchers at UT were able to access everything available on them, including data, applications, photos, and more.

Of course, the hackers would need to have physical access to your phone in order to do any damage, and you could avoid the situation altogether by simply implementing a PIN or pattern to protect your phone, but still, this latest revelation doesn’t exactly inspire faith in the software.

That being said, ExtremeTech points out that there really isn’t anything to worry about, and that such vulnerabilities are discovered and subsequently addressed relatively frequently. As Ryan Whitwam writes, “This is how software patches work when handled responsibly — an issue is reported, a patch is issued, and the method is disclosed. There’s nothing unusual about this flaw, and there aren’t millions of phones out there with broken lock screens. Don’t believe the hype.”

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
An Android phone you haven’t heard of just won the charging game
Infinix Note 40 Pro Plus with MagSafe green-colored compatible vegan leather case kept on a table.

Infinix is an underdog phone brand that's slowly gaining momentum in developing nations. It offers a variety of low-spec and midrange phones with premium designs and features at astoundingly low prices. That continues with the newest midrange series, the Infinix Note 40, which packs some unusual perks, most notably frictionless charging.

The series' top-of-the-line Note 40 Pro+ is crammed with features you wouldn't otherwise find on other sub-$300 phones. Among them is a 120Hz curved AMOLED display with an in-display fingerprint scanner, built-in AI features, dual speakers tuned by JBL, a super-slim profile with a vegan leather finish and gold accents, and wildly fast 100-watt wired charging.

Read more
Samsung just launched a secret Android tablet
Three Samsung Galaxy Tab S6 Lite 2024 tablets next to each other, in mint, pink, and black.

Samsung just launched a new Android tablet, but you probably didn't know anything about it. That's because the company has quietly released a new version of the Galaxy Tab S6 Lite in Romania, and it's done so without any fanfare — no launch event, trailer, press release, or anything.

The 2024 model of the Galaxy Tab S6 Lite is now listed on Samsung's Romanian website. Although we don't know how much it costs — or if/when it's coming to other markets — we do know what the tablet looks like and what specs it's packing.

Read more
A new Android 15 update just launched. Here’s everything that’s new
Android 15 logo on a Google Pixel 8.

Less than a month ago, Google formally announced Android 15 and released the first developer preview for the software update. Now, Google is rolling out Android 15 Developer Preview 2 — and with it — a few new features that weren't in Developer Preview 1.

So, what's new in this second developer preview? Here are the biggest things to keep an eye out for.
New satellite connectivity features

Read more