jerdog · Nov 12, 2012 at 12:00 am

S-Memo Stores Google Account Passwords in Clear Text, Viewable When Rooted

There are always inherent risks when you root your device, though voiding your warranty in and of itself is not one of them, unlike what manufacturers would have you believe. Instead, the real risks are those things like having your /data partition readable by any app in the /system partition, as XDA Recognized Developer and Forum Moderator graffixnyc found out recently.

While browsing his AT&T Samsung Galaxy S3 on a lazy Saturday afternoon, graffixnyc opened the Samsung S-Memo SQLite files and found something shocking: S-Memo stored his Google account password in clear text. After posting his findings in the thread, fellow XDA Recognized Developer ViViDboarder reminded graffixnyc that since he was rooted he was able to view the contents of the SQLite files. And while this is true, graffixnyc pointed out that even though the only users affected by this are root users, the records themselves should have been encrypted.

Let this be a warning to you that if you find yourself with root on your device, be careful.  Some developers don’t take proper precautions when creating an application. They can’t be trusted to protect your credentials; only you can.

 


_________
Want something on the XDA Portal? Send us a tip!

jerdog

jerdog is an editor on XDA-Developers, the largest community for Android users. Jeremy has been an XDA member since 2007, and has been involved in technology in one way or another, dating back to when he was 8 years old and was given his first PC in 1984 - which promptly got formatted. It was a match made in the stars, and he never looked back. He has owned, to date, over 60 mobile devices over the last 15 years and mobile technology just clicks with him. In addition to being a News Editor and OEM Relations Manager, he is a Senior Moderator and member of the Developer and Moderator Committees at XDA.
Emil Kako · Mar 28, 2015 at 11:01 pm · no comments

Best Alarm App for Android?

There are tons of choices to choose from when looking for a great alarm app for Android. While the stock Clock app for AOSP does the job, it may lack some of the more advanced features from competitors. Let us know what your favorite alarm clock app is for Android and why.

DISCUSS
Chris Gilliam · Mar 28, 2015 at 12:45 pm · 1 comment

Pinsy Brings Social Sketching To Your Watch & Phone

Did you watch Apple's VP draw on his wrist during the Apple Watch announcement and wonder "why can't my Wear watch do that?" In typical XDA fashion, one enterprising forum member has brought similar functionality to Android Wear with a twist; it works on phones and watches alike, with other platforms on the way! The app is called Pinsy, and its release debut is a strong proof of concept with plenty of room to grow. You may remember the developer behind this project, XDA...

XDA NEWS
Mario Tomás Serrafero · Mar 27, 2015 at 04:13 pm · 2 comments

Should You Get Wear? Wearer’s Practical Observations

Wear is said to not offer enough for mass adoption, even though its been in the market for over 9 months. I personally have a Gear Live which I purchased 8 months ago, and my experience with it has had its ups and downs throughout my time with it. For the longest time, I was not able to recommend the platform to anyone. Since then, a lot of updates have hit Wear watches, some improving battery life, others changing the...

XDA NEWS
Share This