jerdog · Nov 12, 2012 at 12:00 am

S-Memo Stores Google Account Passwords in Clear Text, Viewable When Rooted

There are always inherent risks when you root your device, though voiding your warranty in and of itself is not one of them, unlike what manufacturers would have you believe. Instead, the real risks are those things like having your /data partition readable by any app in the /system partition, as XDA Recognized Developer and Forum Moderator graffixnyc found out recently.

While browsing his AT&T Samsung Galaxy S3 on a lazy Saturday afternoon, graffixnyc opened the Samsung S-Memo SQLite files and found something shocking: S-Memo stored his Google account password in clear text. After posting his findings in the thread, fellow XDA Recognized Developer ViViDboarder reminded graffixnyc that since he was rooted he was able to view the contents of the SQLite files. And while this is true, graffixnyc pointed out that even though the only users affected by this are root users, the records themselves should have been encrypted.

Let this be a warning to you that if you find yourself with root on your device, be careful.  Some developers don’t take proper precautions when creating an application. They can’t be trusted to protect your credentials; only you can.

 


_________
Want something on the XDA Portal? Send us a tip!

jerdog

jerdog is an editor on XDA-Developers, the largest community for Android users. Jeremy has been an XDA member since 2007, and has been involved in technology in one way or another, dating back to when he was 8 years old and was given his first PC in 1984 - which promptly got formatted. It was a match made in the stars, and he never looked back. He has owned, to date, over 60 mobile devices over the last 15 years and mobile technology just clicks with him. In addition to being a News Editor and OEM Relations Manager, he is a Senior Moderator and member of the Developer and Moderator Committees at XDA. View jerdog's posts and articles here.
TK · May 21, 2015 at 02:15 pm · 1 comment

Device Review: No.1 X1 Rugged Smartphone

We are almost at the end of Q2 for 2015, and we have seen most of the flagship phones for the year already. While flagship phones usually offer bleeding-edge specs and are the most sought after phones, there is a huge market for non-flagship phones. Some offer value, others offer unique differentiating features. Today, we are going to look at the X1 phone by a Chinese company named N0.1. The company promises a truly rugged IP68 Certified phone. The device has a Quad...

XDA NEWS
Emil Kako · May 21, 2015 at 01:10 pm · 4 comments

When a Friend or Family Member Asks for a Phone Recommendation, What Do You Tell Them?

The majority of us here at XDA would consider ourselves power users and Android enthusiasts. Thus, when a friend or family member has a question about which phone they should get, they usually come to us. However, this is where we all differ. While some will atomically recommend the Nexus line, others in the community will suggest an offering from Samsung or LG. When a friend or family member asks you for a phone recommendation, what do you say?

DISCUSS
Chris Gilliam · May 20, 2015 at 04:08 pm · 7 comments

Nexus 4, 5, and 9 OTA Downloads of 5.1.1

This month was a big one for Android 5.1.1 updates, as you can see from last week's roundup and the barrage of posts on the portal's front page in the recent past. So far we are seeing the lineup of Wear watches, the Nexus 4, Nexus 9, Nexus 10, Nexus Player, and a handfull of others slowly make their way to the latest Android. While waiting around for updates may be fine for casual users, this is XDA; we have OTA download links...

XDA NEWS
Share This