• Home
  • Reviews
  • Featured
  • Archives
  • Videos
  • Devices
  • Tegra
  • Send Tips
  • Contact
  • AndroidCommunity on Twitter AndroidCommunity on Facebook AndroidCommunity on Google+ AndroidCommunity RSS Feed

Android Community

    • MUST READ

      STORIES

    • Otterbox Defender and Commuter GALAXY S 4 case hands-on

      May 20, 2013

    • Verizon HTC One reality returns as DROID DNA offer pops up

      May 20, 2013

    • Student wins science fair with 30-second phone battery charger

      May 20, 2013

  • Trending Topics
  • Jelly Bean
  • NVIDIA
  • Galaxy S 4
  • HTC One
  • Nexus 7
  • Sell Your Used Phone

XDA developers discover S Memo saves passwords in plain text

2
  • By Eric Abent
  • on 12 Nov, 2012

XDA developers discover S Memo saves passwords in plain text

If you use S Memo and happen to have a rooted device, you might want to pay attention to this next bit of news: one XDA Developers Forum member has discovered that S Memo stores Google user names and passwords in plain text. He happened upon this while he was going through his SQLite files on his Samsung Galaxy S III, and promptly took to the Developers Forum to talk about it. Another user, one ViViDboarder, replied saying that those files can only be viewed if the device is rooted and would otherwise be inaccessible.


So, those who haven’t rooted their devices can breathe a sigh of relief, as this is only an issue for those who have rooted their Samsung handset. It seems that rooted users make up a pretty large subset of all Android users though, so there’s still plenty of people who could be affected by this security issue. This could potentially lead to root apps gaining access to these files and making off with the information, though ViViDboarder says that would be difficult “without asking for root or cracking root itself.”

Be that as it may, this is still a pretty scary discovery. We’ve always known that there are some security risks that go along with rooting your phone, but this just serves as reinforcement that those who root their device need to tread carefully. That goes for installing root apps too – if you don’t check out the app yourself before installing, it could lead to some pretty major headaches.

It’s also kind of alarming that S Memo doesn’t encrypt this information, but it makes at least some sense if Samsung’s expectation is that most users aren’t going to root their phones. In any case, it seems like that’s the kind of information that should be encrypted, even if it is inaccessible on non-rooted devices. Be sure to have a look at the full thread over at the XDA Developers Forum for more information!

[via Talk Android]
Share
  • Student wins science fair with 30-second phone battery charger
  • Hisense Sero 7 Pro with Tegra 3, Android 4.2 takes on Google's Nexus 7
  • Verizon HTC One reality returns as DROID DNA offer pops up

Tags: Mobile SecurityrootSamsungsecurity

  • http://twitter.com/robber32 Robb Nice

    If you are a person who roots their phone it pays to deal with developers who removed a lot of the Sammy bloatware, or used ASOP roms.

  • tripper

    Wow, this is a major fail. And it doesn’t matter that this file is inaccessible without root. Gaining root access is what malicious code does and this little file contains a very delicious piece of data that may be targeted by such malicious code. You won’t even notice.

    And I seriously see no reason to store this kind of data in plain text. What this tells me is that the developers behind S Memo are amateurs, that’s what.

  • Search

  • REVIEWS

    • AT&T LG Optimus G Pro ReviewAT&T LG Optimus G Pro Review
    • Iron Man 3 game Review: what you need to knowIron Man 3 game Review: what you need to know
    • Samsung GALAXY S 4 ReviewSamsung GALAXY S 4 Review
    • Samsung Galaxy Note 8.0 ReviewSamsung Galaxy Note 8.0 Review
    • Pebble review: Two weeks with a smartwatchPebble review: Two weeks with a smartwatch
  • HANDS-ON & QUICK LOOKS

    • Google+ Hangouts app goes live, we go hands-onGoogle+ Hangouts app goes live, we go hands-on
    • Flipboard magazines arrive with v2.0 update, we go hands-onFlipboard magazines arrive with v2.0 update, we go hands-on
    • Lenovo IdeaCentre Horizon hands-on with BlueStacks for Android gamingLenovo IdeaCentre Horizon hands-on with BlueStacks for Android gaming


  • T-Mobile G1 Accessories
  • RECENT COMMENTS

  • About
  • Contact
  • Terms of Use
  • Privacy Policy
  • Advertise

Copyright 2013 Android Community