Go Back   maemo.org - Talk > OS / Platform > Maemo 5 / Fremantle
 
Register FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools
  #1  
Old 2010-01-18, 11:29
Venomrush Venomrush is offline
 
Join Date: Nov 2009
Location: UK
Posts: 891
Thanks!: 10
Thanked 499 Times in 207 Posts
Default IM, Email Passwords Are Stored as Plain Text

See bug 8146
__________________
Follow me on Twitter
Reply With Quote
The Following 10 Users Say Thank You to Venomrush For This Useful Post:
  #2  
Old 2010-01-18, 11:34
Hexagoon Hexagoon is offline
 
Join Date: Dec 2009
Location: Sweden
Posts: 84
Thanks!: 12
Thanked 96 Times in 26 Posts
Default Re: Warning - Exploit found, keep N900 to yourself until it's fixed!

Well, this doesn't seem to apply to my device. Isn't this only if you've taken a full backup?
Reply With Quote
  #3  
Old 2010-01-18, 11:35
slender slender is offline
 
Join Date: Dec 2009
Location: Finland
Posts: 2,829
Thanks!: 2,124
Thanked 1,459 Times in 856 Posts
Default Re: Warning - Exploit found, keep N900 to yourself until it's fixed!

file:///home/user/.rt-accounts/accounts.cfg
could not find there but here:
file:///home/user/.rtcom-accounts/accounts.cfg
Reply With Quote
  #4  
Old 2010-01-18, 11:36
Hexagoon Hexagoon is offline
 
Join Date: Dec 2009
Location: Sweden
Posts: 84
Thanks!: 12
Thanked 96 Times in 26 Posts
Default Re: Warning - Exploit found, keep N900 to yourself until it's fixed!

Oh.. now i see... That's just plain stupid...
Reply With Quote
  #5  
Old 2010-01-18, 11:41
torpedo48 torpedo48 is offline
 
Join Date: Dec 2009
Posts: 489
Thanks!: 96
Thanked 404 Times in 167 Posts
Default Re: Warning - Exploit found, keep N900 to yourself until it's fixed!

Very nice catch, already verified that

file:///home/user/.rtcom-accounts/accounts.cfg

in Web let me know all my friends' IM passwords in their N900.
Reply With Quote
  #6  
Old 2010-01-18, 11:41
MartinNZ MartinNZ is offline
 
Join Date: Dec 2009
Posts: 71
Thanks!: 24
Thanked 49 Times in 14 Posts
Default Re: Warning - Exploit found, keep N900 to yourself until it's fixed!

also I've noticed that the autocomplete function caches my passwords too. Yesterday a frend of mine was composing an email with my N900 and the device suggested my passwords to him. Grr
Reply With Quote
The Following 2 Users Say Thank You to MartinNZ For This Useful Post:
  #7  
Old 2010-01-18, 11:42
slux slux is offline
 
Join Date: Jan 2010
Posts: 68
Thanks!: 22
Thanked 24 Times in 15 Posts
Default Re: Warning - Exploit found, keep N900 to yourself until it's fixed!

Well, to put things into perspective I believe that not having them there in plaintext would only serve as making it slightly more difficult to do this as the software still has to decrypt and send the passwords when logging in and it would not be a major problem to snatch them if you have physical access to the system said software is running on.
Reply With Quote
  #8  
Old 2010-01-18, 11:43
HeinzHarald HeinzHarald is offline
 
Join Date: Jan 2010
Location: Varberg, Sweden
Posts: 18
Thanks!: 6
Thanked 3 Times in 2 Posts
Send a message via ICQ to HeinzHarald Send a message via MSN to HeinzHarald
Default Re: Warning - Exploit found, keep N900 to yourself until it's fixed!

Quote:
Originally Posted by slender View Post
could not find there but here:
file:///home/user/.rtcom-accounts/accounts.cfg
I just tried that and as far as personal information goes it only contained my login, not password (never taken a backup if that were to make a difference).
Reply With Quote
  #9  
Old 2010-01-18, 11:45
slender slender is offline
 
Join Date: Dec 2009
Location: Finland
Posts: 2,829
Thanks!: 2,124
Thanked 1,459 Times in 856 Posts
Default Re: Warning - Exploit found, keep N900 to yourself until it's fixed!

Quote:
Originally Posted by HeinzHarald View Post
I just tried that and as far as personal information goes it only contained my login, not password (never taken a backup if that were to make a difference).
i have skype and google talk installed and it seems like i have google talk passowrd in plain text.

.edit
skype is also in plain text and i have made backup

Last edited by slender; 2010-01-18 at 11:53.
Reply With Quote
  #10  
Old 2010-01-18, 11:45
Venomrush Venomrush is offline
 
Join Date: Nov 2009
Location: UK
Posts: 891
Thanks!: 10
Thanked 499 Times in 207 Posts
Default Re: Warning - Exploit found, keep N900 to yourself until it's fixed!

Quote:
Originally Posted by MartinNZ View Post
also I've noticed that the autocomplete function caches my passwords too. Yesterday a frend of mine was composing an email with my N900 and the device suggested my passwords to him. Grr
Think it's already been reported and was fixed in PR1.1?
__________________
Follow me on Twitter
Reply With Quote
The Following User Says Thank You to Venomrush For This Useful Post:
Reply

Tags
conversations, debate, email, fremantle, instant message, instant messaging, maemo, maemo 5, modest, password, passwords, plain text, security, telepathy


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 18:31.