Android Password Vulnerability - Atrix 4G General

So I was bored today and started digging around and happen to find something that is particularly disturbing IMO. Most settings for apps and system are stored in databases of course. Not going to name which particular files contain this but the passwords for pretty much all my accounts and various things are stored in plain text. With that said one could easily create script to drop on someone phone and pull all of their user names and passwords. This is a huge security flaw that could expose everyone's account information easily. Does anyone know if there is way we can get this information encrypted?
Sent from my MB860 using XDA Premium App

playin4sheezy said:
So I was bored today and started digging around and happen to find something that is particularly disturbing IMO. Most settings for apps and system are stored in databases of course. Not going to name which particular files contain this but the passwords for pretty much all my accounts and various things are stored in plain text. With that said one could easily create script to drop on someone phone and pull all of their user names and passwords. This is a huge security flaw that could expose everyone's account information easily. Does anyone know if there is way we can get this information encrypted?
Sent from my MB860 using XDA Premium App
Click to expand...
Click to collapse
1) If you're out and about set a password
2) With the password set, turn off usb debuging

I'm confused. Please elaborate
Sent from my MB860 using XDA Premium App

Bravo: i think what he's trying to say is that if someone somehow made an app that also for some strange reason had access to that file... anyone installing that app would basically be voluntarily handing out their account details.

Wouldnt this be more of a MotoBlur issue? Since MotoBlur is the one that handles all that Facebook, Twitter, Myspace, Picasa, Photobucket, Email Accounts. I mean it is build into the phones custom UI.

Ok I must confirmed that also aosp email app does the same thing. I froze blur email and loaded gingerbread email and out shows the login info for my gmail and work exchange account
Sent from my MB860 using XDA Premium App

well to be honest you need root to get this files, and yes use sqlite in market version and you can see ALL apps and password , you can even edit it so maybe i will worry when you can have access to this without root. this isnt new, even you can check wpa_suplicant and check wifi password if you dont remember

Related

[Q] Are multi user logins possible on honeycomb?

I was thinking how great it would be to have home and work logins for different gmail accounts, apps, voice, etc. Even others such as one for my daughter, wife, guests? Does this exist and did I miss it in my search results?
Thanks in advance! Don't be too harsh if its a boneheaded question.
It don't exist but I agree it would be awesome.
Maybe someday... Google wink*wink*
Sent from my Xoom using XDA App
yeah it would be a nice feature but adds a lot of complexity to the OS and also to App purchases.
I know right now LG and VMware are working on a project together where you can basically run a virtual machine on your android device. I think this is due out later this year as they had a demo in December. So, once it is available for the LG, I am sure some smart people will port it over.
Sent from my Xoom using XDA Premium App
Inphinitizeit said:
yeah it would be a nice feature but adds a lot of complexity to the OS and also to App purchases.
Click to expand...
Click to collapse
I don't see why, except to the os. But it would still be the same UDID so the apps would stay on the phone.
It would just basically make different folders that would save the shorcuts for the homesceeen and allow you to save specific files and settings for different accounts.
Think of windows.
User settings
C\Users
And apps and drm protection settings
C:\Program Files
Apps would be fine, but it would take up space. I don't exactly know the specifics of designing it into an os.
Sent from my Xoom using XDA App
Honeycomb does support multiple logins for apps like gmail, calendar, and contacts. My wife and I currently have both our google accounts on the Xoom and it works great. There is just a drop down up in the top right corner where you can select between the account. Hope this helps.
Sent from my Xoom using XDA App
i"d love this, as my wife could have a diff set of shortcuts on her homescreen, Smartkeyboard as her default input device, and the locale set to Japan.
Anyone who pulled this off would get a purchase from me hands down.
I wish there is the same for Facebook app
Nvious1 said:
Honeycomb does support multiple logins for apps like gmail, calendar, and contacts. My wife and I currently have both our google accounts on the Xoom and it works great. There is just a drop down up in the top right corner where you can select between the account. Hope this helps.
Sent from my Xoom using XDA App
Click to expand...
Click to collapse
well it looks like interest is there. I too was thinking along the widows users folders. Ive always maintained a device between work and homed on my laptops. Different wallpaper, bookmarks, personal email seperate from business. So my daughter can plant pokemon bookmarks and youtube links on the home account. Or not email someone on my business emai account.
Yeah, I'm currently trying to navigate a screen for my work, a screen for my girlfriend, and the rest just w/e. I hate the one all the way to the right as my work. Luckily my work uses an @att e-mail address, and i use firefox only for work which helps me keep my bookmarks seperate.
It would be awesome to have specific files for different users, but for now, this will have to work.
Please star this for me.
http://code.google.com/p/android/issues/detail?id=15030
I put it up a few days ago. Stars == attention
multi profiles would be a good start?
Something like firefox profiles where one could login an sync to their gmail account bookmarks, etc. Could be a start from the last post? Now if only I were talented enough to code! I'm glad to see I'm not all nuts with the idea.
found iOS has a hacked feature like this
http://vr-zone.com/articles/ios-hack-brings-multi-user-support-to-apple-s-ipad/13005.html
login SwiftKey Facebook url

Administrator accounts

Anyone know how to set this up I will be letting my girlfriend and kids use my tab so I need to be able to login an out of my accounts to keep mainly my girlfriend out of my accounts like Facebook email thanks for any help
Sent from my T-Mobile G2 using XDA App
You could try an app called Invisible Protector. You can use it to lock your apps, but instead of the app showing up as locked it will show up w/ a FC error, and you can then use several different ways to access the locked app. And the only place the Protector app shows up is in the Widgets list. They also have one (Invisible Protector II) that doesn't show up at all. You have to dial a command to get to the settings.
For example I have mine setup so that when the error pops up it gives me an option to send an error report and in the next field I just enter my password and the app loads.
Sent from my A500 using XDA Premium App
But there is administrator under settings but I can't get it setup
Sent from my T-Mobile G2 using XDA App
That administrator option under settings I believe is to enable administrator features to certain apps - for instance allow a find my phone app to enable the GPS without going through the warning dialog, or enable a wipe app to remotely wipe the entire device's memory without confirmations if you lose it.
Ok thanks that's to bad I would love to have a guest account
Sent from my T-Mobile G2 using XDA App
temekio2000 said:
Ok thanks that's to bad I would love to have a guest account
Sent from my T-Mobile G2 using XDA App
Click to expand...
Click to collapse
Thee is a developer asking for testers for just what you are asking for look in the bottom forum section for apps and themes
http://forum.xda-developers.com/showthread.php?t=1478321
I think this is the thread
Use this with a app lock program.
That being said, there is no 'non-hackish' way to do that. While the kernel supports true multiuser, the rest of the OS doesn't. The Admin stuff in the settings is for locked-down devices integrated into corporate networks (i. e. you're only allowed to use apps approved by your boss and installed by your admin and your device gets wiped if you try to get around it... though it can be made less strict)
I also use an app to lock thing down. Only I know of
Sent from my AT100 using Tapatalk
The lockdown works via certain apps that install security hooks in your device -- basically giving them the ability to remote-wipe the device or do other funny stuff without your consent. The only app I know of that acually uses this is Junos Pulse, used to access Juniper SSL VPN networks (mostly in corporate or university settings), though I guess some of the 'remote admin' capabilities of antivirus tools use the same mechanisms.
The bottom line: Your app may actually use the mechanisms I described in my earlier post. If you want to check, see settings -> location & security -> device administrators.
temekio2000 said:
Anyone know how to set this up I will be letting my girlfriend and kids use my tab so I need to be able to login an out of my accounts to keep mainly my girlfriend out of my accounts like Facebook email thanks for any help
Sent from my T-Mobile G2 using XDA App
Click to expand...
Click to collapse
I noticed this post on the Gtablet site. It looks to do what you are asking for. Read down the the last post on page 1. I have not tried it yet so cant verify whether it works or not.
http://forum.xda-developers.com/showthread.php?t=863073

[Q] How to change the initial, 'primary' account?

My son got my first HD2. What I did not know when I installed it the first time before he got it, was the fixation of the phone to the gmail-account I used at that time and only for that purpose. Intuition has its flip side too.
My son has his own gmail account, which I was not aware of, and obviously he wants to have his HD2 running his affairs on his own account (communicate with friends etc.)
Now, he has used the HD2 extensively, installed lots of apps, also some paid ones. Purging my old (installation-) account will reset the whole device to its initial state, all accounts and licences will be lost, if he understands that warning correctly.
Is there a way to change the 'ownership' with as little damage to the contents as possible, like save all contents as a backup, start with a new account identity, and restore all contents? Or will that also inevitably overwrite the new account with the old one too?
One could call the task also a migration of an android installation to a different account. BTW, it's equipped with a 16 GB card which has lots of free space left right now (looking at the backup space needs).
I am sure this has been discussed here before, but I seem to not find the right search words. Any hints, links, advice?
Would a total backup using Titanium be advisable? Or will that restore the present status including the unwanted account again?
Thanks for your help in advance. It doesn't make things simpler that my son and his HD2 are some 1.000 miles from here, studying there. but we have skype and other paths on PCs...
Cheers,
the longkeeler.
You can always use Titanium Backup to back up the apps (the paid ones, too), make a factory reset and let him set his own account and then restore the backup.
But you can never transfer the ownership of app(s) from one account to another. (For example, by using TB backup, he can use the paid apps, but he won't be able to update them, he'd need to buy them from his own account)
I'm sorry, but that is the way Android works. (which is lame)
follow-up
Clearing the primary gmail-account and thus resetting the device did not remove just that account, which kind of surprises me. Well, I don't have the HD2 in my hands, and I just hope that my son will have made the backup I advised hin to make and store it where he can reconstruct from.
Cheers,
the longkeeler.
But at least, he would have back what was there before. The nature of the paid apps is static, there are no backups to be expected. And it was not an amount of money that would kill anyone - just throwing it away should be avoided. Now, as posted a few minutes before, he was not successful to remove the undesired account. Are there any protections built in, that follow the great old MS tradition , it's not a bug, it's a feature, if not even industry standard?
it is however possible - to some extent - to "merge" google accounts.
if you do not use your gmail acc (as i understood from your first post) you can transfer quite a bit of contacts/features and stuff to your sons account and the other way round. this way he might be able to keep the paid apps (and updates) and also communicate with his friend on the dame account.
if thats any help...
Is the phone running froyo or gingerbread? If it is on Ginger then try deleting the account from sync and accounts... that's all for froyo u will need root explorer to delete a file located in the data folder.
Sent from my HTC HD2 using XDA Premium App
From accounts and sync remove the account.. I believe this only works for Ginger ..
Sent from my HTC HD2 using XDA Premium App
You can also do it by deleting this file With root explorer . Hope this helped.
Sent from my HTC HD2 using XDA Premium App
Just use your sons email and then go to accounts and sync.turn sync off. That's basically your only hope.
Sent from my HD2 using xda premium
First: Thanks to all for your replies!
Afaik, it's the gingerbread flavor.
I have the same type of HD2 here for myself but don't want to mess that up too much - I just saw under acc and synch that my account appears there once under mail and then under google.
If I remove either of those - does it only purge the link from my device to gmail resp. all other google-accounts, or does it remove the account as a whole from google's servers? (if so, probably only from the visible surface, but that's a different story...)
I am not sure if my son sees the same image and what he did there.
So again: Does "removing" the account on the smartphone just "divorce" it from google, or does it kill it?
Thanks again for your help!
Cheers,
The Longkeeler
Nieve, thank you so much. I am not sure yet if it will work but it sounds plausible. surprising how close to the surface such an essential database is located - like the rock that merged with the Costa Concordia... So, everybody just can hope that it will become easier in future to change the primary account rights.
A different side-question: What tool did you use to add the hints to the screen shots?
Extended thought, not necessarily useful for my son's problem, but: Would it be possible to cultivate different versions of the accounts.db, renaming them according to the desired application spectrum (like, say, change the "personality" of the phone from business to leisure)?
Reset device completely
With a clean device when the touch android screen comes up...
he signs in with his account. Establishes his acct as primary
then logs in with your acct secondly or later on in order to get access to the paid apps on your account
Only way to xhange primary is a wipe of data. The primary is simply the very first acccount entered after a device reset.
Your a great mom!
Sent from my Kindle Fire using xda premium
nieves53 said:
You can also do it by deleting this file With root explorer
Click to expand...
Click to collapse
Nieve, thanks. After getting root explorer 2.15 I can see into the innards now too - on my phone here, there is the accounts.db of course, and two more entries, one called accounts.db-wal and the other accounts.db-shm. Look more like folders. What about those?
androidcues said:
Your a great mom!
Click to expand...
Click to collapse
Always try to do my best, and I'll ask my wife for her opinion on this . Well, I'm just only the dad...
But your proposal sounds very reasonable and based on practice. If nieve's and your advice can be combined (purging the data base, tnen installing accs from scratch), it would be great.
accounts removed now, but no re-installation yet.
nieves53 said:
You can also do it by deleting this file
Click to expand...
Click to collapse
(\data\system\accounts.db) deleted - et voilĂ , after rebooting, no more accounts. So, step one done successfully. So, again, thanks for that!
Now came the next one, re-installing his own gmail account as a primary one. He could open the dialogue - but his entry was refused, 'sorry, username and pw don't match.' Bummer. He tried it several times, took care that the account was not opened anywhere else - no avail so far. The error message could well be misleading.
There must be a missing resp. hidden link.
Update: re-installing the prior "false" primary account worked immediately. So, the error message IS misleading. I guess there will be no other way than to completely re-initiate the whole system and then start with the other identiy. Unfortunately, the HD2 has to travel 2.000 miles for that, but it is the safest way then. My son has neither the experience nor the tools to do that himself there.
If somebody has yet another idea - please don't hesitate to let us know!
The application is call picsin, you can find it in the android market...about his account ask him to make sure his email and password are correct. I have change my accounts many times doing that process. He can maybe try login to his account thru the browser, just to make sure the email and password are right.
Sent from my HTC HD2 using XDA Premium App
SOLVED
longkeeler said:
Update: re-installing the prior "false" primary account worked immediately. So, the error message IS misleading.
Click to expand...
Click to collapse
Some times, the solution comes as a surprise. Just before my son had started his trial to rearrange the accounts yesterday, he had applied for a new login scheme with google - some double-password story. This, he had not mentioned until today, an hour ago, when he received a mail from google, giving him directions on how to handle logins in a transitional phase.
You guess it: All is well now, he has his own account as the primary one, and sounds much more relaxed than before.
Oh well...
But nevertheless: Your help was absolutely substantial in achieving this, and I hope that the bitdust will settle soon... So thanks again, I can recommend you
Cheers, and a happy rest of this weekend!
The Longkeeler, now also a bit more in weekend mood/mode.
That's good to hear! And a pleasure to help.
Sent from my HTC HD2 using XDA Premium App

Multiuser: anyone knows how to change game data from one user to another one?

Hi all
After updated to 4.2 I created new user for my wife.
"Installed" same games but they are 'new' for new user.
I want to copy data games files from my user to her user.
Anyone knows how to do it?
Need to be root?
Thanks
Sent from my Nexus 7 using xda app-developers app
Assuming they are free games, as paid ones will need to be purchased twice. You can use titanium backup to back them up on your account and then restore them into her account. You do need to be root for titanium though.
Sent from my Nexus 7 using Tapatalk 2
dr.m0x said:
Assuming they are free games, as paid ones will need to be purchased twice. You can use titanium backup to back them up on your account and then restore them into her account. You do need to be root for titanium though.
Sent from my Nexus 7 using Tapatalk 2
Click to expand...
Click to collapse
Sorry - misinformation.
Paid apps do not need to be purchased twice, or restored into her user ID. That would be a really bad idea anyway - you would have two copies of the app.
With root use file explorer to find your save file under /sdcard/o/...something. Copy that file to an identical file structure under /sdcard/1, or whatever number your second user uses.
Apps done the correct way for multi-user never download a second copy. The Play store just sets a link to them in the main user.
Assuming app is available to both:
adb backup/restore might work for unrooted. Me, I'd Titanium Backup if it was important.
On a slight tangent, is there a shared data area that I could put shared files and videos that each user account would be able to view? If so do I need root access? Thanks.
bertracoon said:
On a slight tangent, is there a shared data area that I could put shared files and videos that each user account would be able to view? If so do I need root access? Thanks.
Click to expand...
Click to collapse
Don't forget a shared data area would mean the contents, like high scores, are shared between the users.
Most of the time, different users will want their own customizable data.
Technically, you need to purchase the app twice for two different account under playstore, that's the whole purpose of multiuser right?
Sent from my Nexus 7 using xda premium
Leechoonhwee said:
Technically, you need to purchase the app twice for two different account under playstore, that's the whole purpose of multiuser right?
Sent from my Nexus 7 using xda premium
Click to expand...
Click to collapse
Multi-user is not a developer enrichment scheme.
Your tablet has one owner, and apps are sold to that owner on an account basis - not by user or device ID.
The owner is able to make them available to any other users of that tablet without repurchase.
I suppose you would want an eye sensor, to make sure the person using the app is the one that paid for it?
No need to pay twice.just install twice.
Seems I need root.
I used some file explorer, find this:
/storage/emulated
/storage/sdcard0
/sdcard
All seems point to the same folders.
No sdcard1.
More than this, can't find data game. I have to explain that I have free games (from play store) and paid games (humble pack). If I search imaginarium game with Astro, no resulta found -.-'
Pd: No root at this moment, original 4.2 room
Sent from my Nexus 7 using xda app-developers app
Sorry - misinformation.
Paid apps do not need to be purchased twice, or restored into her user ID. That would be a really bad idea anyway - you would have two copies of the app.
Click to expand...
Click to collapse
Can you clarify this, apps are linked to the gmail account they were purchased with no? I haven't tried multiuser yet but I thought I read from others you have to add the primary gmail account to any secondary account to access the bought apps. Is this not correct? And if it is correct, can one add it only to google play and not have a secondary account access the associated email?
sark666 said:
Can you clarify this, apps are linked to the gmail account they were purchased with no? I haven't tried multiuser yet but I thought I read from others you have to add the primary gmail account to any secondary account to access the bought apps. Is this not correct? And if it is correct, can one add it only to google play and not have a secondary account access the associated email?
Click to expand...
Click to collapse
Set up a secondary user. Secondary user needs a Google account. Create a new one if appropriate.
Open Google Play on the secondary user. Click Options, then Add Account. Add your primary account (the one that owns your apps).
You will be given a choice of items to synch - uncheck them all. All you want is app access.
Display your apps (they are now visible to you). Install the ones you want the secondary user to have. They will NOT download - this user just gets a link.
When done, you can delete the main account from this user - or just leave it
I am going to start cutting and pasting this description - I keep having to retype it...
rmm200 said:
Don't forget a shared data area would mean the contents, like high scores, are shared between the users.
Most of the time, different users will want their own customizable data.
Click to expand...
Click to collapse
I appreciate that, I was just wondering whether there was a shared folder everyone could access as well as completely private areas for each user. Sounds as though there is absolutely no difference between multi user and having two completely separate tablets.
Well... Biggest difference is that only one copy of the app is shared by all the users.
Sent from my Nexus 7 using xda app-developers app
When done, you can delete the main account from this user - or just leave it
Click to expand...
Click to collapse
Thanks, but one more thing. If I leave it in google play do they have access to the associated gmail? I would prefer to just leave it for future apps and add a password for google wallet so they can't purchase things. Hmm, I guess though they can uninstall things that I wouldn't want uninstalled. I"m thinking of a kid mucking about where he shouldn't.
sark666 said:
Thanks, but one more thing. If I leave it in google play do they have access to the associated gmail? I would prefer to just leave it for future apps and add a password for google wallet so they can't purchase things. Hmm, I guess though they can uninstall things that I wouldn't want uninstalled. I"m thinking of a kid mucking about where he shouldn't.
Click to expand...
Click to collapse
You could try an 'app lock' app. i've tried 'app lock' on the play store which allows you to pin protect stuff like settings and install/uninstall and other apps - although couldn't lock gmail or certain system apps. But it should work for the play store. Maybe there are similar apps that allow you protect gmail.
rmm200 said:
They will NOT download - this user just gets a link.
Click to expand...
Click to collapse
Is it possible to move apps and its data from one user to another? To to so can I just uninstall app from first user? After that will this app and its data still be available for new user?
rmm200 said:
Set up a secondary user. Secondary user needs a Google account. Create a new one if appropriate.
Open Google Play on the secondary user. Click Options, then Add Account. Add your primary account (the one that owns your apps).
You will be given a choice of items to synch - uncheck them all. All you want is app access.
Display your apps (they are now visible to you). Install the ones you want the secondary user to have. They will NOT download - this user just gets a link.
When done, you can delete the main account from this user - or just leave it
I am going to start cutting and pasting this description - I keep having to retype it...
Click to expand...
Click to collapse
I tried to follow these instructions but a) I didn't get the sync message b) Play store doesn't display my bought apps in one place so it's not easy to find them and c) I have the feeling that it really double installs (I was hoping for a link).

Wifi Passwords did not Sync from Google

Hi, Just got S5 and for some reason google sync did not sync any applications or wifi password to my phone and i don't know how to force it... i am manually installing all apps, but passwords would really like to sync with google. any ideas how to force it? I still have them on my old phone...
arkady2k said:
Hi, Just got S5 and for some reason google sync did not sync any applications or wifi password to my phone and i don't know how to force it... i am manually installing all apps, but passwords would really like to sync with google. any ideas how to force it? I still have them on my old phone...
Click to expand...
Click to collapse
Google doesnt sync WiFi passwords. Those are saved in the phone, not to your google account. You have to manually enter all WiFi passwords on the new phone.
Gargamel198024 said:
Google doesnt sync WiFi passwords. Those are saved in the phone, not to your google account. You have to manually enter all WiFi passwords on the new phone.
Click to expand...
Click to collapse
Yes google does. It just usually never works
jjlean said:
Yes google does. It just usually never works
Click to expand...
Click to collapse
Damn, learn something new everyday.
Yup very annoying. It says right on the setup screen it syncs wifi passwords but I've never seen it work.
Sent from my SM-G900V using xda app-developers app
Questions and help issues belong in Q&A and help section
Thread moved
Thanks
Friendly Neighborhood Senior Moderator
hibby50 said:
Yup very annoying. It says right on the setup screen it syncs wifi passwords but I've never seen it work.
Sent from my SM-G900V using xda app-developers app
Click to expand...
Click to collapse
It has always worked for me actually... no matter what phone or tablet, wifi passwords always synced... but with S5... it's like it does not even know me...
I'll add that the network names and passwords were there for me as well when I activated my account on the S5. I was actually kind of surprised to see it all there.
Looks like I'm one of the unlucky ones it didn't sync for. Anyone find a way to force a sync from Google or a 3rd party workaround? I'm trying to get passwords from a rooted VZW GNex to a rooted VZW S5. I already tried backing up the Wi-Fi access points on the GNex in TiBu and restoring them on the S5 but no go. Thanks in advance for any ideas anyone might have.
KarlStyles said:
Looks like I'm one of the unlucky ones it didn't sync for. Anyone find a way to force a sync from Google or a 3rd party workaround? I'm trying to get passwords from a rooted VZW GNex to a rooted VZW S5. I already tried backing up the Wi-Fi access points on the GNex in TiBu and restoring them on the S5 but no go. Thanks in advance for any ideas anyone might have.
Click to expand...
Click to collapse
You can download Wi-Fi recovery from play store on both devices, on the one with all your Wi-Fi password hit export file then on the s5 you can import the file, then your all set.
I would *NOT* recommend using app for exporting WiFi data, mentioned above. Looking at the reviews many are saying that it doesn't work and is malware, which is actually feasible since it requires root. All the app is really doing is copying/pasting the /data/misc/wifi/wpa_supplicant.conf file. So instead of trusting a badly reviewed root-required app just get Root Browser and copy paste the file.
Sent from my HTCONE using XDA Free mobile app
After a hard-long internet search I've discovered that there's an alternative way in which you can eventually recover the information from google's own servers since that's where your device (or past devices) backups/backed up your data. The following link is a guide to this option.
http://jftr.de/2014/01/fairphone-and-android-backups-to-the-google-cloud/
As a reminder, you're the only one responsible for any possible damages involved when "tinkering" with your phone. Adb and root are necessary, so please refrain yourself from continuing if you don't even know these words!
Cheers

Categories

Resources