4 ms·
The credentials are stored in plaintext on your phone. You can trivially extract them with a backup of your phone and a SQLite database editor.
by devicenull 15y ago
The credentials are stored in plaintext on your phone. You can trivially extract them with a backup of your phone and a SQLite database editor.
- piggity 15y agoAre these credentials all that are needed to impersonate your authenticator? This seems "bad" - as I'd personally expect there to be no "magic" data migration path between different apps. There should be a confirmation step from the security manager at least.
- andrewpi 15y agoI'm familiar with the 'extract from a backup' vulnerability for any information stored on Android. However, I'm more concerned that another (non root-privileged) app can access credentials without confirmation.
- skeletonjelly 15y agoI believe you'd need a rooted device for it to access another app's files, and even then you should get a popup prompting for access.