<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Samsung S-Memo Security Flaw Reminds Us of the Dangers of Rooting a Device</title>
	<atom:link href="http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/</link>
	<description>An intense Android news community bringing you the latest in phones, rooting, apps, and reviews.</description>
	<lastBuildDate>Wed, 22 May 2013 00:36:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: jdrch</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2538799</link>
		<dc:creator>jdrch</dc:creator>
		<pubDate>Tue, 13 Nov 2012 15:24:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2538799</guid>
		<description><![CDATA[Quite a few social networking webapps]]></description>
		<content:encoded><![CDATA[<p>Quite a few social networking webapps</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: someone</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2537313</link>
		<dc:creator>someone</dc:creator>
		<pubDate>Tue, 13 Nov 2012 08:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2537313</guid>
		<description><![CDATA[What a non issue.  Service that requires automated gmail password stores it in plain text.

Next you&#039;ll be telling me that your IMAP or POP mail password stored in k9 or other mail clients are stored in plain text too (they are, or they have an easily reversible encryption).

 Not even OAuth could save the day because with root access, one would simply intercept the authentication token.  Root isn&#039;t bad.  You just have to take care of it, as people have been saying all along.]]></description>
		<content:encoded><![CDATA[<p>What a non issue.  Service that requires automated gmail password stores it in plain text.</p>
<p>Next you&#8217;ll be telling me that your IMAP or POP mail password stored in k9 or other mail clients are stored in plain text too (they are, or they have an easily reversible encryption).</p>
<p> Not even OAuth could save the day because with root access, one would simply intercept the authentication token.  Root isn&#8217;t bad.  You just have to take care of it, as people have been saying all along.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VZWIndirect</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2536671</link>
		<dc:creator>VZWIndirect</dc:creator>
		<pubDate>Tue, 13 Nov 2012 04:35:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2536671</guid>
		<description><![CDATA[I hate to say it, but I would freakin love it, if this worked on every device. One the biggest pain the arse&#039;s I have is customers that have forgotten their G-Mail password, and blew through the set up, skipping all the unimportant stuff like secret question answers and recovery e-mails. 

Have you ever tried to recover a lost G-Mail password without these? It would be easier to hack into the Pentagon.]]></description>
		<content:encoded><![CDATA[<p>I hate to say it, but I would freakin love it, if this worked on every device. One the biggest pain the arse&#8217;s I have is customers that have forgotten their G-Mail password, and blew through the set up, skipping all the unimportant stuff like secret question answers and recovery e-mails. </p>
<p>Have you ever tried to recover a lost G-Mail password without these? It would be easier to hack into the Pentagon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Name</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2536041</link>
		<dc:creator>Name</dc:creator>
		<pubDate>Tue, 13 Nov 2012 01:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2536041</guid>
		<description><![CDATA[You mean something like the Google Voice app?  That&#039;s not 3rd party, but who else needs Google credentials??  Unless you mean some 3rd party Twitter like app that requires your Twitter login info??]]></description>
		<content:encoded><![CDATA[<p>You mean something like the Google Voice app?  That&#8217;s not 3rd party, but who else needs Google credentials??  Unless you mean some 3rd party Twitter like app that requires your Twitter login info??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacob Davis</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534955</link>
		<dc:creator>Jacob Davis</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534955</guid>
		<description><![CDATA[Shouldn&#039;t be storing the password in any manner. Not in this case.]]></description>
		<content:encoded><![CDATA[<p>Shouldn&#8217;t be storing the password in any manner. Not in this case.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon Belmont</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534937</link>
		<dc:creator>Simon Belmont</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:13:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534937</guid>
		<description><![CDATA[Yes. So the moral of the story is to be careful what apps you allow root access.

Do research and don&#039;t just sideload any old app that can use root. You know, common sense stuff.
]]></description>
		<content:encoded><![CDATA[<p>Yes. So the moral of the story is to be careful what apps you allow root access.</p>
<p>Do research and don&#8217;t just sideload any old app that can use root. You know, common sense stuff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr E</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534935</link>
		<dc:creator>Mr E</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:10:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534935</guid>
		<description><![CDATA[yep]]></description>
		<content:encoded><![CDATA[<p>yep</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nate Davidson</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534930</link>
		<dc:creator>Nate Davidson</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:09:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534930</guid>
		<description><![CDATA[Galaxy S3 has S-Memo?]]></description>
		<content:encoded><![CDATA[<p>Galaxy S3 has S-Memo?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Kusold</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534913</link>
		<dc:creator>Mike Kusold</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:07:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534913</guid>
		<description><![CDATA[This is not the solution. Because the app needs to be able to decrypt the password in order to log you in to Google&#039;s services, any one would also be able to decrypt it once they found out the passphrase that Samsung uses (which would be hard coded into the app and trivial to get).


Hashing and Salting your password works well on websites because the website never needs to know how to decrypt your password. They simply take the password that you are attempting to log in with, then they hash it and see if the resulting hash matches the password they have stored in their database.



The real solution here is to use OAuth.]]></description>
		<content:encoded><![CDATA[<p>This is not the solution. Because the app needs to be able to decrypt the password in order to log you in to Google&#8217;s services, any one would also be able to decrypt it once they found out the passphrase that Samsung uses (which would be hard coded into the app and trivial to get).</p>
<p>Hashing and Salting your password works well on websites because the website never needs to know how to decrypt your password. They simply take the password that you are attempting to log in with, then they hash it and see if the resulting hash matches the password they have stored in their database.</p>
<p>The real solution here is to use OAuth.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will P</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534912</link>
		<dc:creator>Will P</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:06:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534912</guid>
		<description><![CDATA[You don&#039;t have to have S-Memo installed for your passwords to be stored in plaintext. There are multiple databases in which stock android stores plaintext passwords that are only accessible if you&#039;re rooted.]]></description>
		<content:encoded><![CDATA[<p>You don&#8217;t have to have S-Memo installed for your passwords to be stored in plaintext. There are multiple databases in which stock android stores plaintext passwords that are only accessible if you&#8217;re rooted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: burntcookie90</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534906</link>
		<dc:creator>burntcookie90</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534906</guid>
		<description><![CDATA[Why store password, everything should be OAuth.]]></description>
		<content:encoded><![CDATA[<p>Why store password, everything should be OAuth.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NastyEmu</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534899</link>
		<dc:creator>NastyEmu</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:03:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534899</guid>
		<description><![CDATA[I&#039;ve never minded having to add application specific passwords, although if those are also viewable in plaintext via S-memo then two-factor isn&#039;t going to give you much protection

Edit: Nevermind, I don&#039;t think we are talking about the same thing.  What 3rd-party services do you use Google credentials for?]]></description>
		<content:encoded><![CDATA[<p>I&#8217;ve never minded having to add application specific passwords, although if those are also viewable in plaintext via S-memo then two-factor isn&#8217;t going to give you much protection</p>
<p>Edit: Nevermind, I don&#8217;t think we are talking about the same thing.  What 3rd-party services do you use Google credentials for?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luis Reich</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534878</link>
		<dc:creator>Luis Reich</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:02:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534878</guid>
		<description><![CDATA[Blah blah blah... Rooting is evil... Yeah...]]></description>
		<content:encoded><![CDATA[<p>Blah blah blah&#8230; Rooting is evil&#8230; Yeah&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jdrch</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534876</link>
		<dc:creator>jdrch</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534876</guid>
		<description><![CDATA[That&#039;s a major PITA if you use multiple 3rd party services with your Google credentials]]></description>
		<content:encoded><![CDATA[<p>That&#8217;s a major PITA if you use multiple 3rd party services with your Google credentials</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sr_erick</title>
		<link>http://www.droid-life.com/2012/11/12/samsung-s-memo-security-flaw-reminds-us-of-the-dangers-of-rooting-a-device/comment-page-1/#comment-2534877</link>
		<dc:creator>sr_erick</dc:creator>
		<pubDate>Mon, 12 Nov 2012 21:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.droid-life.com/?p=88858#comment-2534877</guid>
		<description><![CDATA[Who the hell stores passwords in plain text and calls themselves a developer? Bad, bad, bad.]]></description>
		<content:encoded><![CDATA[<p>Who the hell stores passwords in plain text and calls themselves a developer? Bad, bad, bad.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using apc
Database Caching 8/28 queries in 0.025 seconds using apc
Object Caching 662/678 objects using apc

 Served from: www.droid-life.com @ 2013-05-21 17:45:08 by W3 Total Cache -->