Sunday, April 20, 2008

Gmail MIDlet security

Did you know, that your GMail application mail texts are stored in java rms memory as plain-text?

It is easy to extract phone RMS data, you just need to have access to phone for couple of minutes.

Here is example of RMS data of GMail (windows notepad is used to open it):



Sometimes there could be very sensitive data in mails, such as passwords or bank data.

Btw, there are applications that store also login credentials as plain-text in RMS memory.

Don't underestimate those security risks, when developing applications.


No comments: