<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Dissection and Rants &#187; password</title>
	<atom:link href="http://www.iglobalonline.com/tag/password/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.iglobalonline.com</link>
	<description>Penetrating security, one app at a time</description>
	<lastBuildDate>Fri, 09 Apr 2010 18:08:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Password Storage Applications: Just how secure are they?</title>
		<link>http://www.iglobalonline.com/2010/02/07/password-security-applications-just-how-secure/</link>
		<comments>http://www.iglobalonline.com/2010/02/07/password-security-applications-just-how-secure/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 00:25:54 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Android Security]]></category>
		<category><![CDATA[applications]]></category>
		<category><![CDATA[banking information]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[sensitive data]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.iglobalonline.com/?p=28</guid>
		<description><![CDATA[Recently I started playing with password security applications in the Android market that claimed &#8216;reliable&#8217; from the authors. I decided to focus on the applications that had 4 or more stars and a lot of downloads. Since these types of applications store sensitive data, I wanted to see how hard it was to obtain this [...]]]></description>
			<content:encoded><![CDATA[<p>Recently I started playing with password security applications in the Android market that claimed &#8216;reliable&#8217; from the authors. I decided to focus on the applications that had 4 or more stars and a lot of downloads.</p>
<p>Since these types of applications store sensitive data, I wanted to see how hard it was to obtain this information assuming a handset was lost or stolen.  The common denominator between all the popular apps were the use of a master password. Some of the apps stored master passwords locally while others stored them remotely. All the apps stored banking information, passwords, and credit card numbers.</p>
<p>With being able to turn off your SIM card if your phone is lost or stolen; its not as easy to change passwords to sites or notify banks of accounts that could have been compromised.</p>
<p>With such a major number of users adding Android MOD&#8217;s such as Cyanogen to their device, it greatly increases the risk of personal information being leaked when a phone is stolen or lost.</p>
<p>We have already started notifying vendors of the vulnerabilities we have found.  Stay tuned as we start posting some of the results, you will be surprised at just how easy these applications could be compromised by attackers.</p>

	All Tags: <a href="http://www.iglobalonline.com/tag/android-security/" title="Android Security" rel="tag nofollow">Android Security</a>, <a href="http://www.iglobalonline.com/tag/applications/" title="applications" rel="tag nofollow">applications</a>, <a href="http://www.iglobalonline.com/tag/banking-information/" title="banking information" rel="tag nofollow">banking information</a>, <a href="http://www.iglobalonline.com/tag/compromise/" title="compromise" rel="tag nofollow">compromise</a>, <a href="http://www.iglobalonline.com/tag/credit-cards/" title="credit cards" rel="tag nofollow">credit cards</a>, <a href="http://www.iglobalonline.com/tag/password/" title="password" rel="tag nofollow">password</a>, <a href="http://www.iglobalonline.com/tag/secure/" title="secure" rel="tag nofollow">secure</a>, <a href="http://www.iglobalonline.com/tag/security/" title="Security" rel="tag nofollow">Security</a>, <a href="http://www.iglobalonline.com/tag/sensitive-data/" title="sensitive data" rel="tag nofollow">sensitive data</a>, <a href="http://www.iglobalonline.com/tag/vulnerability/" title="vulnerability" rel="tag nofollow">vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.iglobalonline.com/2010/02/07/password-security-applications-just-how-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
