We have moved to a new Sailfish OS Forum. Please start new discussions there.
1 | initial version | posted 2014-04-15 10:30:47 +0200 |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I thin this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but tha fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
i think two steps should be performed, set a user passord for the sqlite dbs and/or encrypt the password. Even if both methods can broken by brute force it will at least raise the efforts needed to use the information.
Greetings
2 | No.2 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I thin think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but tha fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
i think two steps should be performed, set a user passord for the sqlite dbs and/or encrypt the password. Even if both methods can broken by brute force it will at least raise the efforts needed to use the information.
Greetings
3 | No.3 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but tha the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
i I think two steps should be performed, set a user passord for the sqlite dbs and/or encrypt the password. Even if both methods can broken by brute force it will at least raise the efforts needed to use the information.
Greetings
4 | No.4 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
I think two steps should be performed, set a user passord for the sqlite dbs and/or encrypt the password. Even if both methods can broken by brute force it will at least raise the efforts needed to use the information.
Greetings
5 | No.5 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
I think two steps should be performed, set a user passord for the sqlite dbs and/or encrypt the password. Even if both methods can broken by brute force it will at least raise the efforts needed to use the information.
Greetings
6 | No.6 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
I think two steps should be performed, set a user passord for the sqlite dbs and/or encrypt the password. Even if both methods can broken by brute force it will at least raise the efforts needed to use the information.
Greetings
7 | No.7 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
I think two steps should be performed, set a user passord for the sqlite dbs and/or encrypt the password. Even if both methods can broken by brute force it will at least raise the efforts needed to use the information.
Greetings
Edit jgr 2014-04-16: To see how easy it is for anyone to steal your credentials (e.g. mail address + password), see my answer below. You only have to visit the wrong web site.
8 | No.8 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
I think two steps should be performed, set a user passord for the sqlite dbs and/or encrypt the password. Even if both methods can broken by brute force it will at least raise the efforts needed to use the information.
Greetings
Edit jgr 2014-04-16: To see how easy it is for anyone to steal your credentials (e.g. mail address + password), see my answer below. You only have to visit the wrong web site.
9 | No.9 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
I think two steps should be performed, set a user passord for the sqlite dbs and/or encrypt the password. Even if both methods can broken by brute force it will at least raise the efforts needed to use the information.
Greetings
Edit jgr 2014-04-16: To see how easy it is for anyone to steal your credentials (e.g. mail address + password), see my answer below. You only have to visit the wrong web site.
10 | No.10 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
I think two steps should be performed, set a user passord for the sqlite dbs and/or encrypt the password. Even if both methods can broken by brute force it will at least raise the efforts needed to use the information.
Greetings
Edit jgr 2014-04-16: To see how easy it is for anyone to steal your credentials (e.g. mail address + password), see my answer below. You only have to visit the wrong web site.
11 | No.11 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
I think two steps should be performed, set a user passord password for the sqlite dbs and/or encrypt the password. Even if both methods can be broken by brute force it will at least raise the efforts needed to use the information.
Greetings
12 | No.12 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
I think two steps should be performed, set a user password for the sqlite dbs and/or encrypt the password. Even if both methods can be broken by brute force it will at least raise the efforts needed to use the information.
Greetings
13 | No.13 Revision |
Dear Jolla Team, I found out today that a Jolla Phone which is connected via USB gives complete access to the folder Sailfish\Phone Memory.config\signond. Within this folder are lying 2 sqlite databases. Both can be opened with a stadard SQLite Manager like, for example, the Firefox Extension https://code.google.com/p/sqlite-manager/. In both cases the databases can be accessed without knowing any passwort. Inside I found my eMail-Passwort in clearcase-readable.
I think this is a security risk since connecting a phone to the wrong computer could give a script a chance to copy these dbs directly and giving my credentials for 3rd party accounts.
I know that this is not so likely to happen but the fact that one can simply access these files via windows explorer could give even other possibilities to read these files.
I think two steps should be performed, set a user password for the sqlite dbs and/or encrypt the password. Even if both methods can be broken by brute force it will at least raise the efforts needed to use the information.
Greetings