Page 1 of 1

Plaintext username and password in Android LDS Tools

Posted: Wed May 25, 2011 1:55 pm
by jcdjcd2
The username and password cache used to authenticate to the Church servers is in plaintext. This is a rather poor security decision. Please consider updating the app to obfuscate the password appropriately.

The file in question is /data/data/org.lds.ldstools/shared_prefs/org.lds.ldstools_preferences.xml