Android mail apps send your passwords to the manufacturer

Discussion in 'mobile device security' started by summerheat, Mar 6, 2018.

  1. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
    German security researcher Mike Kuketz has tested mail apps for Android. He found out that the apps Blue Mail and Type-App send the user's login data including the email passwords to the manufacturer's sites.

    Although both apps are said to have different developers, Kuketz found that the POST requests in both apps are nearly identical. This suggests that the same people are behind both apps.

    Bottom line: If you were or still are using one of those apps you should assume that your accounts are compromised. Consequently, you should alter your mail passwords as soon as possible!

    Kuketz recommends trustworthy open-source mail apps like K-9.
     
  2. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    It's always been like this or only from a certain version on?
     
  3. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
    I don't know. Kuketz is right now testing various mail apps for Android, and, at least, the current versions are affected.

    According to a new blog post several other apps show the same behaviour!
     
  4. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
  5. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    With all those apps it should be possible to pinpoint those responsible
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    This has always been a concern for me, when it comes to third party email apps for both PC and smartphones.
     
  7. entropism

    entropism Registered Member

    Joined:
    Dec 9, 2004
    Posts:
    500
    The dev for both apps is a russian guy in Brooklyn, NY. He's shady as ****, has been for years.
     
  8. entropism

    entropism Registered Member

    Joined:
    Dec 9, 2004
    Posts:
    500
    If you want good email apps for Android:

    Maildroid, K9, Nine, Outlook, GMail. That's just about it. I've been using Edison. It's OK... still looking into the security, don't trust it yet.
     
  9. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
    I'm only familiar witk K-9 and agree that it's a good solution. Regarding Outlook - see post #4 above. :thumbd:
     
  10. dogbite

    dogbite Registered Member

    Joined:
    Dec 13, 2012
    Posts:
    1,290
    Location:
    EU
  11. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
    Agreed, I had used it, too. But I don't think it is open source ...
     
  12. zapjb

    zapjb Registered Member

    Joined:
    Nov 15, 2005
    Posts:
    5,556
    Location:
    USA still the best. But barely.
    K9 is excellent.
     
  13. 142395

    142395 Guest

    It's too bad K9 dropped support for ActiveSync. You can use AOSP email app which was included in older devices for ActiveSync tho.
     
  14. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
  15. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Today with Play Protect it is more difficult to disregard privacy/security than in the past.
    I only have 2 permissions in Blue Mail,basically the ones that almost all my apps have.
    Even Avast AV has never flagged anything.
     
  16. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,640
    Location:
    USA
    I see no mention of Outlook after clicking that link?
     
  17. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    well, i don't know about you, but in my book, once shady, always shady. :cautious:
     
  18. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,009
    Location:
    Member state of European Union
    Click Datensammler (Apps)
     
  19. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    thanks for the info, rp. :thumb:

    excerpt from the linked article (translated via google translate):

    https://www.privacy-handbuch.de/handbuch_70f.htm
     
  20. jaypeecee

    jaypeecee Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    165
    Location:
    UK
    Presumably, ProtonMail is safe to use?

    JPC
     
  21. Melionix

    Melionix Registered Member

    Joined:
    Jun 22, 2020
    Posts:
    111
    Location:
    Earth
    Yup. Tutanota and Fairemail is what I'm using. I fail to see why anyone would ever use anything but Fairemail for IMAP.
     
  22. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,009
    Location:
    Member state of European Union
    Does ProtonMail app support IMAP/other e-mail providers?
     
  23. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    no, it doesn't, due to lack of etee.
     
  24. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,009
    Location:
    Member state of European Union
    So, technically, the ProtonMail app can only send Proton e-mail password to ProtonMail, right? I don't think that is the issue.
    OP post is about sending password from e-mail provider X to e-mail client provider Y.
     
  25. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    yes, "technically" speaking, that is correct.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.