FAQ

[k-9-mail] K-9 password security

Cketti
Aug 10, 2012 at 12:44 pm

On 09.08.2012 14:02, WIni wrote:
Hi folks,

I'm very concerned about security issue and before setting up my
business email account with K-9 mail on my smartphone I've got a question:

How is the password for the email accounts saved in this application?
If it's saved as plain text: Can I bring K-9 to save it on my SD card
instead of the internal memory? Because my SD card is completely
encrypted and I'm feeling very save with it.

Thanks & greets,
Wini
It's really simple. If the user doesn't have to supply some form of
secret (e.g. a password) every time the app is started, the data isn't
encrypted by the app (technically, it still might be; but if the app has
all the information to decrypt it automatically, so has an attacker).

K-9 Mail stores the passwords in a database on the internal storage. If
you use Android's device encryption (available since Android 3.0) this
database (and the rest of the app) is encrypted, otherwise it's not.
Due to many reasons moving the database to the SD card is not an option.
I have never heard of an Android version that only encrypts the SD card;
and for all other setups having the data on the SD card will make it
less secure.

--
You received this message because you are subscribed to the K-9 Mail Users List.
To post to this group, send email to k-9-mail@googlegroups.com
To unsubscribe, email k-9-mail+unsubscribe@googlegroups.com
To report an issue with K-9 Mail, visit http://code.google.com/p/k9mail/issues/list
For more options, visit this group at http://groups.google.com/group/k-9-mail
reply

Search Discussions

Discussion Posts

Previous

Follow ups

Related Discussions

Discussion Navigation
viewthread | post
posts ‹ prev | 2 of 3 | next ›

2 users in discussion

WIni: 2 posts Cketti: 1 post