[Q] GMAIL Password ? - Android Software/Hacking General [Developers Only]

I've had a GMail account for years, and never once had a problem. I recently got an Android phone, and started getting GMail delivery failures for emails about "acai berry" slimming, which obviously is spam I didnt send. As a developer, I can understand that servers can be hacked, and nothing is perfect.
Earlier in the week I couldn't check my GMail email from my Android phone. I then logged in from my PC & was told there was suspicious activity. I got an access code sent by SMS & reset my password. I then checked the suspicious activity & found 2 accesses to my account from Poland. Definately not me. I still thought someone had hacked the server.
But last night alarm bells started ringing. I was running some API example code in Eclipse through the debugger on the emulator, and saw in the LogCat window some messages about permissions being requested by the app. One of them being requested was "ACCESS_GMAIL_PASSWORD" (may not have been the exact wording - I forgot to make a note of it) but it definately said GMAIL & PASSWORD in the permission name.
Now it was only in the Emulator, which didnt have any personal info in it. But when installing apps from the Marketplace on my real phone, I always check the permissions very carefully & wouldnt have installed anything that requested my GMail password. I cant believe Google would have provided API methods to access my GMail password ? Is this right ? Is it possible for an app to do so without me knowing it has permission to do so ? If its possible, I may have to reconsider using GMail.
Thanks for any feedback.

Well some apps do actually require the Google login credentials. Like appbrain for example. And I've been using appvrain forever with no problem.
Sent from my DROIDX using Tapatalk

Yeah, but shouldn't we be aware of these permissions when we are installing. I know I haven't installed any apps that explicitly said they would access my GMail account.

Well I've checked for the following applications I've got on my phone and that use Gmail password:
- Android Market
- Chrome to Phone
- Gmail
- Google Reader
- GTasks
- Google Maps
and for all of them in the Authorisations list it is clearly written "Use an account authentification information" (I've translated from what I read in French so it may not be the exact wording in English).
So IMO if you use at least Android Market and Gmail application you have inevitably given access to your Gmail password.

On that list I have
- Android Market
- GMail
- Google Maps
All were pre-installed on the phone. Also, I trust the authors of these pieces of software. The problem is my GMail account has been accessed by a spammer sending "Acai berry" slimming emails. I dont think Google would misuse my GMail password for this purpose.
I am more concerned that I have been downloading apps from the Marketplace & one of them got my GMail password. I realise that apps have "Full internet access" when they are ad sponsored, I suspect a rogue app accessed my GMail password & then used its internet access to send the password to a spammer.
I have several apps from sources I dont fully trust, with "Full Internet Access". But I dont have any that asked for Account Authorisation when installed.
Is there any way I can recheck what apps can access my GMail password ?
Thanks.

There is an app on the market called task identifier that should help you out.
Sent from my DROIDX using Tapatalk

Looks exactly what I'm after. Thanks.

gungh0 said:
Looks exactly what I'm after. Thanks.
Click to expand...
Click to collapse
No problem. Good luck with it all.
Sent from my DROIDX using Tapatalk

Related

How do I remove my Google Mail account?!

Hi all.
I've recently bought my very first smartphone which is running Android 2.1. I'm absolutely loving it so far but I have a couple of questions regarding security.
Soon after setting up Android I configured the Google Mail app to sync with my Google Mail account, which is my primary email address.
I've noticed that whenever I open the Google Mail app it displays thousands of my emails, some of which contain very personal and sensitive information. My concern is that if somebody was to steal my phone and get passed the pretty basic key lock, they will have access to all of my emails over the past few years!
I've been told that it's not possible to password protect it or log out of the account; is that true?
I've tried to remove my Google Mail account from the app but it gives me the message:
This account is required by some applications. You can only remove it by resetting the phone to factory defaults (which deletes all your personal data). You do that in the Settings application, under Privacy.
Click to expand...
Click to collapse
Surely I don't have to do a factory reset just to remove my Google Mail account?
Any help would be appreciated.
Clear data for gmail in manage applications.
May I know why u want to delete ur gmail account ?
XperiaX10iUser said:
Clear data for gmail in manage applications.
Click to expand...
Click to collapse
I've done that already but as soon as I reopen the Google Mail app all of my messages reappear.
I've now archived all of my emails in Gmail and removed them from my inbox so they have now stopped showing in the Google Mail app but any new messages will appear.
I just don't understand why it's not possible to remove my account from the application.
sanketprabhu said:
May I know why u want to delete ur gmail account ?
Click to expand...
Click to collapse
I only want to remove it from the Google Mail application on Android so that if my phone was stolen or got into the wrong hands they don't have access to thousands of personal and sensitive emails.

install mutliple email applications

Hi,
Is there any issue about installing different email applications, so that each handle separately the various email accounts ?
To be more specific, I'd like to install a specific email application to handle a Exchange email account -application like Libre Email, which bypasses the pin lock security enforcement . While I would keep standard email application from android ICS to handle my other email accounts. And of course, target is to avoid that my Infinity gets "pin locked" due to the Exchange account.. Or is there a risk that the standard ICS email client detects another email app has an exchange account and would thus enforce the pin lock ?
NB: if any one knows an app which would restrict the pin lock to only when opening the Exchange email account, without forcing me to enter a pin every time I want to access my tablet, I'd be glad..
ricorico94
You can lock specific applications with Asus app that comes preinstalled with Infinity tablet..i don't know what the name of the app is as i don't have a tablet with me right now, but it is there. App locker or something. Does pretty much what you would like...
But if I lock the usual email app, will I be able to still use it ? I mean that my plan would be to used a specific email app for my exchange account but still use the standard email app for my usual accounts.
I think that is true.
Every app has its own settings, don't see a problem here.
I think you can safely use E-mail app that comes with android for one type of account and TouchDown for exchange account..
At least i think that's a way it works. Both have different settings and accounts of course.
Thanks for the clarification.
I found this topics http://forum.xda-developers.com/showthread.php?t=1117452 in the samsung threads. Could the patch work on my TF700T (9.4.5.22) ? Or are email.apk different on the various devices ?
Yeah you can. That is a simple android feature they have had since day one.
Sent from my HTC Sensation using Tapatalk 2

Android security app

I'll not bore you with the details, but a friend of mine thinks her accounts have been compromised (Gmail, skype etc..)
Is there any such thing as an app that will alert you when someone logs into your accounts ?
I've done a quick search and I'm not so sure !!
Google itself will alert you if your account is being accessed at the same time from an unusual IP and you can also check while you're logged into your Google account to see what IP addresses your account has been visited from.
Lock Apps
You can simply lock your applications on your phone if you suspect somebody accessing them via your phone.. Few apps http://gg.gg/fu0 | http://gg.gg/fu1
MissionImprobable said:
Google itself will alert you if your account is being accessed at the same time from an unusual IP and you can also check while you're logged into your Google account to see what IP addresses your account has been visited from.
Click to expand...
Click to collapse
Yeah that's true. That happened to me a few days ago when I was setting up a new email and I was schocked when I saw that email with all that red color

In-App Purchases use wrong account?

I have two Gmail accounts on my phone: a personal one and a business one (we subscribe to Google Apps at work). I use all the goodies like calendar and talk on both accounts, so it's important to have both. I put the personal account on the phone first (haven't determined if this matters).
Regardless of which account I make active in the play store, my work account is always selected when I try to make an in app purchase (such as touch recovery from Rom manager or 'unlock full' from Plague Inc and other games).
Are others experiencing this? Anyone know a fix? I just tried on stock jellybean via the following steps:
1. Add personal account
2. Install an app with in app purchase ability
3. Add work account
4. Open play, verify personal account is selected.
5. Try to purchase something 'in app's
6. It shows my work account. Open play store, work account now selected.
I don't do in app purchases much, but they seem to be getting more common, and it's annoying to remove the work account before every purchase.
Sent from my Galaxy Nexus using xda app-developers app
I have this same problem and have not figured out a solution for it. If you've figured out how to fix this, posting the solution would be awesome.
divinemyth99 said:
I have two Gmail accounts on my phone: a personal one and a business one (we subscribe to Google Apps at work). I use all the goodies like calendar and talk on both accounts, so it's important to have both. I put the personal account on the phone first (haven't determined if this matters).
Regardless of which account I make active in the play store, my work account is always selected when I try to make an in app purchase (such as touch recovery from Rom manager or 'unlock full' from Plague Inc and other games).
Are others experiencing this? Anyone know a fix? I just tried on stock jellybean via the following steps:
1. Add personal account
2. Install an app with in app purchase ability
3. Add work account
4. Open play, verify personal account is selected.
5. Try to purchase something 'in app's
6. It shows my work account. Open play store, work account now selected.
I don't do in app purchases much, but they seem to be getting more common, and it's annoying to remove the work account before every purchase.
Sent from my Galaxy Nexus using xda app-developers app
Click to expand...
Click to collapse
same here
same problem - please post solution!
Just ran into this problem too. My google apps account is automatically coming up for in-app upgrades, even though I don't have any play content (or credit cards or ...) associated with that account. Seems like a major flaw in google play. Can't select the other account, so I can't make any in-app purchases. Only solution (for one upgrade I had to buy) was to delete gapps account, make purchase, then re-add the other account.
Stupid. Please fix this google.
Same problem. I Can't test my own in app purchase for my own app. It keeps on selecting the first account on my phone that's also my developer account. Looks like some sort of bug.
Any progress?
Hi guys, I've noticed the same problem - did anyone get anywhere with it?
I thought it might be related to the order in which the accounts were added so I deleted both my accounts and added just the one that should be used for in app purchases. I then installed Microsoft OneNote mobile and went to its in app upgrade screen. It showed the correct account with payment details for upgrading. When I added the second google account though, the OneNote payment screen refreshed, even without me doing anything or having existed the app or even the payment screen, to show the newly added, wrong account!
So in order to make it work you'd have to remove one account, make the purchase with just one account set up, then add the second account. What a pain!
P3450 said:
Hi guys, I've noticed the same problem - did anyone get anywhere with it?
I thought it might be related to the order in which the accounts were added so I deleted both my accounts and added just the one that should be used for in app purchases. I then installed Microsoft OneNote mobile and went to its in app upgrade screen. It showed the correct account with payment details for upgrading. When I added the second google account though, the OneNote payment screen refreshed, even without me doing anything or having existed the app or even the payment screen, to show the newly added, wrong account!
So in order to make it work you'd have to remove one account, make the purchase with just one account set up, then add the second account. What a pain!
Click to expand...
Click to collapse
what happened when you delete your primary account? I got this warning: "Removing this account will delete all of its messages, contacts, and other data from the phone." and i afraid to lose my data
Did you guys figure out a better way yet?
edw1nyang said:
what happened when you delete your primary account? I got this warning: "Removing this account will delete all of its messages, contacts, and other data from the phone." and i afraid to lose my data
Click to expand...
Click to collapse
Data that was stored in the account is removed from your phone and gets back when you add it again
Still the same. Google is a horrible company when it comes to certain things. A bug like this at Apple would be squashed within a week.
Is there an official bug report somewhere for this to vote for?
divinemyth99 said:
I have two Gmail accounts on my phone: a personal one and a business one (we subscribe to Google Apps at work). I use all the goodies like calendar and talk on both accounts, so it's important to have both. I put the personal account on the phone first (haven't determined if this matters).
Regardless of which account I make active in the play store, my work account is always selected when I try to make an in app purchase (such as touch recovery from Rom manager or 'unlock full' from Plague Inc and other games).
Are others experiencing this? Anyone know a fix? I just tried on stock jellybean via the following steps:
1. Add personal account
2. Install an app with in app purchase ability
3. Add work account
4. Open play, verify personal account is selected.
5. Try to purchase something 'in app's
6. It shows my work account. Open play store, work account now selected.
I don't do in app purchases much, but they seem to be getting more common, and it's annoying to remove the work account before every purchase.
Sent from my Galaxy Nexus using xda app-developers app
Click to expand...
Click to collapse
Change the main account you want for in app purchases as Default by following steps below and u should do good
To change the default Google account when you are using the multiple sign-in, you need to Sign out of all accounts. Then log in to the Google account that you want to be the default first.
ive also attached an image if it helps:highfive:
shaik_u said:
Change the main account you want for in app purchases as Default by following steps below and u should do good
To change the default Google account when you are using the multiple sign-in, you need to Sign out of all accounts. Then log in to the Google account that you want to be the default first.
ive also attached an image if it helps:highfive:
Click to expand...
Click to collapse
We said about in-app purchase cannot select account in Payment Options. Not on the web.
Solution that worked for me!
Hey Guys,
I had the same problem as you describe, what i did to make it work and not show my work account in app purchases.
1. Delete app
2. install the app from browser where you are logged in to you private account.
3. Enjoy.
Hope with works great for you guys
Roundabout, but it works
what you have to do (seems like last guy was saying this?)
1. is uninstall the app from your phone.
2. the only way to change it is to go from your PC browser (very important!) to play.google.com and log in with the specific account you're trying to use for IAP's on your particular app.
3. you should be able to install the app, then go back to your phone and use the IAP with the correct account.
hope this helps everyone!
solution:
1) uninstall the app
2) go to play store and switch to the account you want to use to pay from
3) find the app in play store and install again
4) make your in-app purchase
divinemyth99 said:
I have two Gmail accounts on my phone: a personal one and a business one (we subscribe to Google Apps at work). I use all the goodies like calendar and talk on both accounts, so it's important to have both. I put the personal account on the phone first (haven't determined if this matters).
Regardless of which account I make active in the play store, my work account is always selected when I try to make an in app purchase (such as touch recovery from Rom manager or 'unlock full' from Plague Inc and other games).
Are others experiencing this? Anyone know a fix? I just tried on stock jellybean via the following steps:
1. Add personal account
2. Install an app with in app purchase ability
3. Add work account
4. Open play, verify personal account is selected.
5. Try to purchase something 'in app's
6. It shows my work account. Open play store, work account now selected.
I don't do in app purchases much, but they seem to be getting more common, and it's annoying to remove the work account before every purchase.
Sent from my Galaxy Nexus using xda app-developers app
Click to expand...
Click to collapse
YehoshuaL said:
solution:
1) uninstall the app
2) go to play store and switch to the account you want to use to pay from
3) find the app in play store and install again
4) make your in-app purchase
Click to expand...
Click to collapse
Have you tried this yourself? or is this the solution that made the most sense? I ask because this actually doesn't work.
---------- Post added at 10:37 AM ---------- Previous post was at 10:37 AM ----------
robnez said:
what you have to do (seems like last guy was saying this?)
1. is uninstall the app from your phone.
2. the only way to change it is to go from your PC browser (very important!) to play.google.com and log in with the specific account you're trying to use for IAP's on your particular app.
3. you should be able to install the app, then go back to your phone and use the IAP with the correct account.
hope this helps everyone!
Click to expand...
Click to collapse
This worked beautifully, thank you!
Know source of the problem, did not solve it though
Hello guys,
It's my first post here. And I hope this contributes something to solve this problem.
I think the problem lies within the 'all app' drawer of the playstore.
Simply the 'all app' drawer of the main account on which you installed the app first, will connect to the app as long as multiple accounts are available.
You can see it in the playstore in 'my apps' - > 'all apps'.
Usually all once installed apps show up there.
But if you've first installed an app connected to your 'secondary account' on some phone, then install it on a phone with another 'main account' and your 'secondary account', the app will show up only in the 'all apps' drawer of the 'secondary account'.
I hope that was understandable
One similar approach to the former workarounds.
-> You must have a backup of your accounts (titanium backup for example)
-> delete the secondary account
-> install the app (it will show up in the 'all apps' drawer)
-> restore your accounts (the app will remain in the 'all apps' drawer of the main account)
-> the app will connect to the right payment settings while in-app purchasing.
Now if there is any easier way to disable one account during the setup or to just connect the app to the right 'all apps' drawer , the problem should be fixed maybe
Best eazyRidor
vulcZ said:
Have you tried this yourself? or is this the solution that made the most sense? I ask because this actually doesn't work.
Yes. That's what worked for me.
Read the instructions CAREFULLY that I posted and it ought to work for you, too.
Click to expand...
Click to collapse
Uninstall the app
Go to Play Store and switch to the account you want to use to pay from
Find the app and install again
Make your in-app purchase

How can i tell which apps have access to my google account

Ok,
so this is more a general question about google rather than ANDROID, but android is google haha,
anyway, you know for example when you give an app permission to access google or sync with gmail it says
"the following application will do these things;
see your contacts" etc
etc
etc
so how do i check what apps have been given permission?
also theirs some app called BOXBE and i had to click onit to send seomeone a email and i think i let it access my emails LOL so please tell me what to do
https://security.google.com/settings/security/permissions
"Access to basic info" means you've logged in or linked with the account. Click on the item and you can revoke access.
Sent From My Samsung Galaxy Note 3 N9005 Using Tapatalk

Categories

Resources