This post is regarding the Xfinity Mobile app: https://market.android.com/details?id=net.comcast.ottclient
My system log shows <userName>[email protected]</userName> and <password>MYPASSWORD</password> on a line that starts with "D/HTTPManager". I read the log using aLogcat (app available in the market). Open aLogcat, press menu and filter for "password". After I clear my log (using aLogcat) that line reappears even when I haven't used the Xfinity app. I don't use my comcast credentials in any other app.
To try and resolve this I cleared data and cache for the Xfinity app, then cleared the system log in aLogcat, and restarted the phone for good measure. I opened the Xfinity app, logged in without checking "remember me" and unfortunately my username and password immediately reappeared in the system log.
I posted this issue here: http://forums.comcast.net/t5/Mobile-Apps-and-Web/Password-revealed-in-android-system-log/td-p/872295. A Comcast employee responded to say they will investigate this issue and fix it within a few weeks. In the mean time, you may want to uninstall the Xfinity Mobile app and change your Comcast password, or at least do not share your system log with anyone (in bug reports for example) if you have Xfinity Mobile installed.
This may not be the only app that exposes sensitive information in the system log, but this is the only password I have found exposed.
I have a Motorola Droid running stock Android 2.2.
UPDATE - As squiddy20 pointed out, Comcast has updated their app to 2.0.2. They include instructions to clear the app data as part of the upgrade, but that may be unrelated to this issue. In any case, I cleared the app data and installed the update, and my credentials no longer show up in the log. As far as I can tell, they have completely resolved this issue. If the problem persists for anyone else, be sure to post that here and on the Comcast forum.
Wow Comcast.
Thanks for the heads up
I checked this out for myself and the only way I could get it to show up was by logging out and then back in. I then did a reboot, let it sit for well over 5 minutes after it was fully booted, and then tried it and still no entry under "password". I dont get any of the sporadic, random popups you seem to have gotten. Oddly though, I have it set to not login automatically, yet after the reboot, it took me right to my email messages without me actually typing in my login info. That in itself is room for concern, let alone the possibility that login info is contained in the logcat in plain text.
Samsung Moment 2.1 running TiX 1.6 rom.
Interesting I to have the same issue squiddy20. Very concerning not a good thing Comcast
I was not able to see my password
I use an EVO with 2.3 and checked the same on my logs after logging in .. and only saw my username the password was nowhere to be found. I guess it would only happen when you first try to login.
squiddy20 said:
I checked this out for myself and the only way I could get it to show up was by logging out and then back in. I then did a reboot, let it sit for well over 5 minutes after it was fully booted, and then tried it and still no entry under "password". I dont get any of the sporadic, random popups you seem to have gotten. Oddly though, I have it set to not login automatically, yet after the reboot, it took me right to my email messages without me actually typing in my login info. That in itself is room for concern, let alone the possibility that login info is contained in the logcat in plain text.
Samsung Moment 2.1 running TiX 1.6 rom.
Click to expand...
Click to collapse
Now that I have unchecked "remember me" my credentials only show up in my log when I log out and back in. Not sporadic any more.
Check your Xfinity Mobile -> Settings -> Log Out setting. If it is set to "Never", then you wouldn't have to log in again after a reboot. If it is set to "On Exit" then you should have to log in again after exiting the app or after a reboot... but that may be buggy.
Thanks for the tip, but I honestly don't access my email through the app very much. To me, less things logged into and running in the background, means more memory for other things and slightly more battery life.
Also slightly less security problems!
Well, they've updated the app and I assume they've fixed the logcat problem (haven't checked for myself yet). They do have a note: "This Update will require you to log in to the application" plus the usual updates, improvements, and fixes.
Edit: just ran 2 checks with aLogcat and can confirm that the username and password info does not show up when searching for keyword "password". On a slight side note, I've noticed that hitting the home button on my Samsung Moment exits the app, but doesn't sign out. While hitting the back button from the main screen exits the app AND signs out. Settings also seem to be staying the same, even after reboots. Mine would reset occasionally, turning notifications on and other things.
I have had some concerns as well. I have lost most of my channels in the TV listings area. It goes from 2-29 and then 75-99 but that is it. I have uninstalled and reinstalled the app several times, cleared data in applications, etc. As I reinstall the app, it is going right into my system without asking for a password which I find a bit alarming.
I assume that the program has reverted to a selection that is not the full digital programming which shows up when you first do an initial install. I cannot find a way to get back to that area to reset my configuration and add all my channels back. I have emailed Comcast and those idiots responded that they do not have an app that works with Android yet, only iPads and iPhones. Quite comical.
Any help would be greatly appreciated.
I have tried all of the methods mentioned above and when I log in using username and password, and filter alogcat only my username appears in the log. Also tried brief and long settings in alogcat preferences.
Edit: This is using the 2.0.2 version.
Hi Squiddy ,
Pressing the backbutton will exit the app and pressing the home screen actually puts the app in the background so that at later point of time we can launch the app from the page where we left .
I dont think this is an Issue.
Hi Dawgman25,
There is a settings for the program area where you can change the zipcode of yours and select the proper digital option.
After logging in tap on the settings on the lower right corner.
There will be an option program area under TV Listings.
There you can enter your zipcode and give the correct Headend (Digital) option
I think the forums.comcast.net will respond quicker and properly .
you can also directly send mail to [email protected] to get lightning response !!
I tried this and he responded immediately
Every like 5 minutes, a box pops up saying "SORRY!, The application mail (process com.htc.android.mail) has stopped unexpectedly. Please try again."
It also displays this message every time I open either my contacts or the mail app.
So.. I can't open my email or contacts.. and I need those.
Any ideas, or suggestions on how to fix this? Thanks!
did you root your phone?
did you flash any rom?
My first response would be to wipe the app data. Assuming you already did this and it didn't do anything, I searched for a possible solution. I found something below in the link.
http://www.nexusoneforum.net/forum/...android-email-has-stopped-unexpectedly-2.html
I tried deleting the account setup and everything and it did not fix anything.
so FYI, it turns out it had nothing to do with the setup, since it has been working all this time. However, as I found somewhere else, a certain email was causing this problem to happen. For some reason, a newsletter/email from buy.com was causing this problem. I basically went to my inbox from my computer... then moved the last few days of email to a temporary folder. Sure enough the email app stopped crashing. I moved the emails back into the inbox until I found the one that was causing it.
I have had no problems with this update except for 1...
I cannot permanently delet e-mail. It uploaded a bunch of old e-mails as "new" and everytime I delete them they come back. EVERY email I delete comes back after a few hours.
Is there a setting I don't know about? Is there something I can do to permanently get rid of e-mail messages?
Thanks!
Please be specific
Can you please specify which mail account you are facing this issue with and describe in great detail step wise, starting point 1 until the issue cropping up with some screenshots to understand the problem better.
If I were to talk like a typical company technical help associate it would sound like this "Do a factory reset" but lets see what you come up with to help you further.
musicteachersheff said:
I have had no problems with this update except for 1...
I cannot permanently delet e-mail. It uploaded a bunch of old e-mails as "new" and everytime I delete them they come back. EVERY email I delete comes back after a few hours.
Is there a setting I don't know about? Is there something I can do to permanently get rid of e-mail messages?
Thanks!
Click to expand...
Click to collapse
Have you turned on the sync??
your issue sounds a lot like you delete the mails but the app doesn't sync it and hence they don't actually get deleted.so when you open it again after some time it connects to the server and your deleted mails come back again.
Sent from my Atrix2 Stock ICS Leak#2 Rooted,Deodexed,With Google Now...
Hi,
I've been using Sultan ROM with great satisfaction, but recently I have encountered very strange error. My phone was charging and when I picked it up to check emails, I had this error message in notifications: "Back up account: you need to set back up account". I dismissed that message, but then I noticed, that there are no contacts in my Contacts. I went to the Setting and noticed, that there is no Google account set on my device. I have manually restored them and all went back to normal. But 14 days later (today), the same has happened again. All my Google accounts lost with the same error message.
This time, I decided to go to check Settings>Accounts before I dismiss that error message. But I cannot access that setting, it always gets stuck. I can go back to home screen, but repeated attempts to access account settings always end with the same result - stuck screen. By checking Contacts I can see that there are no accounts on my phone again...
Any idea what can be wrong?
Thank you for any advices...
Try to flash the latest gapps
namanjr said:
Try to flash the latest gapps
Click to expand...
Click to collapse
I can do that, but can you elaborate more? Why should that help? THX...
Hi all
Hope your all enjoying your new phones
Does anyone else have the same problem with gmail as me? After maybe 30 minutes to an hour i keep on getting the message that my sign-in has failed and i need to keep on entering my password, also when i delete emails they either stay there or reappear later on!
Nope, but I do sometimes get the error that it couldn't sync my contacts on the regular email app for my work Office 365 exchange account
This is what I get and it's driving me crazy !
No problems here with gmail...yet.
ant78 said:
This is what I get and it's driving me crazy !
Click to expand...
Click to collapse
I had that, I deleted the account, added it again & it fixed it.
Jcko1 said:
I had that, I deleted the account, added it again & it fixed it.
Click to expand...
Click to collapse
thanks, will try that later
Used to be a common problem with Android. The solution was what was stated earlier, remove the account and add again. I don't think I've seen that problem since KitKat...
And with emails coming back, this used to happen to myself as well. I have my Yahoo email come through the Gmail app and it used to happen all the time. Now when I get an email I don't care to read I'll delete it from the notification bar and I haven't seen it return like it did to myself on marshmallow on my s7. But I'm able to see multiple emails and still delete them individually from the notification bar now, I couldn't do that before.