RediffMail component of MobileRediff application has a "Remember Me" function. When a user selects this option, the mobile application writes user's username and password to phone storage in clear text without encryption. If the phone is lost, stolen or when any other person is able to access the file system on the phone, the stored username and password can be compromised.
Symbian OS 9.1, Series 60 v3.0. Other mobile platforms might behave in same way.
Workaround
Do not enable store username and password option on the Rediffmail component of Mobile Rediff application.
Disclosure Timeline:
4/24/2009 - Vendor notified by email
7/15/2009 - release date