This isn't specific to Android, as you can pull symbols out of many kinds of binaries with some work.
Being silly with you credentials can hurt you, regardless of the platform or using a compiled or interpreted environment.
Being silly with you credentials can hurt you, regardless of the platform or using a compiled or interpreted environment.
This isnt as much a "vulnerability" as it is a complete miss understanding of security and the technology they are using. Everything on the client side should be assumed as obtainable.