On Wednesday, February 20, 2013 at 12:44 PM, Anil Saldhana wrote:
I have heard one of the biggest challenges with Android apps is once thephone is rooted, you have access to the APK. Basically any unencryptedsecrets/tokens used by the app are vulnerable.
At a bare minimum, OAuthinteractions require (ClientID + ClientSecret) combination to be saved.
On 02/20/2013 05:27 AM, Bruno Oliveira wrote:Morning, just be careful with the earlier releases from--"The measure of a man is what he does with power" - Plato-@abstractj-Volenti Nihil DifficileOn Tuesday, February 19, 2013 at 11:20 PM, Anil Saldhana wrote:_______________________________________________security-dev mailing list