Knowledgebase

Mobile Security: Everything That Matters, Briefly Print

  • mobiledevelopment, mobile, security, ssl, troubleshooting, permissions, guide, howto
  • 0

The summary.

THE CLIENT CANNOT BE TRUSTED, EVER

Every authorisation decision belongs on the server. Prices, balances and permissions are never determined by the client.

NEVER EMBED SECRETS IN AN APPLICATION

Applications are decompiled routinely and extracting strings is trivial. Obfuscation provides delay, not protection.

Route anything requiring a secret through your own server.

PUT TOKENS AND CREDENTIALS IN SECURE HARDWARE-BACKED STORAGE

Never in preference storage, files or logs. And clear all user data on sign-out — devices are shared.

NEVER DISABLE CERTIFICATE VALIDATION FOR DEVELOPMENT CONVENIENCE

It is frequently left disabled, and it removes all protection.

Weigh certificate pinning carefully — a pinning failure cannot be fixed without a release, and users may not update.

BIOMETRICS CONFIRM PRESENCE, NOT IDENTITY TO YOUR SERVER

The correct pattern is a token in secure storage, released after biometric confirmation. Always provide a fallback.

TREAT DEEP LINK PARAMETERS AS UNTRUSTED INPUT

REVOKE SESSIONS SERVER-SIDE ON SIGN-OUT

Otherwise a stolen token remains valid.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot