3 ms·
> The app should provide its own keyboard for entering the username and password. Otherwise, malicious third party keyboards can act as keyloggers to obtain the
by problems 10y ago
> The app should provide its own keyboard for entering the username and password. Otherwise, malicious third party keyboards can act as keyloggers to obtain the user’s credentials.
This doesn't really help, if the attacker already has root on the device they can simply hook the login or key entry function in the application. They can also just screenshot on tap when the app is launched (though that's the lame way).
> The app should be protected against reverse engineering.
There's no such thing, I hate when people say things like this. If you rely on protections against reverse engineering, you rely on half-measures.
A determined reverser will always break your app. It might take minutes or days, but it'll always happen and they only need to break it once for it to be broken for everyone.
Ultimately this is a phone security issue. Don't download and run untrustworthy code, doubly so if your ROM is out of date and vulnerable.
As the immutable law of security says: If someone has root on your device, it's not your device anymore!
- on_and_off 10y agoif the attacker has root on the device, he can do absolutely everything he wants with it. I don't think any app can do anything at that point.