4 ms·
I think for API consumption one important consideration is keeping API keys secure. Besides that, most of the modern issues I have seen are related to authentic
by s_streichsbier 8y ago
I think for API consumption one important consideration is keeping API keys secure. Besides that, most of the modern issues I have seen are related to authentication and access control.
Regarding reverse engineering, I personally feel that this is not as important an issue as others. Anyone that get's access to an app or a mobile device will always be able to reverse engineer it. It is just a question of time and effort. Mobile apps mostly should have the same objective as modern browsers, as providing the UI and UX.
Business logic and security should be handled on the backend side.
If you are still keen on reverse engineering and resiliency against it, check out this document https://www.owasp.org/images/6/61/MASVS_v0.9.4.pdf https://www.owasp.org/images/6/61/MASVS_v0.9.4.pdf.