4 ms·
One thing I'm curious about is what they do to try to stop you from just ripping out the obfuscated token generation library and setting up a harness to run the
by trishume 6y ago
One thing I'm curious about is what they do to try to stop you from just ripping out the obfuscated token generation library and setting up a harness to run the whole thing in https://www.unicorn-engine.org/ https://www.unicorn-engine.org/ or something. Like presumably they don't compile their whole app with obfuscation and it's just some library that's linked in with some kind of stable-ish API contract with the rest of the app. I wouldn't be surprised if they do interesting things to try and stop you from ripping it out and it'd be cool to learn what those are.
- ponker 6y agoWhy wouldn’t they obfuscate the whole app?
- 3eed 6y agoThat'd be a noticeable performance hit I'd say.
- benmmurphy 6y agoI think someone used this route but ran the real binary on real phones that had been injected with his code that allowed tokens to be generated.
- 3eed 6y agoYou could manage to isolate these functions. The problem is that it's much of a hassle to run the whole thing on an emulator because there are way too many real environment dependencies, and even if you go the hackery way and patch all those, you won't know if you're generating one with the correct parameters because you're treating the whole thing as a black box.