4 ms·
So what can you do ? You can't fight the private key retrieval right ?
by cake 13y ago
So what can you do ? You can't fight the private key retrieval right ?
- CGamesPlay 13y agoWell, you can lock down the device so that the end user doesn't own it, doesn't have root, and can't inspect your binary/data outside of your exposed interface. Which is exactly what iPhones and many Android vendors attempt to do.
- danhoc01 13y agoYou can download an APK using http://apps.evozi.com/apk-downloader/ http://apps.evozi.com/apk-downloader/, decompile and modify just as the article has said, and push to the Android SDK's emulator. I have done several analyses of apps using this method and a MITM proxy. I'm sure there are additional techniques to obfuscate the private key, but relying on locked down devices isn't possible in the Android ecosystem. You don't need a device at all to perform the steps outlined in the article.
- somesay 13y agoTypical DRM/crypto problem. As soon as one party is out of your control (e.g. client on end-user device) you already lost. Even on the iPhone you could do a jailbreak. You could only make things more difficult, in worst case you would have to open the device and directly access the RAM or something. Indeed you could personalizes the keys for every user. So you could detect a leaked private key that is widely used and proceed against. Still that wouldn't hinder personal further use of that private key, e.g. for exporting data (similar to breaking DRM).
- nly 13y agoNothing. If this article reminds of anything it's that anyone can patch Android apps (and resign them with a new key) to do anything they want.
- somesay 13y agoWhy exactly is that bad? Decompiling is a common tool, not only on Android. And however, Android notices that the app is signed differently, so it's still secure.