3 ms·
I think this is a more plausible approach (and likely cheaper resource-wise to implement). Though, if the authentication requests somehow identify the Android a
by ampersandy 13y ago
I think this is a more plausible approach (and likely cheaper resource-wise to implement). Though, if the authentication requests somehow identify the Android app in question, it might be easy for Amazon to then perform a follow-up and download the app to verify their suspicions and avoid false-positives.
- lugg 13y agoI dont think it would be that hard to automate decompilation and fire off an email after looking for secret keys. Either way it's good to see.
- joelhaasnoot 13y agoThis exists as a service - http://apkscan.nviso.be/ http://apkscan.nviso.be/ does a scan of your APK and registers requests to servers, lists hardcoded strings and other possible issues.