Hiding Secrets in Android Apps
As a follow up on my somewhat incoherent rant about developers hiding passwords, keys, and other sensitive information in Android apps, I wanted to go through a semi-realistic example and explain the thought behind some of these strategies and why they may not be as effective as you might initially hope. While not a comprehensive review, we’ll take a look at the most common secret-stashing strategies (and how it can go wrong): To help illustrate some of these concepts, I created an example Android app on Github that we’ll analyze in this post. The full source code is available for review, but be sure to also take a look at the decompiled source. It’s important that you appreciate the perspective of both the developer and the reverse-engineer as you look for potential vulnerabilities. As an Android developer, your first instinct is probably to include any secrets, such as an API key, in your XML resources as you would with any other assets. We’ve done just that as well in our res/values
Hiding Secrets in Android Apps Sick of Acronyms Archive Pages Categories Tags Hiding Secrets in Android Apps 28 July 2015 As a follow up on my somewhat incoherent rant about developers hiding passwords, keys, and other sensitive information in Android apps , I wanted to go through a semi-realistic example and explain the thought behind some of these strategies and why they may not be as effective as you might initially hope. While not a comprehensive review, we’ll take a look at the most common secret-stashing strategies (and how it can go wrong): Embedded in strings.xml Hidden in Source Code
Explore this link on the map →related reading
- Ghidra Is Best: Android Reverse Engineering | REMY HAXremyhax.xyz
- An app can be a home-cooked mealrobinsloan.com
- Signal >> Blog >> Storage management for Signal Androidsignal.org
- GitHub - GitGuardian/ggshield: Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security. · GitHubgithub.com
- Security through obscurity - Wikipediaen.wikipedia.org
- Mitigating Memory-Safety Vulnerabilities | Computer Securitytextbook.cs161.org
- Google's Fully Homomorphic Encryption Compiler — A Primer || Math ∩ Programmingjeremykun.com
- Configure on-device developer options | Android Studio | Android Developersdeveloper.android.com
- Building and running an app | Apple Developer Documentationdeveloper.apple.com
- Themes from Real World Crypto 2022 - The Trail of Bits Blogblog.trailofbits.com
- Steganography - Wikipediaen.wikipedia.org
- Andrej Karpathy on X: "I wrote a quick new post on "Digital Hygiene". Basically there are some no-brainer decisions you can make in your life to dramatically improve the privacy and security of your computing and this post goes over some of them. Blog post link in the reply, but copy pasting below https://t.co/gRyeVouko5" / Xx.com