8 ms·
So your professional opinion is that the attack surface of mobile banking apps is limited to tokenized payments? Honestly, I'd be appalled if tokens were routed
by jfyi 1mo ago
So your professional opinion is that the attack surface of mobile banking apps is limited to tokenized payments? Honestly, I'd be appalled if tokens were routed through my banking app. There is no reason the local client needs that data.
- hparadiz 1mo agoMy professional opinion is that APKs can be de-compiled regardless and that has nothing to do with tokenized payments themselves which are like you said handled through server-server communications at the payment processor level. Your phone simply sends a one time use token to authorize the transaction.
- jfyi 1mo agoYou were the one that brought up payments though. Nobody else specified. They just said it could be hacked, which you seem to agree with.
- hparadiz 1mo agoI don't agree that your example makes sense. Don't feel like writing a wall of text. Zero justification for a locked down system.
- jfyi 1mo agoWhat exactly was my example? You agreed with me already. Kind of odd to flip around now. > which are like you said handled Also, I corrected your misstatement about payments. They have absolutely nothing to do with decomp, and certainly can't be used to dismiss the entire attack surface of a mobile banking app. Your example is complete nonsense. You are really digging a hole here.