Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That achieves nothing against someone who uses something like apktool/baksmali to do static RE, let alone inject something like Frida to perform dynamic RE. There are even Xposed modules designed to just bypass certificate pinning.

Certificate pinning is a good security measure, but not a counter-RE one.



Certificate pinning is neither a good security measure nor a good obfuscation one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: