forumNew topic

My mobile app has passwords, tokens, and API keys — can it be reverse-engineered?

KKemal S***Member
Job title
Field sales representative
Sector
Machinery manufacturing
Organization type
two-branch business
Joined
Jun 2023
Message
62
#1

Reverse engineering my Android APK takes 5 minutes. Passwords and tokens are visible with decompilers (ApkTool, Frida). How can I protect against this?

I get that I shouldn't hard-code API keys. But fetching them dynamically from the server loads it up. Is there a middle ground?

Is there the same risk on iOS apps? Can we read app data on jailbroken devices?

DDoki ekibiDoki team
Job title
Official account
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Mar 2023
Message
310
Most Helpful#2

Mobile App Security: Reverse engineering risk (Android APK/iOS IPA easily decompiled). Protection strategies: 1) Sensitive data storage: Keychain (iOS), KeyStore (Android), encrypted SharedPreferences, 2) Obfuscation (ProGuard Android, SwiftShield iOS), 3) API keys: server-side storage (never embed), certificate pinning (validate server identity), dynamic token refresh (short-lived tokens, server-issued), 4) Root/Jailbreak detection (API call fails if detected, not foolproof), 5) Runtime protection (code virtualization: difficult/complex, cost-benefit low for SMEs), 6) Network security: TLS 1.2+, certificate pinning (prevent MITM), 7) Frida anti-instrumentation (difficult, cat-and-mouse). Practical advice: Keep API keys on the server, app → server request → server returns authenticated token, cache token on client (expiry: 1-24 hours). Data storage: sensitive data = encrypted (Android Encrypter library, iOS Keychain), non-sensitive = SharedPreferences/UserDefaults. Jailbreak risk: data access possible (root privilege), mitigation = encryption + certificate pinning (limits attack vectors). iOS risk is lower (closed ecosystem), Android is higher (open, rooting easy). Pentest: tool-based vulnerability scan (Burp Suite mobile, OWASP Mobile Top 10 checklist).

YYavuz A***MemberCommunity member
Joined
Nov 2022
Message
139
#3

dont hard-code api keys. keep them on the server request a token from the app. use certificate pinning (to prevent MITM). use keystore/keychain for sensitive data. obfuscate the apk with proguard. add root/jailbreak checks...

EEsra O***Member
Job title
Quality Assurance Manager
Sector
Agriculture
Organization type
8-person team
Joined
May 2023
Message
84
#4

Mobile security implementation: 1) AndroidKeyStore: KeyStore.getInstance('AndroidKeyStore'), key generation with encryption, 2) iOS Keychain: SecItemAdd() for secure storage, 3) API auth: OAuth token refresh (expires in 1 hour, issued by server), 4) Certificate pinning (TrustKit iOS, Network Security Configuration Android), 5) Obfuscation (ProGuard rules: protect API classes, obfuscate others), 6) Runtime checks (RootBeer Android, DTTJailbreakDetection iOS), 7) Frida hardening (anti-hook detection: verify API function signatures). Storage hierarchy: Public (none), Local (encrypted), Keychain/Keystore (hardware-backed if available). Pen testing tools: Burp Suite mobile proxy, Frida interactive instrumentation, APK decompiler (apktool, dex2jar), debugger (gdb on Android, lldb on iOS).

UUğur V***MemberCommunity member
Joined
Aug 2023
Message
282
#5

don't hardcode API keys, keep them on the server but app login → server sends token → client caches it. token expires in 1-4 hours. use keystore/keychain for data storage. obfuscate with proguard. add jailbreak/root checks, close the app if detected...

UUğur Y***Veteran
Job title
Clinic manager
Sector
Catering
Organization type
medium-sized business
Joined
Mar 2023
Message
253
#6

Mobile app security layers: Network (TLS 1.2+, cert pinning), API (token-based auth OAuth short-lived tokens), Storage (encrypted keystore), Code (obfuscation anti-tampering), Runtime (jailbreak/root detection). Threat model: physical access (rooted device debugger), network access (proxy intercept — blocked by cert pinning) code analysis (reverse engineering — mitigated by obfuscation). OWASP Mobile Top 10: insecure transmission (prevent TLS bypass) insecure storage (keystore encryption), insecure auth (OAuth best practices), weak cryptography (AES-256), client-side injection (input validation).

JJülide A***Member
Job title
Accounting Manager
Sector
Jewelry
Organization type
20-person company
Joined
May 2024
Message
103

Doki · Vulnerability scanning · 2026

#7

Let me clarify the technical side. When we decide without measuring, we always end up in the same place.

I'm also curious if anyone does it differently.

GGamze E***MemberCommunity member
Joined
May 2022
Message
248
#8

Same here.

SSena B***MemberCommunity member
Joined
Jul 2024
Message
353
#9

I'd say don't rush. I mean when we decide without measuring we always end up in the same place.

That's all, sorry if I went on too long.

YYiğit D***Expert
Job title
Finance Manager
Sector
Healthcare services
Organization type
chain store
Joined
Dec 2023
Message
176
#10

My questions are cleared up thanks.

AAv. Kemal U***Expert
Job title
Lawyer · IT
Organization type
300-person organization
Joined
Sep 2023
Message
168
#11

There's a trap here, let me mention it. If permission and scope aren't in writing, don't start that test.

Don't rely on a single measure; go layer by layer.

GGürkan K***Member
Job title
Production planning
Sector
Packaging
Organization type
early-stage startup
Joined
May 2024
Message
109

Doki · Penetration test · 2026

#12

I have a question. When you try to change everything at once, nothing settles.

Hope this helps.

CCem B***MemberCommunity member
Joined
Sep 2023
Message
50
#13

I'm in the same situation that's why I'm asking. If permission and scope aren't in writing, don't start that test.

OOrhan D***Expert
Job title
Store associate
Sector
IT services
Organization type
early-stage startup
Joined
Nov 2024
Message
228
#14

Thanks a lot, I'll try it today. Mistakes made on the mobile app security side are usually reversible but expensive.

FFeyza K***Member
Job title
Intern
Sector
Catering
Organization type
workshop
Joined
Nov 2024
Message
2
#15

Saved. The harder it is to reverse a decision, the slower you should make it.

Mistakes made on the mobile app security side are usually reversible but expensive.

SSimgeMember
Job title
Event organizer
Joined
May 2024
Message
88

Doki · Log management setup · 2025

#16

I didn't know that.

ZZübeyde B***Expert
Job title
Graphic Designer
Sector
Agriculture
Organization type
sole proprietorship
Joined
Oct 2024
Message
128
#17

I'm curious too. Most time waste accumulates in tasks waiting for approval.

If you post the result here, it will help others too.

LLale Ç***New member
Job title
System support specialist
Sector
Tourism
Organization type
chain store
Joined
Jun 2026
Message
161
#18

My question might sound amateurish, sorry about that. Having backups accessible on the same network and with the same identity makes them part of the target.

Payment information changes are never verified through the channel they came from. If I were you, I'd go this route.

EElif Z***Expert
Job title
Production planning
Sector
Glass
Organization type
medium-sized business
Joined
Feb 2023
Message
164
#19

Noted, thanks. If it's your first time, start small; scaling comes later.

Correct me if I'm wrong.

HHavva G***MemberCommunity member
Joined
Feb 2023
Message
384
#20

This thread is archived. Payment information changes are never verified through the channel they came from.

Correct me if I'm wrong.

Reply