1. Hi @UIDAI and @KhoslaLabs
! Let me show you how to bypass the protection mechanism you set up and run the #Aadhaar #Android app on a rooted phone.
-
-
7. A basic protection against this unpack/repack is to check if the apk certificate had been modified. If this mechanism detect that your app had been modified, it will not start the app. They have a getApkCertificateDigestSha256 method in their app but it's not used...
pic.twitter.com/bTecaOtm2z
Prikaži ovu nit - Kraj razgovora
Novi razgovor -
-
-
Ok so the security of an app can be weakened by changing the app.... Isn't that true of anything? If they used a cert check, you could change the program code to bypass that check too. What's your point here?
-
As well said by
@troyhunt in his blog post, nothing is "Hack proof" but you can protect yourself against basic attack when you handle the data of 1.2 billion of people... - Još 5 drugih odgovora
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
Hacker. Fight disinformation at fsociety. Not completely schizophrenic. Not related to USANetwork. For business inquiries my email is below