@cyberMilosz@YaroST12@vxunderground Actually all frontend reliant encryption are not safe and best option is not to store high risk data on frontend. Frontend security is a security flaw!
@cyberMilosz@YaroST12@vxunderground Encrypted Shared Preference is not safe. If an attacker got root and physical access, it can just easily be exploited. That's why Google killed the library
@Paul_Reviews@vxunderground That's why Tink, Google's crypto library, specifically mentioned in the docs that it's okay to save *frontend* cryptographic keys like PINs in plaintext because it is extremely hard to access an app's internal data while bypassing anti tempering checks
@Paul_Reviews@vxunderground The problem is it can only be done with physical possession of the phone which is an extremely low attack vector that it's negligible. What encryption do you recommend anyways? If a hacker got root and physical access, no frontend encryption is safe.
@acoolrocket@Paul_Reviews Tbf no root detection is fully reliable but OP conveniently didn't mention that normal users don't root their device, and that this is very low chance to be exploited considering an attacker would need physical access to root the device
@Paul_Reviews And for a non rooted device, unlocking boot loader automatically wipe out all the data. And even if that is bypassed and an attacker got physical access to an untempered phone, you'd be more concerned about banking apps
@Paul_Reviews I don't support government surveillance but you're not disclosing that it is impossible for another app to modify an app's internal data like shared preference unless the device has root access. For attacker to realistically exploit this attack, they'd need physical access
@chhopsky@drewlevin@Drututt Not being able to play a game is not as serious impact as a security vulnerability. Bugs like this are reported in open forums likes GitHub all the time
@TD_Mani "I hate when a rapper talk about guns, then somebody die They turn into nuns, then hop online, like "pray for my city" He fakin' for likes and digital hugs"