logoalt Hacker News

hparadizyesterday at 1:14 PM3 repliesview on HN

The crypographic flow that allows payments to work is straight up pub/priv key encryption with one time use tokens. It's not something you can hack. As soon you see the token it's already been used and thrown away. So whatever nonsense about decompiling literally doesn't matter.


Replies

jfyiyesterday at 1:27 PM

So your professional opinion is that the attack surface of mobile banking apps is limited to tokenized payments? Honestly, I'd be appalled if tokens were routed through my banking app. There is no reason the local client needs that data.

show 1 reply
pixardyesterday at 1:34 PM

He said his app is a one time payment. Presumably there isn’t a backend and he relies on App Store purchases. I know, it’s shocking an app could just be an actual application rather than a web view.

skinfaxiyesterday at 1:26 PM

You can patch out the payment checks if you can decompile it

show 1 reply