| ▲ | jfyi 4 hours ago | |||||||||||||||||||||||||
So your professional opinion is that the attack surface of mobile banking apps is limited to tokenized payments? Honestly, I'd be appalled if tokens were routed through my banking app. There is no reason the local client needs that data. | ||||||||||||||||||||||||||
| ▲ | hparadiz 3 hours ago | parent [-] | |||||||||||||||||||||||||
My professional opinion is that APKs can be de-compiled regardless and that has nothing to do with tokenized payments themselves which are like you said handled through server-server communications at the payment processor level. Your phone simply sends a one time use token to authorize the transaction. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||