Keeping Secrets Out of Mobile Apps
Bashir Lucas Samson Lukman
Anything shipped inside a mobile binary can be extracted. At Sybrix we assume that — and design APIs accordingly.
Never ship
- Cloud admin keys
- Payment secret keys
- Database credentials
- “Hidden” feature passwords in code

Do ship carefully
Public client IDs, when required by a provider, plus certificate pinning only when you understand rotation. User tokens belong in secure storage, not shared preferences in plaintext.
Server-side enforcement
Rate limits, per-user authz, and signed uploads beat clever obfuscation. Obfuscation slows casual attackers; it does not create confidentiality.

A release habit
Scan builds for high-entropy strings before store upload. Rotate anything that ever leaked into a chat or CI log.
— Bashir Lucas Samson Lukman, Full Stack Cross-Platform Developer at Sybrix

Sources
- OWASP Mobile Top 10
- Apple Keychain / Android Keystore guidance
- Sybrix mobile security reviews
About the Author
Bashir Lucas Samson Lukman is a Full-Stack Cross-Platform Developer and the founder of Sybrix, where he builds scalable web and mobile applications while researching artificial intelligence, software architecture, cybersecurity, and emerging technologies. His writing focuses on the intersection of AI, software engineering, and digital trust.