Keeping Secrets Out of Mobile Apps

Bashir Lucas Samson Lukman

Anything shipped inside a mobile binary can be extracted. At Sybrix we assume that — and design APIs accordingly.


Never ship

  • Cloud admin keys
  • Payment secret keys
  • Database credentials
  • “Hidden” feature passwords in code
Picsum ID: 29

Do ship carefully

Public client IDs, when required by a provider, plus certificate pinning only when you understand rotation. User tokens belong in secure storage, not shared preferences in plaintext.

Server-side enforcement

Rate limits, per-user authz, and signed uploads beat clever obfuscation. Obfuscation slows casual attackers; it does not create confidentiality.

Picsum ID: 30

A release habit

Scan builds for high-entropy strings before store upload. Rotate anything that ever leaked into a chat or CI log.

— Bashir Lucas Samson Lukman, Full Stack Cross-Platform Developer at Sybrix

Picsum ID: 31

Sources

  • OWASP Mobile Top 10
  • Apple Keychain / Android Keystore guidance
  • Sybrix mobile security reviews

About the Author

Bashir Lucas Samson Lukman is a Full-Stack Cross-Platform Developer and the founder of Sybrix, where he builds scalable web and mobile applications while researching artificial intelligence, software architecture, cybersecurity, and emerging technologies. His writing focuses on the intersection of AI, software engineering, and digital trust.