A follow-up on how to store tokens securely in Android
Enrique López Mañas
5868
I have not done much decompiling, so this may be a dumb question, but it is it harder for someone to decompile and see the results of function() (therefore being able to dupe the server) than it is to see a decompiled String?