.
apk
, . .class , . .
. - private static String SECRET = "sesame123";. . - , , .so.
.so apk
.
, "". , , () Java- . (source-) "" . - , , ( , . ), , .
:
a) .
b) Java source is much easier to recover from compiled files .class; code obfuscation can complicate the job.
c) Any functionality that your application may have, native or not, can be easily extracted and used by another application that an attacker could write.
See also: http://en.wikipedia.org/wiki/Security_through_obscurity
source
share