YMY Musicinymusic.hashnode.dev·Sep 29 · 7 min readHow to Verify an Android APK Before Sideloading: Hashes, Signatures, Permissions, and Runtime ChecksSideloading an Android APK is not automatically unsafe, but it removes some of the screening and update controls users expect from an app store. A professional review therefore should not stop at “the00
MSManuel Spataroinmobile-cybersecurity.hashnode.dev·Sep 9 · 11 min readEncrypted Phone or Consumer Smartphone? The Security Perimeter Is the DeviceWhen sensitive information is discussed through smartphones, the usual security question is simple: Is the communication encrypted? Encryption is essential. But for government, defense, political, and00
DTDavid Timothyindigitalunpacked.hashnode.dev·Aug 31 · 12 min readGoogle Quietly Killed MTE on the Pixel 11, and It's Worse Than It SoundsGrapheneOS spent a week porting to the Pixel 11 series and hit a wall. Not a driver quirk, not a locked bootloader thing. ARM hardware memory tagging is missing. Not disabled in firmware behind a flag00
MSManuel Spataroinmobile-cybersecurity.hashnode.dev·Aug 14 · 15 min readHow Can I Tell If My Phone Is Being Tracked? Beyond the Usual Warning SignsSmartphones have become much more than communication devices. They are used to authenticate identities, access cloud services, exchange confidential information, store contacts, manage professional re00
SSaguninsagunwrites.hashnode.dev·Aug 1 · 4 min readWhat Is Mobile Malware?Your phone probably knows a lot about you. It may contain your conversations, photographs, contacts, emails, accounts, location data, and countless applications you use every day. And unlike a desktop00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 18 · 13 min readFAM CTF: The Library to The Endpoint WriteupExecutive Summary FAM is a mobile CTF challenge distributed as an Android APK (fam-ctf.apk) with four staged flags, each themed around a different layer of the app's Firebase backend: The Library (nat00
ASAneesa Shaikinaneesas.hashnode.dev·Jun 5 · 3 min readWhen App Security Meets AI: The Economics of Easy ExploitsBefore AI, attacking a mobile app was hard work. You needed someone who could read 𝗔𝗥𝗠 𝗮𝘀𝘀𝗲𝗺𝗯𝗹𝘆, set up 𝗙𝗿𝗶𝗱𝗮, 𝗠𝗜𝗧𝗠 your traffic, and actually understand what they were looking a00
SASahil Ahmedinsahilahmed.hashnode.dev·Jun 1 · 42 min readThe Complete Guide to React Native Debugging & Performance in 2026Table of Contents How React Native Actually Runs Your Code The Death of Flipper & The New Debugging Stack Development Environment Debugging Production App Debugging (Without Codebase) Network Deb00
JGJesus Guerrainjesusguerra.hashnode.dev·May 28 · 5 min readSecurity Isn’t About Shipping Fast. It’s About Knowing What You’re ReleasingI recently got pulled into a project that was technically “finished.” The app worked, the flows worked, and the subscriptions worked. But the founder still didn’t feel safe releasing it, and honestly…00
FSFarouq Serikiinfasthedeveloper.hashnode.dev·May 16 · 38 min read OWASP Mobile Top 10 for React Native Fintech Apps: A Practical Implementation ChecklistTL;DR The OWASP Mobile Top 10 isn't abstract theory — it's the exact list pen testers use to fail your app. Here's the cheat sheet: M1 — stop storing tokens in AsyncStorage, use Keychain/Keystore. M2 00