Hacker News new | ask | show | jobs
by ericpauley 2690 days ago
Does this mean the app is necessarily a trusted component here? What's to stop an adversary from reverse engineering the application, especially on a platform like Android where applications are side-loaded and binaries largely maintain source-level semantics?

I guess you could argue that, from the merchant's perspective, they just want to avoid being the easiest target.

1 comments

Exactly - the effort required for this much beyond what most fraudsters would be willing to do on most platforms.