Hacker News new | ask | show | jobs
by Asraelite 2031 days ago
There is some difference in the skill level required to convincingly craft a fake screenshot versus to spoof an API request, but yeah, it's not a huge difference.
2 comments

The fact that it's an API request will make it easier to create checks. For example, they could check if the length of the messages match with the length of the encrypted ciphertext the server sent. In theory you can do with this a screenshot already, by redigitizing the content, but it's harder. Or they could check whether the received/sent/etc dates match with what the servers recorded, etc.
do not underestimate the script kiddy tools, which are created to proof a vulnerability.

For example rooting a phone by hand is pretty hard. Many tools exist to do it automatically.