DEV Community

Discussion on: Pre-Launch Android App Security Checklist

Collapse
 
exadra37 profile image
Paulo Renato

Congrats for you excellent article and advice :)

Preferably, pin your certificates.

I would say always pin, but it's a very complicated area with a lot of potential for shoot yourself on the foot, thus a developer must really understand what is doing and understand all the implications for the mobile app when rotating certificates in the backend. I have wrote the article Securing Https with Certificate Pinning on Android that can help developers to implement it on Android. I realize now that I could write another article just around the shout on the foot scenarios.