27 November, 2020
Blogs by Paulo Renato
Paulo Renato
Paulo Renato is known more often than not as paranoid about security. He strongly believes that all software should be secure by default. He thinks security should be always opt-out instead of opt-in and be treated as a first class citizen in the software development cycle, instead of an after thought when the product is about to be finished or released.
Posts on
- Mobile API Security (202)
- Mobile App Authentication (93)
- Mobile App Development (85)
- Mobile App Security (82)
- Mobile Security (75)
- Threats (74)
- API Abuse (64)
- Integration (56)
- API Keys (53)
- MitM (49)
- Bots (43)
- Business (38)
- Certificate Pinning (35)
- Reverse Engineering (31)
- App Attestation (30)
- Quickstart (26)
- Backend (25)
- Android Security (24)
- TLS (22)
- Repackaged Apps (20)
- Mobile Finance (19)
- Scrapers (18)
- iOS (18)
- RASP (15)
- Connected Car (14)
- Zero Trust (13)
- Mobile Health (12)
- Gaming and Gambling (11)
- News (10)
- Run-time Secrets Protection (10)
- ReactNative (9)
- Third Party APIs (8)
- Fake Accounts (7)
- Huawei (7)
- Retail (7)
- API Gateway (6)
- Account Hijacking (6)
- Apple (6)
- Compliance & Privacy (6)
- Zero Secret (6)
- Code Obfuscation (5)
- Cybersecurity (5)
- Google (5)
- OAuth2 (5)
- Reverse Proxy (5)
- Agentic AI (4)
- App Store (4)
- Cloud (4)
- Cross-Platform (4)
- OWASP (4)
- Runtime Application Self-Protection (4)
- Web Security (4)
- Aggregators (3)
- Data Security (3)
- E-Commerce (3)
- Mobile App Distribution (3)
- Mobile Banking (3)
- SafetyNet (3)
- Token-Based API Access (3)
- gRPC (3)
- Frida (2)
- Frontend (2)
- Mobile Payment Security (2)
- Pentesting (2)
- SDLC (2)
- AI Scraping (1)
- App Shielding (1)
- CNIL (1)
- Credential Stuffing (1)
- DeviceCheck (1)
- Google Play (1)
- Government (1)
- Runtime Secrets Protection (1)
- SDK (1)
- Supply-chain (1)
Popular Posts
- Limitations of Google Play Integrity API vs. Approov Mobile Security
- Revealing the Limitations of Apple DeviceCheck and Apple App Attest
- How to Bypass Certificate Pinning with Frida on an Android App
- Securing APIs with Approov and Cloudflare: A Comprehensive Guide
- How to Extract an API Key from a Mobile App by Static Binary Analysis
- Are You Human, Robot or Just Impatient?
- MitM Attacks on Android Apps: A Step-by-Step Guide Using Emulators
- Bypassing Certificate Pinning
- 5 Threats to Mobile Games and 5 Essential Security Measures
- Secure Your Mobile App from Geo-Spoofing with Robust API Integration
- Three Actions You Should Take Right Now to Stop Mobile MitM Attacks
- Limitations of Hardware-Backed Key Attestation in Mobile Security
- Limitations of Huawei HarmonyOS Safety Detect: What You Need to Know
- How to Ride the Bus for Free (Hackers Need Not Apply)
- How to Prevent Credential Stuffing Attacks on Mobile Apps
