How secure is GoogleAuthUtils.getToken() if app gets decompiled

Viewed 354

I am currently building an app for Android that requests data from my backend server. Of course, I want to know if a request received on my server really comes from my app or if someone just sends HTTP requests from another server etc. I read Tim Bray's article on that topic, but want to know how secure this approach really is. The article mentions that a rooted device might be able to compromise security, but I was thinking about the following scenario:

  • A malicious person takes my app, fully decompiles it and detects that I use GoogleAuthUtils
  • She/he changes my app in order to hack it and deploys it onto her/his device (using the same package name etc.)

I know that the fake app's signature will be different (since the malicious person does not have my private key) and that it cannot be downloaded from the Play Store (because no two apps with the same package names can be published there).

Provided the device is not rooted: is this fake app getting the same (or any) result from GoogleAuthUtils.getToken() as my real app?

What are the possible changes that the hacker could apply to the response on a rooted device (I could also ask: which fields of the response are signed by Google so I could detect whether they are untampered)?

1 Answers
Related