While performing the security audit of an android application, it was found that the firebase token used for push notifications is stored locally in the phone storage.
This falls under a medium risk, storing sensitive information locally. The attack vector is physical and complexity is high.
- Why does firebase store the token locally since it is not a secure approach?
- Is it possible to use the push notification functionality without storing it locally?