Firebase token in local storage

Viewed 232

While performing the security audit of an android application, it was found that the firebase token used for push notifications is stored locally in the phone storage.

This falls under a medium risk, storing sensitive information locally. The attack vector is physical and complexity is high.

  1. Why does firebase store the token locally since it is not a secure approach?
  2. Is it possible to use the push notification functionality without storing it locally?
0 Answers
Related