Welcome to our new developer portal! Use the "Ask" button to chat with our AI Agent.
For the complete documentation index, see llms.txt. This page is also available as Markdown.

Countermesures

Thales SDK is designed to provide countermeasures against security threats. The following table shows the list of the known security threats and their corresponding SDK behaviors.

Security threat
Description
Build Type
SDK Countermeasure

Debugger attached

A hacker attempts to reverse engineer Mobile Application by using debugger that can be attached while executing Mobile Application.

Release

SDK will return an error when the debugger is detected.

Man in the middle attack (MITM)

A hacker tries to sniff or interfere with the communication channel between SDK and server.

Release

When using the Release build of the SDK with wrongly configured SSL certificate, SDK will return an error during respective flow.

Rooted/jailbroken mobile device

Using a rooted/jailbroken phone or device to run Mobile Application.

Debug and Release

SDK will return an error on rooted/jailbroken phone during respective flow.

Device unlock bootloader on Android

Using a device with bootloader unlocked to run Mobile Application.

Debug and Release

SDK will return an error on device with bootloader unlocked during respective flow.

Hook detection

A hacker attempts to hook (intercept) method calls in order to monitor/modify the behavior of the methods.

Debug and Release

SDK will return returns an error when the hook is detected.

Debug SDK in production application on Android

Play store application use Debug SDK variant.

Debug

The SDK returns the error when it detects that application is on Release configuration while using Debug SDK binary.

Use of emulator on Android

Using an emulator to run Mobile Application.

Debug and Release

The SDK returns the error when the emulator is detected.

Using non-designated application signing certificate and package name on Android or developer team ID and application bundle identifier on iOS

Mobile Application should always be signed using a designated certificate on Android or designated developer team ID and application bundle identifier on iOS.

Debug and Release

Create binding will fail if the developer signing certificate or package name on Android or developer team ID and application bundle identifier on iOS are not the same as that in the Server. The SDK returns the error when Mobile Application is using non-designated signing certificate on Android or developer team ID and application bundle identifier on iOS.

Last updated

Was this helpful?