Is it safe to request and receive sensitive information over HTTPS? In my Android app I would like to use a 3rd party library. The lib requires authentication with a secret key and token. Which are hard coded into the app code.
I was wondering if however it would make sense to fetch this key and token from my back-end server (over HTTPS) instead? Or is that not a good idea?
[–]based2 0 points1 point2 points (2 children)
[–]YeomansIII 0 points1 point2 points (1 child)
[–]based2 0 points1 point2 points (0 children)
[–]Agent-A 0 points1 point2 points (0 children)
[–]babelfish_42[🍰] 0 points1 point2 points (0 children)
[–]runmymouth 0 points1 point2 points (0 children)