mDbxAcctMgr = DbxAccountManager.getInstance(getApplicationContext(), APP_KEY, APP_SECRET);
So anyone with some basic Android knowledge will be able to extract my applications key and secret?
mDbxAcctMgr = DbxAccountManager.getInstance(getApplicationContext(), APP_KEY, APP_SECRET);
So anyone with some basic Android knowledge will be able to extract my applications key and secret?
I would be interested in the implications of this from the authorising servers perspective. Here is the main mention of it in the OAuth spec: http://tools.ietf.org/html/rfc6749#page-52 and google's interpretation: https://developers.google.com/accounts/docs/OAuth2InstalledA.... Even though google say "t is assumed that these applications cannot keep secrets" I can't quite infer the actual implications of this?
Yes:
http://news.ycombinator.com/item?id=4410398
http://stackoverflow.com/questions/4419915/how-to-keep-the-o...
Probably, just like AirFoil Speakers Touch has been kicked out for using some Apple private key extracted from the Airport firmware to act as an AirpLay receiver.
Surely you need to grant your app to be able to indentify itself, that means it has to have its secret baked in?
It can still be abused, but at least you can know who did it.