Android Security Hardening 🛡️🔐
Professional security practices for protecting sensitive user data, identity, and application integrity on Android devices.
⚡ When to Use
- Biometric Authentication: Fingerprint/Face ID for app lock.
- Local Encryption: Securing login tokens or user profiles.
- Keystore Management: Safe storage of cryptographic keys.
- Root/Emulator Detection: Verifying device integrity for high-risk apps.
- Certificate Pinning: Hardening HTTPS via network security config.
🏗️ The 5 Pillars of Security
- Identity: Strong authentication (OIDC, Biometrics).
- Confidentiality: Encrypting data at rest and in transit.
- Integrity: Preventing tampering (App signing, Root check).
- Available: Ensuring resilience (DDoS protection, Offline access control).
- Audit: Logging security-relevant events safely.
🔑 KeyStore & Cryptography
1. Android Keystore System
- Rule: NEVER store encryption keys in resources or hardcoded.
- Use
KeyGeneratorwithpurpose(PURPOSE_ENCRYPT | PURPOSE_DECRYPT)andblockMode(BLOCK_MODE_GCM). - Use GCM (Galois/Counter Mode) for authenticated encryption.
2. EncryptedSharedPreferences
- Rule: Use
Jetpack Securityto encrypt standardSharedPreferences.val masterKey = MasterKey.Builder(context).setKeyScheme(AES256_GCM).build() val sharedPrefs = EncryptedSharedPreferences.create( context, "secret_prefs", masterKey, AES256_SIV, AES256_GCM )
🔐 Biometric Auth (BiometricPrompt)
- Use the androidx.biometric library for consistent UI across devices.
- Class 3 (Strong): Highest security, requires biological match.
- Class 2 (Weak): Fallback for older devices.
🛡️ Device Integrity & Hardening
- Root Detection: Use libraries like
RootBeerorGoogle Play Integrity API. - Emulator Detection: Verify system properties (
ro.product.model,ro.hardware). - Certificate Pinning: Use the
network-security-config.xmlto limit trusted CAs. - ProGuard/R8: Obfuscate sensitive classes and strings. CRITICAL WARNING: Misconfigured R8 rules will crash the app if reflection relies on stripped classes. (See CI/CD Expert Skill for R8 configuration guidelines).
- No Backup: Use
android:allowBackup="false"for sensitive data.
📐 Networking Best Practices
- Always use HTTPS (TLS 1.2+).
- Use
android:usesCleartextTraffic="false"in the manifest. - Sanitize all external inputs (Intents, WebViews).
🧪 Testing and Verification
- MobSF: Use Mobile Security Framework to scan for vulnerabilities.
- Runtime Checks: Use ADB to verify private data is NOT accessible to other apps.
- OWASP MSTG: Follow the Mobile Security Testing Guide.