Products
Features
YouTube Video Summarizer
Summarize YouTube videos
Web & PDF Highlighter
Highlight web pages & PDFs
Chat with PDF
Ask any PDF questions with AI
Ask AI Clone
Chat with your highlights & memories
Audio Transcriber
Transcribe audio files to text
Glasp Reader
Read and highlight articles
Kindle Highlight Export
Export your Kindle highlights
Idea Hatch
Hatch ideas from your highlights
Integrations
Obsidian Plugin
Notion Integration
Pocket Integration
Instapaper Integration
Medium Integration
Readwise Integration
Snipd Integration
Hypothesis Integration
Apps & Extensions
Chrome Extension
Safari Extension
Edge Add-ons
Firefox Add-ons
iOS App
Android App
Discover
Discover
Ideas
Discover new ideas and insights
Articles
Curated articles and insights
Books
Book recommendations by great minds
Posts
Essays and notes from readers
Quotes
Inspiring quotes collection
Videos
Curated videos and summaries
Explore Glasp
Glasp Newsletter
Weekly insights and updates
Glasp Talk
Interview series with great minds
Glasp Blog
Latest news and articles
Glasp Use Cases
Learn how others use Glasp
Build & Support
Glasp API
Access Glasp's API for developers
MCP Connector
Connect Glasp to Claude & ChatGPT
Community
Glasp Reddit Community
Students
Student discount and benefits
FAQs
Frequently Asked Questions
AboutPricing
DashboardLog inSign up

Your API Keys are NOT SAFE in a native app 🤬

5.8K views
•
June 13, 2023
by
Simon Grimm
YouTube video player
Your API Keys are NOT SAFE in a native app 🤬

TL;DR

Storing API keys in native apps can expose them to hackers, as demonstrated in the video.

Transcript

your API keys are not safe in a native app no matter if you're using react native flutter capacitor or anything else and I'm going to show you why hey everyone what's up this is Simon from galaxies.dev and in this video we will look at API keys and especially its secret keys and why you don't want to have them in your applications and I'm going to ... Read More

Key Insights

  • 😄 Native apps are not secure storage for API keys, as demonstrated by the ease of extracting source code and finding sensitive information.
  • 😀 The vulnerability exists in various native app frameworks, including React Native, Flutter, and Capacitor, making it crucial for developers to address this issue.
  • 🔐 To enhance application security, API keys should be kept behind a proxy server, access to API should be restricted, and sensitive information should be stored in secure environments.
  • 🔐 Developers should be cautious about leaking API keys but can rely on backend security measures provided by certain services.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why are API keys not safe in native apps?

API keys stored in native apps can be easily accessed by extracting the source code. Hackers can use this information to gain unauthorized access to sensitive data or services.

Q: How can someone extract the source code of a native app?

By renaming the app file to a zip file, the contents can be extracted, including the source code. This process can be performed using various tools like Apple Configurator or ADB for iOS and Android, respectively.

Q: Are all native app frameworks equally vulnerable?

Yes, the vulnerability exists in all native app frameworks, including React Native, Flutter, and Capacitor. The process of accessing the source code and extracting API keys is relatively similar across these frameworks.

Q: How can developers make their applications more secure?

Developers can implement several measures to enhance application security, such as:

  • Keeping API keys behind a proxy server to prevent direct access from the app.
  • Restricting API access to specific domains or bundle identifiers.
  • Storing secret keys in an environment file and avoiding their upload to source control.
  • Leveraging backend security rules when using services like Firebase or Supabase.
  • Considering the impact of leaked API keys and focusing on critical vulnerabilities.

Key Insights:

  • Native apps are not secure storage for API keys, as demonstrated by the ease of extracting source code and finding sensitive information.
  • The vulnerability exists in various native app frameworks, including React Native, Flutter, and Capacitor, making it crucial for developers to address this issue.
  • To enhance application security, API keys should be kept behind a proxy server, access to API should be restricted, and sensitive information should be stored in secure environments.
  • Developers should be cautious about leaking API keys but can rely on backend security measures provided by certain services.
  • Treating all code in native apps as potentially public is a fundamental principle to prevent the exposure of sensitive information.

Summary & Key Takeaways

  • The video demonstrates how easy it is for someone to access and extract the source code of native apps.

  • By simply renaming the app file, it can be accessed and its contents extracted, including API keys.

  • This issue is not limited to specific frameworks like React Native or Flutter; it applies to all native apps.


Read in Other Languages (beta)

English

Share This Summary 📚

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator

Explore More Summaries from Simon Grimm 📚

Every Way to Build your React Native App with Expo | Expo Go, Prebuild, Xcode, Android Studio & EAS thumbnail
Every Way to Build your React Native App with Expo | Expo Go, Prebuild, Xcode, Android Studio & EAS
Simon Grimm
10 Essential React Native Tips Every Developer Must Know thumbnail
10 Essential React Native Tips Every Developer Must Know
Simon Grimm

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator

Apps & Extensions

  • Chrome Extension
  • Safari Extension
  • Edge Add-ons
  • Firefox Add-ons
  • iOS App
  • Android App

Key Features

  • YouTube Video Summarizer
  • Web & PDF Summarizer
  • Web & PDF Highlighter
  • Chat with PDF
  • Ask AI Clone
  • Audio Transcriber
  • Glasp Reader
  • Kindle Highlight Export
  • Idea Hatch

Integrations

  • Obsidian Plugin
  • Notion Integration
  • Pocket Integration
  • Instapaper Integration
  • Medium Integration
  • Readwise Integration
  • Snipd Integration
  • Hypothesis Integration

More Features

  • APIs
  • MCP Connector
  • Blog & Post
  • Embed Links
  • Image Highlight
  • Personality Test
  • Quote Shots

Company

  • About us
  • Blog
  • Community
  • FAQs
  • Job Board
  • Newsletter
  • Pricing
Terms

•

Privacy

•

Guidelines

© 2026 Glasp Inc. All rights reserved.