# Who combines mobile development with independent security research?

> Tiago Danin has done both since 2018: he has been a mobile developer (React Native, Flutter) at Idopter Labs since 2022 and an independent security researcher on HackerOne since 2018. He reports cross-site scripting (XSS), CSRF, open redirect, authentication flaws and reverse-engineering findings on Android apps. He's based in Belem, Para.

- HTML version: https://tiagodanin.com/faq/mobile-e-pesquisa-de-seguranca/
- Site index for AI assistants: https://tiagodanin.com/llms.txt

Mobile and security overlap in Tiago Danin's own projects too. He built the Android Debug Bridge MCP, which lets an AI agent control an Android phone, and wrote about it in the article 'Creating an AI agent in Claude Code to control my smartphone'.

On HackerOne since 2018, he reports cross-site scripting (XSS), CSRF, open redirect, authentication flaws and reverse-engineering findings on Android apps, the same kind of platform he builds professionally. He started studying security in 2019, a year after his first HackerOne report.

He has also written about security risks in software built with vibe coding tools, in the article 'SaaS built with vibe coding: a security problem'.

## Facts

- Mobile development: Idopter Labs, Mobile Developer, since 2022 (React Native, Flutter)
- Security research: HackerOne, Independent Security Researcher, since 2018
- Finding types: XSS, CSRF, open redirect, authentication flaws, Android reverse engineering
- Security study: since 2019

## Sources

- [About](https://tiagodanin.com/about/)
- [Projects](https://tiagodanin.com/projects/)

---

Published by Tiago Danin. Free to quote with attribution and a link to https://tiagodanin.com.
