Security

2 articles · 1 talk · 2 milestones

Articles

Why Your API Key in Mobile Apps Needs to Be Restricted (Even When It Looks Like It Doesn't)
Article

Why Your API Key in Mobile Apps Needs to Be Restricted (Even When It Looks Like It Doesn't)

I pulled two working Google Maps API keys out of mobile apps in under a minute, both with no restrictions at all. Both reports were closed as Informative on HackerOne. Here is the extraction with apktool, the endpoint validation, and the three layers that actually fix it.

Read article
Video

The Big Security Problem in SaaS Created with Vibe Coding

SaaS products created in the AI rush are failing at the basics: security. In this video, I show you one of the biggest problems I've been finding in various products made with Vibe Coding-style tools: completely exposed databases, with no minimum security policy. In practice, you'll see how this happens. The problem is serious, easy to exploit, and affects many indie hacker projects who don't even know they're vulnerable. If you're creating a digital product, especially with low-code/no-code tools, this content is for you.

Read article

Talks

  • XibĂ©Sec 2026

    Your Fingerprint Is Not Your Password: Your Mobile App's Biometrics Can Be Hacked

    How incorrect biometric implementations on Android allow authentication bypass, with real attacks demonstrated from a vulnerability I found and reported.

Milestones

  • 📝 Article on SaaS Security

    Published an article and a video showing security problems in SaaS products built with vibe coding tools, warning about exposed databases.

  • đź—Ł Events & Security

    Participated in VueJs Norte, Flisol and DataTechDay. Started studying security with HackerOne, reporting vulnerabilities as an independent researcher.