I'm on the edge of finishing my first app, and one last remaining thing is to implement IAP billing, so that's why I am currently reading quite a lot about the topic (including security concerns like encryption, obfuscation and stuff).

My app is a free version, with the ability to upgrade to full verison via IAP, so there would be just one managed purchase item "premium". I have a few questions about this:

In the Google IAP API example (trivialdrivesample), there's always the IAP check in MainActivity to see if the user bought the premium version, done via

mHelper.queryInventoryAsync(mGotInventoryListener);

My first concern: This does mean that the user always needs to have an internet/data connection at app-startup, to be able switch to the premium version right? What if the user doesn't have an internet connection? He would go with the lite version I guess, which I would find annoying.

So I thought about how to save the isPremium status locally, either in the SharedPrefs or in the app database. Now, I know you can't stop a hacker to reverse engineer the app, no matter what, even so because I don't own a server to do some server-side validation.

Nevertheless, one simply can't save an "isPremium" flag somewhere, since that would be too easy to spot.

So I was thinking about something like this:

  • User buys Premium
  • App gets the IMEI/Device-ID and XOR encodes it with a hardcoded String key, saves that locally in the app database.

Now when the user starts the app again:

  • App gets encoded String from database, decodes it and checks if decodedString == IMEI. If yes -> premium
  • If no, then the normal queryInventoryAsync will be called to see if the user bought premium.

What do you think about that approach? I know it's not supersecure, but for me it's more important

Edit
Report