AI made old mobile security cheap to break—so obfuscation, SMS OTP, hardcoded secrets, and client-side checks are useless now. The fix, as explained in the slides, is to move trust to the server, use hardware-backed auth (passkeys, Play Integrity), rotate tokens constantly, and treat every client signal as suspicious