Sorry, but untrusted hardware can always win. For a case study of how hard this is to get right, see Microsoft's Xbox 360 and note that it was still fully compromised at least once.
Re: Simple And Safe In-App Purchase Using Parse
#21Does Parse validate the SSL certificate in a way that can't be patched at runtime? If not, it's just as possible to selectively spoof the Parse request as the Apple request.