• @[email protected]
    link
    fedilink
    English
    911 months ago

    The same host could fake the payload to the attestation server. Cat and mouse game with security through obscurity.

    • @[email protected]
      link
      fedilink
      English
      711 months ago

      If you are on android or ios the phone already cryptografically verifies that the operating system has not been tampered with on a hardware level. Since the operating system is then “trusted” it can verify anything you do on it

      • @[email protected]
        cake
        link
        fedilink
        English
        711 months ago

        Doesn’t work. It’s possible to let many banking apps think they are running on a normal device although it is rooted.

        • @[email protected]
          link
          fedilink
          English
          611 months ago

          Yup Play attestation is dead, even the new and shiny “secure” one is bypassed. It’s now just a hinderence.