4 ms·
For now, until hardware backed attestation becomes properly enforced... Isn't security great
by throwaway52170 5y ago
For now, until hardware backed attestation becomes properly enforced... Isn't security great
- sudosysgen 5y agoIt probably will never be. It just takes one OEM to fuck it up and everyone can use their device ID. That's why hardware backed attestation doesn't work, OnePlus fucked it up and now Magisk can pretend to be that phone and get exempted.
- jsudi 5y agoIf a Chinese oem loses their keys why not just revoke them?
- sudosysgen 5y agoAnd cut off the phone from SafetyNet? That would hurt SafetyNet adoption and be bad for Google, which is presumably why they didn't do it for OnePlus.
- alias_neo 5y agoInteresting, I use OnePlus phones, where can I read more about this?
- sickmate 5y agohttps://www.synopsys.com/blogs/software-security/cve-2020-7958/ https://www.synopsys.com/blogs/software-security/cve-2020-79...