3 ms·
First, there's nothing to patch as it would probably need a cryptographic challenge response flow and not a simple yes or no. Even if there's a patch, it would
by devsda 3y ago
First, there's nothing to patch as it would probably need a cryptographic challenge response flow and not a simple yes or no.
Even if there's a patch, it would be difficult because there are other pieces of attestation that are already in place all the way upto the browser.
You cannot patch executables because os can verify executables via code signing signatures.
You cannot "patch" important parts of your OS (outside any zero days) with secure boot enabled(they can reject user keys for attestation).
- codedokode 3y ago> You cannot "patch" important parts of your OS (outside any zero days) So basically you just need to stop updating OS for 2 weeks and grab a fresh vulnerability to bypass attestation?