3 ms·
> I think the easiest way to do that would be to run Android in a VM. The problem is the critical payment and government ID apps that will never run in an Andr
by rjdj377dhabsn 10mo ago
> I think the easiest way to do that would be to run Android in a VM.
The problem is the critical payment and government ID apps that will never run in an Android VM because they intentionally break without hardware attestation.
- A4ET8a8uTh0_v2 10mo agoYep, otherwise, VM is effectively one of the better ( and maybe even safer ) way of trying to escape the established ecosystem.
- lanfeust6 10mo agoIsn't this spoofable with root access?
- JoshTriplett 10mo agoParts of it are, parts of it aren't. Some of it is based on hardware attestation.
- rjdj377dhabsn 10mo agoThe private key used for attestation is stored in the secure element hardware, which runs its own OS, completely inaccessible to the main hardware's OS, even with root. Some apps don't actually check the attestation signatures, so they could be spoofed for now, but if spoofing became common, apps would just get strict about checking attestation.