Conversation

For the TEE-based keystore, the attestation keys provisioned for the device in the factory are encrypted with the hardware-bound TEE key and stored encrypted in the persist partition. Some users are wiping / replacing the persist partition on unlockable devices and losing them.
1
1
StrongBox keystore on the Pixel 3 has separate attestation keys, and I think they're burned into the Titan M security chip rather than encrypted with a hardware-bound and stored elsewhere, so this kind of issue can't happen. Similar to how StrongBox uses internal key storage.
1
4