Conversation

Ok I fully admit I'm dumb and don't understand this. But a Friday news dump of a hyper-technical article outlining new SafetyNet checks that... now rely on the cloud? Google's going to have a big database of every single phone and flag each one as legit or not? Help?
Quote Tweet
🔑 We’re upgrading Android’s attestation with Remote Key Provisioning. Starting in Android 12.0 and mandated in Android 13.0, this scheme allows us to stop provisioning to compromised devices. Learn how it works and the changes to look out for. ↓ goo.gle/3tD2c5u
4
20
Replying to and
Hardware-based attestation is an AOSP feature which works well for other operating systems and is dramatically more useful and secure than SafetyNet's sketchy software-based attestation. It can also be used based on pinning instead of chaining to Google's attestation roots.
1
1
Show replies