Bypassing Android Hardware Attestation from the Analyst's Chair
Introduction More and more Android apps want to know one thing before they let us in: is this device trustworthy? Banking apps, payment wallets, identity SDKs and a growing crowd of others now ask the operating system to prove that the phone is a genuine device running an untampered boot chain. When the answer is no, the app degrades, refuses a feature, or simply shuts the door. For a security analyst, this is a familiar wall. Our mission phone is usually rooted. That is not an accident, it is t...
Read full article →