6 ms·
It's because of the Play Integrity API, which AFAIK runs downloaded binaries in the DroidGuard environment: https://en.wikipedia.org/wiki/Play_Integrity_API htt
by bilkow 1mo ago
It's because of the Play Integrity API, which AFAIK runs downloaded binaries in the DroidGuard environment: https://en.wikipedia.org/wiki/Play_Integrity_API https://en.wikipedia.org/wiki/Play_Integrity_API
The strongest levels require hardware key attestation (which, in my understanding, uses a certificate that's baked in secure hardware and signed by Google):
- https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu...
- https://developer.android.com/privacy-and-security/security-key-attestation https://developer.android.com/privacy-and-security/security-...
- wolvoleo 1mo agoStill. It must be possible to extract such a key. Even hardware key storage is not 100% safe.