Y
Hacker News
new
|
ask
|
show
|
jobs
by
throwaway52170
1732 days ago
For now, until hardware backed attestation becomes properly enforced... Isn't security great
1 comments
sudosysgen
1732 days ago
It probably will never be. It just takes one OEM to fuck it up and everyone can use their device ID. That's why hardware backed attestation doesn't work, OnePlus fucked it up and now Magisk can pretend to be that phone and get exempted.
link
alias_neo
1732 days ago
Interesting, I use OnePlus phones, where can I read more about this?
link
sickmate
1732 days ago
https://www.synopsys.com/blogs/software-security/cve-2020-79...
link
jsudi
1732 days ago
If a Chinese oem loses their keys why not just revoke them?
link
sudosysgen
1732 days ago
And cut off the phone from SafetyNet? That would hurt SafetyNet adoption and be bad for Google, which is presumably why they didn't do it for OnePlus.
link