|
|
|
|
|
by fc417fc802
294 days ago
|
|
You aren't responding to the scenario that was posed. You're assuming an isolated compromised app on an otherwise clean device. GP is assuming a compromised device. Of course attestation does nothing to improve the "single compromised app" case since (assuming Android) that goes nowhere either way. The only thing attestation does is meddle in end user affairs. |
|
The scenario is the phone isn't compromised. Having root means you, or an app you run can bypass the security protecting the authentication token.