Re: [webauthn] SafetyNet response as an extension

@herrjemand 

Please take a look at the Black Hat Europe presentation available at https://www.blackhat.com/docs/eu-17/materials/eu-17-Mulliner-Inside-Androids-SafetyNet-Attestation.pdf.
The "Attacks" section documents a variety of attacks against SafetyNet, and show how they affect different versions of Android.  The presenters also included several improvements, including anchoring the attestation in trusted HW.

This is the most recent reference I have found. 

-- 
GitHub Notification of comment by gmandyam
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1011#issuecomment-407946997 using your GitHub account

Received on Thursday, 26 July 2018 01:29:08 UTC