New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integrate Google's SafetyNet API #15

Closed
n8fr8 opened this Issue Mar 8, 2017 · 3 comments

Comments

1 participant
@n8fr8
Member

n8fr8 commented Mar 8, 2017

  • provides verification that official ProofMode app was used
  • provides information about if device is rooted or otherwise modified
  • provides signed auto notarization of hashes by Googles server with timestamp and certificate

We won't use it to block use of ProofMode, and the user can disable it, but if this extra blob of data is not in the proofmode.csv it is a warning sign that the content should be closely scrutinized by the receiver by a human.

https://developer.android.com/training/safetynet/index.html
https://www.howtogeek.com/241012/safetynet-explained-why-android-pay-and-other-apps-dont-work-on-rooted-devices/

@n8fr8 n8fr8 added the enhancement label Mar 8, 2017

@n8fr8 n8fr8 self-assigned this Mar 8, 2017

@n8fr8

This comment has been minimized.

Show comment
Hide comment
@n8fr8

n8fr8 Mar 8, 2017

Member

The client side is easy. We will need to consider how recipients, orgs can easily verify this extra data. We might need a web service they can upload to.

Member

n8fr8 commented Mar 8, 2017

The client side is easy. We will need to consider how recipients, orgs can easily verify this extra data. We might need a web service they can upload to.

n8fr8 added a commit that referenced this issue Mar 8, 2017

@n8fr8

This comment has been minimized.

Show comment
Hide comment
@n8fr8

n8fr8 Mar 8, 2017

Member

More explanation of SafetyNet: https://koz.io/inside-safetynet/

Member

n8fr8 commented Mar 8, 2017

More explanation of SafetyNet: https://koz.io/inside-safetynet/

@n8fr8

This comment has been minimized.

Show comment
Hide comment
@n8fr8

n8fr8 Mar 8, 2017

Member

We might want to use this library: https://github.com/scottyab/safetynethelper

Member

n8fr8 commented Mar 8, 2017

We might want to use this library: https://github.com/scottyab/safetynethelper

n8fr8 added a commit that referenced this issue Mar 8, 2017

@n8fr8 n8fr8 closed this Apr 13, 2017

@n8fr8 n8fr8 added this to In Progress in Dev Sprints May 4, 2017

@n8fr8 n8fr8 moved this from In Progress to New Ideas in Dev Sprints May 4, 2017

@n8fr8 n8fr8 moved this from New Ideas to Done! in Dev Sprints May 4, 2017

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment