Skip to content

0.3.0

Choose a tag to compare

@munzzyy munzzyy released this 02 Oct 13:52
· 52 commits to main since this release

A stricter check of files signed by more than one key.

  • A file signed with more than one key passes only when every one of those keys is pinned. An update passes only when the installed app has exactly the same keys. One matching key used to be enough. So a key added to a download could tie a first install to it, and then no later update from the developer would go in until the app was uninstalled.
  • On Android 12 and 12L the question that asks to allow installs no longer says that Android will close Tern when the switch is turned on. Android 11 does that and is still told so. On Android 12 Tern stays open.

Tern can now turn down a file it used to take: one whose keys are not all pinned, or an update whose keys are not the installed app's. That is why this is 0.3.0 and not 0.2.3. A pin that lists more than one certificate still takes a file signed with any one of them, and a rotated key still passes. docs/SECURITY-MODEL.md has the whole rule.

Install tern-0.3.0.apk on Android 9 or later. It installs over earlier versions. Its SHA-256 is:

44969060c192a2a91c0d6d51d51f76007d8cbca3fef489fe7d5e3891a1273ae5

The SHA-256 of the signing certificate is:

a894d9999c8e93a102a1d7afe86028980c25d76e7436dc3b143c5664c95b7003

The device suite passed on the Android TV 9, 11, 12 and 14 emulators. On the phone emulators for Android 9, 10, 13 and 16 a few screen tests failed. Each of them fails the same way with 0.2.2. On Android 13 the new version went in over 0.2.2, kept the list and updated an app.