Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

System image signature / OEM keystore #2

Open
pylerSM opened this issue Sep 26, 2015 · 3 comments
Open

System image signature / OEM keystore #2

pylerSM opened this issue Sep 26, 2015 · 3 comments

Comments

@pylerSM
Copy link
Owner

pylerSM commented Sep 26, 2015

Here is place where I and maybe some other people will share useful info.

Googler: "At the moment, any non-official build will not pass SafetyNet because the system image signature isn't what was expected"

Verified boot (PDF): "Verified boot devices ship with an “OEM Keystore” which is built into the system and signed by a key managed by the OEM"

@pylerSM
Copy link
Owner Author

pylerSM commented Sep 26, 2015

@pylerSM
Copy link
Owner Author

pylerSM commented Sep 26, 2015

@Entropy512
Copy link

https://koz.io/inside-safetynet/ - This was posted 1-2 weeks ago when I was on vacation, I posted it in your reddit thread but you don't seem to be checking reddit any more - did you see this earlier?

It looks like patching the server response is not going to work, since SafetyNet checks can be done on an attestation server-side (My guess is that this is why Android Pay was not getting fixed by your module). You'll need to fool the data collection methods that are used to formulate an attestation.

Sucks that we're back in the dark ages of modified APKs and Xposed attacks on Wallet/Pay to even be able to use it again... I thought https://github.com/Entropy512/XposedWalletPatcher was never going to have to get resurrected. :(

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants