logoalt Hacker News

idontwantthistoday at 12:33 AM1 replyview on HN

Is this not easily patched by the provider encrypting and signing the whole payload? I would have thought that would be table stakes for an identity provider.


Replies

arcologies1985today at 1:18 AM

The identity provider is on-device and has to run on phones which don't do hardware attestation.

show 1 reply