Skip to content

Add support for sandboxed tricky store-like spoofing of hardware keys for banking apps #378

@slg407

Description

@slg407

It may be possible to adapt features from trickystore (specifically trickystore-OSS) into GrapheneOS in a way that enhances privacy without introducing significant security risks.

The idea is to allow a sandboxed profile (for, for example, banking apps) to use user-provided attestation keys (including spoofing strong play integrity with those keys) instead of exposing the device’s real hardware-backed keys, which also has some extra benefits, such as preventing fingerprinting via play integrity attestation, which would in theory increase privacy while still providing (spoofed) play integrity strong attestation for apps requiring it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions