34C3 - Inside Android’s SafetyNet Attestation: Attack and Defense

Title:
34C3 - Inside Android’s SafetyNet Attestation: Attack and Defense
Description:

https://media.ccc.de/v/34c3-8725-inside_android_s_safetynet_attestation_attack_and_defense

SafetyNet Attestation is the primary platform security service on Android. Until recently you had to use third party tools or implemented your own app integrity checks and device rooting checks. Today you can use Android's SafetyNet Attestation infrastructure to ensure the integrity of your application and the user's device. Unfortunately, SafetyNet Attestation is not well documented by Google. This talk is split into three parts. Part one provides a deep dive into SafetyNet Attestation how it works. Part two is a guide on how to implement and use it for real world applications. This is based on the lessons learned from implementing SafetyNet Attestation for an app with a large install base. The talk will provide you with everything you need to know about Android’s SafetyNet Attestation and will help you to implement and use it in your app. Part three presents attacks and bypasses against SafetyNet Attestation. The attack method targets not only SafetyNet but other similar approaches. New tools and techniques will be released at this talk.

Collin Mulliner

https://fahrplan.events.ccc.de/congress/2017/Fahrplan/events/8725.html

more » « less
Video Language:
English
Duration:
59:11
http://www.youtube.com/watch?v=8lv_9mydrjg
Format: Youtube
Primary
Original
Added   by C3Subtitles
Format: Youtube
Primary
Original
http://www.youtube.com/watch?v=46jS-rbB3Ik
Format: Youtube
Added   by C3Subtitles
Format: Youtube
This video is part of Amara Public.

Subtitles download

Incomplete subtitles (1)