Apple already shipped attestation on the web, and we barely noticed - eviltoast
  • CarbonIceDragon@pawb.social
    link
    fedilink
    arrow-up
    5
    ·
    1 year ago

    Hypothetically, I wonder if it would be possible to spoof this if you also had an actual unmodified attested device. Something like a device in your home network that would, if you have an iPhone as well as an unattested computer that you actually want to use: get request for attestation from a website, send that request to your iphone instead, as if your iphone had opened the page and was receiving the request (or just have the iphone also try to load the page), intercept the signature the iphone sends to the website, and have your computer send it to the website instead.