Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Technically nothing.

In practice, banks will demand remote attestation of the environment the app is running in.



Does anyone have a recommendation for a good "Remote Attestation 101" tutorial? I'm trying to wrap my head around why someone couldn't just run an Android emulator to run your banking app or whatever. I mean there then must be hardware keys that are not present in the code, but then there must be a revocation method for compromised hardware keys, etc..




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: