attestation: update verdict status to CRITICAL for non-Verified boot … - #3
Merged
Conversation
…+ ship proof Updated the tee_integrity_verdict status: any boot state that is not Google- Verified (SelfSigned/yellow, Unverified/orange, Failed/red) is now CRITICAL (previously MEDIUM for self-signed, HIGH for unverified) and no longer earns MEETS_DEVICE_INTEGRITY. A custom-signed or unverified boot is the unavoidable footprint of a modified OS (custom kernel / ROM / KernelSU) => most probably rooted. The finding now carries hardware-attested proof of why: verified_boot_key_sha256 (the boot-signing key, which is not Google's on a modified device) plus an os_modified_proof message tailored per boot state. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
self-signed (yellow): now CRITICAL and BASIC-only (drops MEETS_DEVICE_INTEGRITY). unverified (orange): now CRITICAL (was HIGH). Reasons unchanged. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
…+ ship proof
Updated the tee_integrity_verdict status: any boot state that is not Google- Verified (SelfSigned/yellow, Unverified/orange, Failed/red) is now CRITICAL (previously MEDIUM for self-signed, HIGH for unverified) and no longer earns MEETS_DEVICE_INTEGRITY. A custom-signed or unverified boot is the unavoidable footprint of a modified OS (custom kernel / ROM / KernelSU) => most probably rooted.
The finding now carries hardware-attested proof of why: verified_boot_key_sha256 (the boot-signing key, which is not Google's on a modified device) plus an os_modified_proof message tailored per boot state.