SafetyNet api, get nonce from server, not client

I use this library: https://github.com/scottyab/safetynethelper
I read the documentation on the Android Deveoloper website and in the repository. Everything is working fine, but something is not clear to me. It is indicated that it is safer to receive nonce from the server, rather than creating it on your application. And why is it better to transfer the response from the SafetyNet API to the server.

+4
source share
1 answer

The most common SafetyNet security APIs are used to determine if you trust the device and application that communicate with your server.

, JWS Android, , , . ( ).

, , , , , -in .

nonce? Unce, ( , , ), . , nonce! , JWS , , nonce .

nonce .

+5

Source: https://habr.com/ru/post/1659546/


All Articles