Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Was going to ask the something. And also, so the omnipod app is not using android attestation but stores private key it got from omnipod server?


It seems to use the play integrity API when communicating with Insulet's servers which provide a private key to the PDM/app once it was registered with the user's account. However since the Pod doesn't have access to the internet, it has no way to check the play integrity signature AFAIK, so instead it checks that the certificate that the PDM/app presents to it is issued from the cert chain that it trusts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: