This video as a text article: https://blog.nicco.love/google-drms-the-web/
9 points
The same host could fake the payload to the attestation server. Cat and mouse game with security through obscurity.
7 points
If you are on android or ios the phone already cryptografically verifies that the operating system has not been tampered with on a hardware level. Since the operating system is then “trusted” it can verify anything you do on it
7 points
Doesn’t work. It’s possible to let many banking apps think they are running on a normal device although it is rooted.
6 points