There are leaked keyboxes in circulation right now that pass Play Integrity and Key Attestation as genuine hardware and enable attackers to carry out eKYC fraud. Google will revoke them eventually, but until it does, every service relying on a standard attestation verdict is trusting devices that should already have been flagged. Here at Licel, we already know which ones they are, as we see maliciously used keyboxes two months earlier on average. This intelligence is live in Alice RDA right now and is available to a limited number of our clients.
It’s vital intelligence, because the interval between discovery and revocation is where credential stuffing, eKYC bypass and payment fraud operate under a valid hardware identity.
When revocation does arrive, it gives you one piece of information: whether it has been revoked or not. But that is not the distinction you need. After all, a certificate being actively weaponized and a certificate belonging to a device that will simply never receive a renewal are very different problems. One is an attacker, and the other is a legitimate customer you’re about to block.
In this edition of the Layers Bulletin, we examine what evidence is worth from three different angles. We lead with an article by Licel CEO and Co-Founder, Ivan Kinash, in which he explores the gap between a verdict and the truth, and what’s at stake for banks and financial institutions. Our August DexProtector releases are about hardening what happens when a verdict cannot be trusted. And we share news about our latest third party verification (for ISO/IEC 27001 and Cyber Trust Mark surveillance audits) because we continue to believe that in our industry, the best evidence is that which comes from an independent, trusted evaluator.
Hardware-Backed is Not the Same as Fraud-Proof
Forged keyboxes are just one version of a wider problem. A signal can be technically valid and still tell you nothing about whether the interaction in front of you is genuine.
It’s a gap that runs through much more than attestation alone. For example, a key held in secure hardware may never leave the device but could still be used to authorize a transaction your customer never saw.
Ivan has been thinking about this problem in one form or another for the last 15 years, so it’s the perfect subject for his latest article. He argues where trust actually sits in the mobile channel, and why platform security can never fully answer the questions banks and other financial institutions desperately need answers to.
What's new with Licel's solutions?
August’s DexProtector releases for Android and iOS
August's DexProtector releases deliver further security enhancements and platform improvements across Android and iOS.
On Android, runtime protection has been further reinforced with enhanced anti-memory dump capabilities designed to make it more difficult for attackers to extract and inspect sensitive application data at runtime. New internal self-protection mechanisms within the DexProtector Runtime Engine also strengthen its resilience against tampering, reverse engineering and runtime analysis, adding further layers of defense against increasingly sophisticated attack techniques.
On iOS, compatibility has been improved for applications that load protected Frameworks within extension processes, helping ensure more reliable protection across a wider range of application architectures and use cases. Performance optimizations have also been introduced for Public Key Pinning (PKP) and Certificate Transparency (CT) checks, reducing the runtime overhead associated with these network security controls while maintaining strong protection against man-in-the-middle attacks and analysis of API requests and responses.
Licel Completes ISO/IEC 27001 and Cyber Trust Mark Surveillance Audits
We completed our annual ISO/IEC 27001 and CSA Cyber Trust surveillance audits this month with no non-conformities. That's the expected outcome, but what stood out was the auditor's conclusion: that the evidence reflected an information security management system that genuinely operates, rather than one that exists on paper.
It's a distinction we make about security generally: that it shouldn't simply be claimed but rather it should be demonstrated, independently assessed, and continuously maintained.
Thanks for reading this edition of the Licel Layers Bulletin. If you’d like to know what your attestation stack is not telling you, talk to us.
We'll be back next month with more product improvement updates and threat intelligence insights.