scottyab / safetynethelper

SafetyNet Helper wraps the Google Play Services SafetyNet.API and verifies Safety Net API response with the Android Device Verification API.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Inconsistent CTS check results

Sawaba opened this issue · comments

Skycure's security app alerted me that my Samsung Note 5 failed CTS check and therefore was suspected of having been tampered with. I downloaded Safetynet Helper and Cigital's Safetynet Playground for second opinions.

Cigital's app tells me everything is fine every time I run the test.

Safetynet Helper gives me seemingly random results. So far, the first result is always negative (CTS =false), but pressing it again results in CTS = true within 1-2 retestsAs I continue to retest, it continues jumping back and forth between true and false results.

also have a cts mismatch and PoGo is working, who's to believe?

In testing, I noticed back and forth results for Android N devices when Android N was in beta FWIW.

I've updated the lib and the sample app in the playstore to use the latest version of safetyNet. Once the updated .apk has perticulated to your parts of the world @Sawaba @simonbuehler I'd be interested to hear if you get the same results.