ab//

// attestation

what is Attacks on device/app attestation?

The cross-surface evasion and proxy vectors that defeat attestation without breaking the crypto: web<->app collusion (offload the attested step to a real app instance, or replay an app-minted token from a headless web client) and SDK-proxy / residential-proxy-from-phones (route through a real, consenting, genuinely-attested handset). Both convert "is this a real device" from a hard gate into a market price.. Speculative: the mechanisms are documented; specific app pairings and scale figures are inflated by operators and re-estimated by research. Distilled from the richards attestation (mobile) catalog (cross vectors).

source capture as of 2026-06-15

in the benchmark

Attacks on device/app attestation is tracked as part of the attestation taxonomy. see how tracked tools score against it on the capability matrix.

related

where to go from here