Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I am not an iOS dev. What is the significance of App Attest wrt the loophole used here?


With attest, Twitter can tell if there's an actual mobile device hitting Twitter with that bearer token versus today, you can spoof the client and unless they fingerprint the IP address or other subtleties, it's hard to distinguish fake traffic from real traffic.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: