@
kokutou #26 小米这样做本来就是不合规的。如果想以安全换取便利而非要和小米那逆天的解锁政策硬碰硬,那当我没说。
https://source.android.com/docs/compatibility/14/android-14-cdd[C-1-4] MUST prevent adding new biometrics without first establishing a chain of trust by having the user confirm existing or add a new device credential (PIN/pattern/password) that's secured by TEE; the Android Open Source Project implementation provides the mechanism in the framework to do so.
[C-2-3] MUST perform the biometric matching in an isolated execution environment outside Android user or kernel space, such as the Trusted Execution Environment (TEE), or on a chip with a secure channel to the isolated execution environment or on Protected Virtual Machine that meets requirements in Section 9.17.
[C-2-7] MUST NOT allow unencrypted access to identifiable biometric data or any data derived from it (such as embeddings) to the Application Processor outside the context of the TEE or the Protected Virtual Machine controlled by hypervisor that meets requirements in Section 9.17. Upgrading devices launched on Android version 9 or earlier are not exempted from C-2-7.