Why Mobile Apps Use Attestation Instead of Fingerprints
Web detection infers what a client is from what it reveals. Native applications have access to a stronger mechanism, in which the platform itself makes a signed statement about the device and the software running on it.
The platform vouches instead of the app
Attestation is performed by the operating system, which holds keys backed by hardware and produces a signed assertion about the current state of the device and the requesting application.
The assertion is verified by the app's server against the platform vendor's published keys, so trust flows from the vendor rather than from anything the app itself claims.
This is qualitatively different from fingerprinting. It is a verifiable statement from a party with privileged visibility rather than an inference drawn from observable properties.
Binary integrity is part of the claim
The assertion covers the identity of the requesting application, confirming that the caller is the genuine published build rather than a modified or repackaged copy.
This matters because a modified client can be made to send anything, and no amount of client-side checking inside a modified binary is trustworthy.
Attestation moves that check outside the binary entirely, which is the only place it can be performed meaningfully.
Device state is included
The platform also reports whether the device is in a state it considers intact: secure boot verified, system integrity maintained, and no unauthorised modification of the operating system detected.
These properties are observed by the platform at a level no application can reach, and they are exactly the properties an application would otherwise attempt to infer unreliably.
Devices that fail these checks are not necessarily hostile. Development devices and modified but legitimate installations fail too, so treating a failure as proof of abuse creates its own errors.
It answers a narrower question than identity
Attestation establishes that a genuine app is running on an intact device. It does not establish who is using it, and it says nothing about intent.
Assertions are also designed to avoid providing a stable device identifier, since platform vendors treat cross-app tracking as something to prevent rather than enable.
A device farm of unmodified phones passes attestation completely, which is why the technique addresses tampering rather than coordinated abuse.
The web equivalent is contested
Proposals to bring similar assertions to browsers have met sustained objection, because a platform vouching for a browser gives platform vendors influence over which browsers sites accept.
The concern is that such a mechanism could disadvantage independent browsers and user modifications, which is a structural question about the open web rather than a technical one. That tension is why attestation remains normal in apps and unsettled on the web.