Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I would be perfectly happy to receive a popup that an automation had just run. Also, Apple has been pushing for self-adjusting notification preferences. Imagine a popup like:

"The shortcut 'Foo' wants to run. Do you want to allow it?

- Never

- Not this time

- Run once

- Always"

Put an icon next to each shortcut showing whether it's always (or never) allowed, and it seems like the problem would be largely solved without asking much from the end user.



The malicious person would then click "Always Allow" while they are setting up the shortcut. It might be better if it worked like the location/bluetooth prompt, where some time later, it would prompt you if you still wanted that action to occur.


Make the allow and always allow options require Face ID, Touch ID, or passcode…


You don't need them to authenticate again, as the phone would be already unlocked.

What you want to do is periodically (at a random time each time) ask the user if they still want it to do the privacy sensitive action still. This way, it vastly increases the chances of detection if the action was added by a third party.


This sounds like a very reasonable solution. I kinda hope this is the way they end up solving it, if this really is the reason they're not truly automatic.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: