Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The malicious person would then click "Always Allow" while they are setting up the shortcut. It might be better if it worked like the location/bluetooth prompt, where some time later, it would prompt you if you still wanted that action to occur.


Make the allow and always allow options require Face ID, Touch ID, or passcode…


You don't need them to authenticate again, as the phone would be already unlocked.

What you want to do is periodically (at a random time each time) ask the user if they still want it to do the privacy sensitive action still. This way, it vastly increases the chances of detection if the action was added by a third party.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: