Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Make the allow and always allow options require Face ID, Touch ID, or passcode…


You don't need them to authenticate again, as the phone would be already unlocked.

What you want to do is periodically (at a random time each time) ask the user if they still want it to do the privacy sensitive action still. This way, it vastly increases the chances of detection if the action was added by a third party.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: