Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The bad guy can then walk the user through that security verification process, and the user is screwed. Think it through.


Let's extrapolate this to UEFI/Secure Boot.

If a motherboard displayed an error when a piece of hardware from a different manufacturer was inserted and failed to operate, we'd cry bloody fucking murder. Instead, we expect users to take responsibility and if they compromise their own machine / want to take a risk then that's their business.

Just because it's an Apple phone shouldn't reallign our morals concerning user control and responsibility.


Wouldn't touchID get disabled until the verification process was finished? They would need the user's password.


If you're targeted by a "bad guy" at this level of play, you have much bigger problems than an untrustworthy fingerprint sensor.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: