Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Considering there is no 'active' part (e.g. no known secret) it cannot be used for authorization, only for identification. The 'kids unlock phone with sleeping parent and buy stuff' techniques are a clear proof of this. Fine for identification, do not use for authorization (e.g. using secrets like when you buy stuff).


I'm still fine with this threat vector. The idea is to prevent casual intrusion, not premeditated intrusion. If I put my phone on the dinner table, no one is going to send text messages.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: