3 ms·
The malicious person would then click "Always Allow" while they are setting up the shortcut. It might be better if it worked like the location/bluetooth prompt,
by extrapickles 7y ago
The malicious person would then click "Always Allow" while they are setting up the shortcut. It might be better if it worked like the location/bluetooth prompt, where some time later, it would prompt you if you still wanted that action to occur.
- MaysonL 7y agoMake the allow and always allow options require Face ID, Touch ID, or passcode…
- extrapickles 7y agoYou don't need them to authenticate again, as the phone would be already unlocked. What you want to do is periodically (at a random time each time) ask the user if they still want it to do the privacy sensitive action still. This way, it vastly increases the chances of detection if the action was added by a third party.