3 ms·
tl;dr version: it shouldn't be possible to pull out somebody's account information based solely on the UDID. It's simply wrong to authenticate people based sol
by bitanarch 15y ago
tl;dr version: it shouldn't be possible to pull out somebody's account information based solely on the UDID.
It's simply wrong to authenticate people based solely on UDID anyways - what if the same user have one iPhone 3GS, one iPhone 4, and an iPad 2? In that case you'd need another authentication mechanism to make sure the three devices belong to the same user. The UDID is good only for telling the devices apart. So if you gave me Jane's iPad's UDID, I shouldn't really do anything unless I've made sure you're Jane in the first place.
- MichaelApproved 15y agoOr what if I sold my device to someone else. Does that mean they can login as me with my old phone and udid?
- sathyabhat 15y agoYes, that's what happened to me. I sold my iPhone 3G to my friend ( obviously, I had wiped it before handing it over to him). Now, I had Fruit Ninja installed, and I had signed up for openFient.. and approved the facebook connect. Imagine my surprise when a day later - my friend installed Fruit Ninja - so not only did it log me in, it also published to my facebook wall as me. Ended up revoking permissions - something which I should have done, but forgot to do so.
- smackfu 15y agoThe OpenFeint model is to use device-level accounts so you don't need to make people sign-up to the service. If they choose to create an email based account with a password, then they can tie their various devices together.