5 ms·
I love how Safari fills in OTP codes from SMS messages automatically. I know you’re not supposed to use them but so many services still do.
by loopdoend 4y ago
I love how Safari fills in OTP codes from SMS messages automatically. I know you’re not supposed to use them but so many services still do.
- ridiculous_fish 4y agoThis is such a cool feature on Macs. My iPhone receives the OTP via text message, it gets forwarded to Messages on my Mac, and then desktop Safari offers to enter the code. It all takes less than a second. Do other platforms have this? Honest question, I have no idea.
- sofixa 4y agoNope. Android has this API where an app that is confirming your phone number with an SMS can automatically read it (without having access to the rest of your text messages) , but not all apps implement it (probably the majority though). This is the type of feature Apple are capable of doing because they own the full stack - phone OS, computer OS, browser. Nobody else has that (well Google do with ChromeOS but i doubt such UX is a part of their focus there). Of course the problem is that if you want to use a different browser, or Tim Cook forbid, a different mobile OS, you lose of all that because there's no interoperability. A form of vendor lock-in if you will.
- WirelessGigabit 4y agoI think this is more because Safari has access to that data. Other applications do not, as they are second-class citizens on Mac OS.
- tinus_hn 4y agoNo, it’s documented API. It’s either because it doesn’t actually work as documented, or because the other applications’ developers are lazy. https://developer.apple.com/documentation/security/password_autofill/enabling_password_autofill_on_a_text_input_view/ https://developer.apple.com/documentation/security/password_...
- frankthedog 4y agoYour link is for app development, not web.
- tinus_hn 4y agoThe comment claims Safari, an app, has exclusive access to system features, my comment shows how other apps have access to the same features. The web has nothing to do with it.
- frankthedog 4y agoI see that now after re-reading. You meant the other browser developers could add this. I first took it as saying websites could add it with some input attribute. My mistake.
- baby 4y agoOnly works if you have an iPhone right? It annoys me more and more that I’m a prisoner of the apple ecosystem. I want to buy a folding phone but it’s android.
- wintermutestwin 4y agoYes, this is why I use Safari for a handful of financial websites that use 2FA. I still use Firefox with Sidebery for all other browsing because Safari has an inferior interface and poor overall usability.
- ricardobayes 4y agoWould you be ok with the mailman going through your letters and handing you the PIN code for your amex on a post-it note? "Saved you opening it yourself."
- tinus_hn 4y agoThis only works with OTP codes formatted in a specified way so the system can make sure it’s only suggesting OTP codes and only on the website they are intended for. https://wicg.github.io/sms-one-time-codes/ https://wicg.github.io/sms-one-time-codes/
- graftak 4y agoIt also fills in OTP codes from password/TOTP managers.
- trilbyglens 4y agoSo your phone is reading a message and then sending your OTP over the network? Sounds safe...
- pontilanda 4y agoAre you talking about the OTP delivered via unencrypted SMS? Surely Apple knows how to set up a link with a barebones encryption better than SMS’