6 ms·
The AppStore. It's the worst offender.
by div 14y ago
The AppStore. It's the worst offender.
- Cloven 14y agoThe good thing about the AppStore password timing out after 15 minutes is that you can hand your child the ipad/iphone/etc. and not get a surprise $5,000 itunes bill.
- untog 14y agoThat's an edge case, though. Why not make it a configurable option?
- bmj 14y agoThis is definitely not an edge case. How many kids do you see at the grocery store with their noses in an iPhone will their parent(s) shop? That said, it would be nice to have the option of telling the app to cache your credentials.
- untog 14y agoEdge case was perhaps the wrong term. It certainly is not a majority case. As I said- make it an option, everyone is happy.
- sirclueless 14y agoNot the person who turns on the option to make their life easier and then complains because their kid spent $400.
- untog 14y ago?! Are you suggesting that everyone should be denied the choice because some people are unable to make informed decisions?
- yuliyp 14y agoThis is confusing authentication and authorization. Is this phone legitimately tied to this Apple ID? Yes. Is the owner of the account authorized to make such a purchase? No. A short appstore PIN could solve this much more easily.
- radq 14y agoI'm not so sure having _yet another_ PIN for users to remember would be a good idea. And besides, a short PIN would be far easier to deduce by looking over a person's shoulder.
- coob 14y agoIt is a configurable option (Settings -> General -> Restrictions)
- extempore 14y agoYeah, it's configurable between "Demand my password again if 15 minutes has passed" and "Demand my password again immediately." You can tell you're going in the wrong direction when you first have to "enable restrictions" hoping to relax the restriction. I take it you've never actually tried to configure this option.
- moron 14y agoOh my god that is so not an edge case.
- chris_wot 14y agoHoly not an edge case Batman! That is most definitely a very common reason to timeout the password...
- dmitriy_ko 14y agoHow about using fingerprint scanner for authentication? Or face recognition using front-facing camera? It's 2012 after all.
- einhverfr 14y agotoo many false positives. Now, an SD card with a certificate plus face recognition might be ok ;-)
- ricardobeat 14y agoWhy an SD card? The phone itself is already a portable device you control.
- einhverfr 14y agoIt depends on the app but at least in the areas I work (business apps relating to tracking money) I wouldn't assume that device authentication is sufficient. But for biometrics, keep in mind that biometric systems are currently seen as the most subject to false positives of any authentication system out there with the possible exception of improperly maintained and insufficiently strong passwords.
- _morgs_ 14y agoThe Samsung Galaxy S3 has face recognition. It can be unlocked using a photo of the user. Google Images search, point cam at laptop, bingo you're in.
- nileshtrivedi 14y agoThey "fixed" this in JellyBean.
- sil3ntmac 14y agoOnly problem I have with AppStore is that it requires my password for free downloads. Paid download? Hell yes, require my password if I haven't typed it in for 15 minutes.
- harryf 14y agoI have kids. I'm happy they _always_ ask for a password... Free apps can be malicious e.g giving away location to parties unknown. But still you're right - this could be an option users can decide.
- jiggy2011 14y agoThis is part of a deeper problem with most mobile OSes. I might give my phone to somebody so they can make a quick call or look something up online. However, I don't really want them being able to dig through my history or be automatically logged into my email etc. If I had a child I'd want to be able to let them use my phone but only in a special mode that allowed access to a limited number of whitelisted websites & apps.
- dredmorbius 14y agoSchneier today: http://www.schneier.com/blog/archives/2012/07/all-or-nothing_1.html http://www.schneier.com/blog/archives/2012/07/all-or-nothing... http://cups.cs.cmu.edu/soups/2012/proceedings/a2_Hayashi.pdf http://cups.cs.cmu.edu/soups/2012/proceedings/a2_Hayashi.pdf But: yes. I'd like my phone to offer a few different "shells" of access: - Emergency calls. - "Share" or "play" mode. Selected photos or apps. - "Mobile" -- ready access to stuff I need, but not distractions (the "Car Panel" on some Android phones is somewhat like this, but I'd appreciate if it didn't encourage use while driving). - "Full" complete and potentially immersive access.
- maigret 14y agoThere are currently a few projects ongoing with enabling VMs on smartphones. The way it was thought is that you would put your corporate stuff on a protected VM that would have no external app install, and the rest (games, social networks...) would be on the "fun" VM. That way, the company data would be better protected.
- flyt 14y agoiOS 6 removes the needs to enter passwords for app updates. finally.
- pooriaazimi 14y agoI haven't lied if I say it's one of the sweetest things I've found in iOS 6.