Hacker Newsnew | past | comments | ask | show | jobs | submit | more zuprau's commentslogin

iPhones can only do what Apple allows developers to do, which isn’t much.

A random payment provider can’t use NFC on the iPhone, but they can use the camera. So here we are. QR payments are super popular all over Asia (and yes they suck, but you can blame Apple)


Wrong. You know it never ends up being 100kb, and when it reaches 1MB (it always does) then you get the real issues.

It’s because of your thinking that we got bloated webpages.


> somebody who has never worked as a professional UI/UX designer

Such as the Nielsen Norman Group.

> "Do not use modal dialogs for nonessential information that is not related to the current user flow."

> From https://www.nngroup.com/articles/modal-nonmodal-dialog/

Nonessential information such as, let's say, "details."

I'd say that this minisite is exactly on point.


Preach.

You don't even necessarily need to place it in a new page, probably you can just expand it inline.

Most modals are just lazy.

"Where should I put this piece of UI/information?"

"Just place it above everything else."

With SPAs you don't even have an excuse that "a full-page reload will take longer" because you can change the whole page/layout instantly.


> relatively new security feature

Maybe I'm misunderstanding the feature, but I've been auto-filling login forms since I was using IE7 with RoboForm. Other than using Touch ID to trigger the auto-fill instead of 1 click, I don't see any improvements in iOS/macOS Safari.


You leave all your password on the iCloud, accessible by AppleID but that AppleID password is so powerful and covers many more sensitive things (AppleWallet, ApplePay, ...)

Whereas, using a separate PIN/passcode at application-level provides a separate (master) password which would be used for all your passwords (in case your AppleID password gets compromised).

I do not use touchID nor FaceID because it violates the Principle of 3 Factors of Authentication: AppleID merges two of three factors:

1. "what you know (memory rote)" with

2. "what you have (biometric)".

https://www.cs.cornell.edu/courses/cs513/2005fa/NNLauthPeopl...


> using a separate PIN/passcode at application-level provides a separate (master) password which would be used for all your passwords (in case your AppleID password gets compromised).

That already happens exactly as you mentioned.

You need a secondary encryption password for encrypted iCloud data as well. Having access to your Apple account isn't enough.

https://support.apple.com/en-ph/HT202303#:~:text=Apple%20wil...


THIS!

Apple finally provides a modicum variant of Zero Knowledge password.

But that is only available in next iOS version 16.2. [1]

But, but ... BUT the Apple macOS/iOS issue of Three Form of Authentication being still being reduced into Two-Form with their merge (OR-logic) of what you have (FaceID/TouchID) and what you know (PIN/passcode) ... remains.

That reduction of authentication is still the greatest weakest link to individual security (whether ADP is used after v16.2 or not).

https://support.apple.com/en-ph/HT202303#:~:text=Apple%20wil...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: