Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm surprised they're willing to trust a mouse click on a notification. (Can't that be simulated by malware by using the Accessibility APIs?) I was expecting a U2F authenticator that wanted a Touch ID touch first.


Malware is a game-over scenario either way. It can simply steal your session keys or send requests from your browser with an active session.

That said, there seems to be some sort of TouchBar integration[1]. It doesn't currently store the keys in SEP, but that might become an option at some point[2].

[1]: https://twitter.com/mastahyeti/status/889546786221678592

[2]: https://twitter.com/mastahyeti/status/889548782035124224




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: