Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My thought process is

* The iPhone stores your biometric data in its Secure Enclave

* The Secure Enclave also holds the cryptographic private keys

* Every action you do against the server requires your phone to add a cryptographic signature, which can only be written when the iPhone verifies you via FaceID

Apple could act as the Certificate Authority letting websites know that this signature aligns with an iPhone user. Apple may not need to let the website know exactly who performed the action, but just say that Apple verifies that this is a real person making the action.



Sure, but you still don't know who or what actually wrote the text that got posted.


Yep, that's the best part of the idea IMO.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: