And since every app is essentially a full screen modal, this sort of PIN phishing would probably be difficult for a human to detect. I bet you could recreate the iOS passcode prompt in SwiftUI relatively simply.
And since every app is essentially a full screen modal, this sort of PIN phishing would probably be difficult for a human to detect. I bet you could recreate the iOS passcode prompt in SwiftUI relatively simply.
For iOS passcode verification, you’d need both secure input (which the UI almost certainly achieves), but also trusted output of at least one bit of information: Whether the user is currently interacting with the OS (or a trusted application) or an (untrusted) application.
If you're a standard user, you'll be asked for the administrator's username/password on the secure desktop. Also, the secure desktop encompasses other parts of the system as well, like the lockscreen or the password change option on the ctrl-alt-del screen.
>For iOS passcode verification, you’d need both secure input (which the UI almost certainly achieves), but also trusted output of at least one bit of information: Whether the user is currently interacting with the OS (or a trusted application) or an (untrusted) application.
At least on windows that's provided by the secure attention key sequence. It's not enabled by default, but there's a group policy for it: https://learn.microsoft.com/en-us/windows/security/threat-pr...
Unfortunately, it's no longer the default on Windows as you mention (presumably because OS-privileged malware is now the norm, so the net benefit is probably small?), and iOS only very rarely and inconsistently uses their secure attention sequence (i.e. the double home/lock button tap used for Apple Pay).