Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There is no "accessing the secure enclave". Not even the iOS kernel itself can access the secure enclave. That's the point. It's designed to keep your biometrics and private keys safe even when the entire OS is compromised.

It's also not completely relevant to third party payment processors. They don't have to use the secure enclave at all. They could theoretically just ask for your credit card info every time. They're not allowed to do that currently for no other reason than Apple's bottom line.

For convenience, they'd probably want to store it encrypted on your device, using a private key from the secure enclave to decrypt it when you pass the biometrics test. That's the normal level of "access" to the secure enclave that all apps should have. It's in no way concerning because private keys and biometrics never leave the enclave, but can still be used to decrypt data elsewhere on the device when the biometrics test is passed. It's the whole reason why the secure enclave exists in the first place.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: