Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We are using the UDID as an extra precaution in an app currently. The user logs in with username, password and UDID. If the device is stolen the UDID for that user's device can be easily removed. We are dealing with sensitive data that needs a killswitch when things do go wrong. Guess we will have to come up with a new approach.


You could just store a randomly-generated authentication token on each device and allow the user to revoke any/all authentication tokens after entering their username/password in the app or on a website, if that's not what you're doing already.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: