Re: [sensors] Avoid PIN skimming attacks

> @pozdnyakov http://www.gsmarena.com/results.php3?idQwerty=1 . Common denominator is 'user input' so, we have to protect it regardless of input type (hw / sw) :-)

Less than one third from this list has at least one motion sensor
http://www.gsmarena.com/results.php3?chkAccelerometer=selected&idQwerty=1
http://www.gsmarena.com/results.php3?chkGyro=selected&idQwerty=1

I'm not arguing that we should take care about all the input methods, and I'm not challenging the  `<input type="password">` protection proposal :)

But I'd like to point out that reacting on virtual keyboard appearance is quite a "low-hanging fruit" in terms of implementation and at the same time it is efficient for _most_ of the clients.

-- 
GitHub Notification of comment by pozdnyakov
Please view or discuss this issue at https://github.com/w3c/sensors/issues/189#issuecomment-299141949 using your GitHub account

Received on Thursday, 4 May 2017 09:52:28 UTC