passforios
passforios copied to clipboard
Pass ignores Face/Touch ID authentication when autofilling passwords
As hinted by #537 when the user has AutoFill enabled for Pass, in Safari or any app requesting to autofill a password, the authentication of Face/Touch ID is ignored and passwords are filled regardless. The user may simply tap cancel on the authentication prompt.
An attacker with access to an unlocked iPhone effectively has access to any password-protected website.