Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What happens when someone's fingerprint matches up with another? Do they get access to data that they shouldn't have access to?


Unfortunately, there is a very low probability of the mismatch until we have effectively seen every device. As our linking service expands, that percentage gets lower and lower. In our experience, the user experience and analytics insight benefit far outweighs the consequence of a mismatch because they are so rare. We encourage our developers not to bundle sensitive data into the links if they use this base case.

If a developer does want 100% match, we have a separate option that can be used with a slightly degraded user experience which pops the browser open really quickly to check the cookie, then returning to the app with the URI scheme.


FWIW, Apple has frowned upon the browser cookie check approach and they might reject a submission using it: http://techcrunch.com/2013/02/25/apple-rejecting-apps-using-...

Do you guys have any estimates as to what the rate of error might be for the fingerprint approach?

Excited to see where you guys are going with this product!


Ah interesting. We wouldn't be using it in every scenario, basically only scenarios where we believe there to be a match and want 100% confirmation.

Thanks for sharing!


Wouldn't the chance get higher and higher as the service expands? It seems as though there would be more existing fingerprints that might collide.


Dmitri from Branch here. When a user has already had a fingerprint matched once, we can do future matches with much higher certainty, so as more and more users click links and are matched, the chance decreases.

Additionally, as Alex said, though most uses of the links don't require a 100% match rate ("any growth is good"), we do have an option for links which require a 100% match.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: