MattJI had a conversation recently with someone who wanted a mobile app to log into XMPP without requiring a username and password to be entered by the user
MattJand also be secure
ralphmm&m: which planet do you have your eyes on?
m&mCeti Alpha IV
ralphmMattJ: what did you tell him?
MattJWell the plan was to use phone number for authentication (!)
m&m/sigh
MattJBut for fun, I asked what should happen if I changed my SIM
MattJNaturally the answer was nothing - it should still work
m&m....
MattJSo phone number was out
MattJThen IMEI/other handset serial came up
ralphmso yeah, that kinda leaves the phone's own id
MattJSo I asked what should happen if I brought a new phone, put my SIM in there, and downloaded the app again
MattJNaturally the answer was that I should still see all my data :)
ralphmMattJ: so you suggested magic?
m&mso … magic (-:
m&mhehe
MattJA week after this conversation they went to someone else, who I gather is using IBR with the phone number as the username, and I-don't-want-to-know as the password
ralphmMattJ: I'm sure it uses some hash of the image of the user's face