kSecAttrAccessControl vs kSecAttrAccessible for biometric least-privilege
When implementing least-privilege authentication for sensitive credentials in Objective-C, developers must choose between granular access control and device-state protection levels. The kSecAttrAccessControl attribute allows for specific biometric requirements, such as FaceID or TouchID, ensuring that the item is only released upon active user verification.