Can't someone write an app that stays in the background on their phone and copies fingerprints of people who touch your button?

Under the assumption that the sandbox works, no.

I meant jailbroken, of course.

The "sandbox" being referred to is the "Secure Enclave", which apparently is what ARM calls "TrustZone": http://infocenter.arm.com/help/topic/com.arm.doc.prd29-genc-... The data isn't accessible to even the OS. So, in theory at least, jailbreaking doesn't make it any more accessible.

Ah, that's interesting, thanks, I didn't know about it.

