Live data from Hacker News

Face ID and Touch ID for the Web

developer.apple.com

131–140 of 274 posts

Re: Face ID and Touch ID for the Web

#131
post #88

Earlier quoted context omitted.

From the server side, isn't this just a WebAuth integration? How does the server know for sure if the client is on an iOS Safari browser on an iPhone with FaceID or a custom browser on any OS and any non-locked-down hardware being run with Selenium?

The question is more along the lines of: does this provide more security than passwords for real users? Stealing a password is probably more easily done than stealing a private key that is never transmitted. The primary threat model is protecting the credentials of real users rather than protecting against fraudulent users (though some considerations have been made for that too).

While what you say is true, it doesn't seem relevant to this thread.

Re: Face ID and Touch ID for the Web

#132
post #103

What exactly does attestation do vs not having it? Can someone here explain clearly?

The attestation is a signed (digital) document saying basically "We are $manufacturer and we made this $product and we promise it has these desirable security properties".

In WebAuthn the design is that a batch of (at least 1000 but usually far more) authenticator products should have such a document which Javascript can optionally request (together with proof they didn't just knock it off from another authenticator) when using the authenticator.

If you demand multi-factor and aren't willing to take my word (as the user) that I'm using it, you could insist upon seeing the attestation and reject authenticators unless you can see the attestation and you like it. For example maybe Great American Bank accepts Yubikeys, but rejects the Apple iPhone because they believe Steve Jobs was Satan.

Most sites should not use attestation at all. Firefox in particular can tell a site to fuck off when it asks for attestation. I'm happy to use high security WebAuthn but I don't want to have to tell you which products I use to do it. If your site does not require WebAuthn for every user then almost by definition it makes no sense to demand attestation from users who choose to enable it.

The use of "batches" is a privacy safeguard. If you permit attestation a site might know you have a Mattel Barbie Authenticator, but it won't know which one. If Mattel aren't selling many they probably put the same batch on the Buzz Lightyear Authenticator so a site can't even tell if you've got a Barbie or Buzz Lightyear.

According to this video apparently (?) Apple thought that wasn't safe enough and so it has decided to do something else weird instead, but not yet. Whatever, for almost all web sites you should refuse attestation if given the option. Maybe my bank needs to know I'm doing MFA with a high quality product but there's no reason Facebook or GMail or anybody like that should ask.

Re: Face ID and Touch ID for the Web

#133
I dont see a problem with this as part of MFA, but here in the US our fifth amendment protections are pretty lax, and only cover passwords (sometimes). If the police wanted to force your fingerprint or face ID to log into a website (say, maybe a protest message board), they can do it just the same as they can force your blood draw during a DUI with a warrant from a judge.

Re: Face ID and Touch ID for the Web

#134

The keynote a few days ago failed to mention FaceID used to opening your mac... and this video shows/mentions FaceID on a macOS11 website? Seems they missed a step here with rolling it out, or are withholding the obvious. I'm assuming the latter.

Apple supports WebAuthn on iOS/iPadOS as well (since iOS/iPadOS 13) so presumably FaceID part is referring to iOS/iPadOS.

Re: Face ID and Touch ID for the Web

#135

Earlier quoted context omitted.

It's funny how much bashing Google gets for monopoly with Android, pushing users to use Chrome, Play Store and whatnot. While all of that is relevant, Apple's stranglehold seems much more and worse.

Apple sells between 10-20% of smartphones per quarter[1], that implies Android makes up 80+% and Windows/Blackberry a neglible amount. How can Apple be a monopolist from such a small position, or have a "stranglehold" when they are outsold 4-8x by the competition? [1] https://www.statista.com/statistics/216459/global-market-sha...

So you are comparing Android vs iOS. You cannot see how that is Apples Vs Oranges? Just because something is based on Android doesn't make Everything Android vs iOS a direct comparison. Try Google Phones Vs Apple phones or Huawei vs Apple.

Re: Face ID and Touch ID for the Web

#136

Earlier quoted context omitted.

They didn't develop the capability to backdoor phones at the FBI's request. They are generally happy to hand over iCloud backups, which they did in that case and the FBI "lost" them IIRC. It was also an iPhone 5c, the last iPhone without a Secure Enclave, I believe they were able to get in with GrayKey.

> They are generally happy to hand over iCloud backups That one they legally have to do when given a subpoena.

They could encrypt everything and not have the keys. So not really.

Re: Face ID and Touch ID for the Web

#137
So for the non-developer, is this basically as if any participating website could send an 2FA request to your iPhone (like the role of the SMS code but more secure), have the iPhone verify you by face/touch, and then confirm back to the website and let you in? (also like Google does with their app?). Or even take the place of a password?

Re: Face ID and Touch ID for the Web

#138
post #58

Earlier quoted context omitted.

Apple users will get this natively without having to acquire 1Password. If you’ve bought into the Apple ecosystem and don’t have needs outside of it (Windows, Linux), you can eliminate the need for a separate password manager. Similar to how iCloud Files is moving towards (but likely won’t meet, while not needing to) Dropbox parity. This is making a friendly version of Yubikeys (using Apple devices) and password vaul…

For interested readers: 1Password does a few more things. For example, you can add 2FA to 1Password logins, so that 1Password replaces Google Authenticator with the immense advantage that you don’t have to setup 2FA again if you get a new device. Just a happy 1Password user, nut related to them in any way.

I use LastPass for passwords and Authy for 2FA. I like the idea that two different programs have to be attacked to get access to Google, Facebook, etc. There's a little bit more friction than having both in one program but that's the point.

Re: Face ID and Touch ID for the Web

#139
post #68

I think it's pretty ridiculous that Apple pours time and effort into stuff like this but apps have been able to steal from your clipboard for years. It reminds me of the phenomenon when researchers and engineers don't work on something that's useful for everyday users, instead prioritizing what they find exciting and cool. The security team is so busy dealing with absurd edge cases like nation-states attacking your e…

i don't want to focus too much on why i think you're being downvoted but i would say it's probably because your message came across as quite reductive.

> engineers don't work on something that's useful for everyday users, instead prioritizing what they find exciting and cool

i get this, to some extent. i really do. but i don't think WebAuthn, sign in with apple, ios 14's recent microphone and camera usage indicators, etc. are not huge steps forward in terms of mobile privacy & security. (rough double negative. you get me.)

i am pretty sure Apple knows about everything you stated, and would wager they are developing, or at least R&D'ing, effective, polished, "Apple" solutions to these problems.

clipboard is a bit of an obscure one, but is absolutely a problem and must be addressed. but Apple is in the business of juggling user experience and privacy. it's quite difficult, because you don't want to get in the way of the user's intents and make things way hard to do. but you also don't want to make things so easy that bad actors can get away with bloody murder.

granted, they still can, if they really want, but it's way harder. and slowly apple is killing the mice. it's a cat and mouse game. i think they're doing exactly what they should be.

could they be doing more? hell yes. they should -always- strive to do more. but right now, this is better than last year, and the year before that, and the year... yknow.

Re: Face ID and Touch ID for the Web

#140

Earlier quoted context omitted.

Client certificates suck in a bunch of ways that WebAuthn, specifically designed to solve this problem, does not. Example: If the certificate used to sign into Hacker News as "sneak" is also used to sign into PornHub then I can correlate that to discern that "sneak" on HN uses PornHub. Whereas you can't do that with WebAuthn credentials - a separate credential is spun up for every single registration, it's completely…

There's no reason a browser couldn't have generated a new self-signed client certificate for each site, though; the fact that they don't offer that as an option is just a browser design decision.

There was actually a html tag used within s to generate a keypair what was then supposed to be signed by the server and finally returned to the browser for local installation. At least that's how I understand it. It's been deprecated for a while now.
Post reply on HN