Live data from Hacker News

Face ID and Touch ID for the Web

webkit.org

71–80 of 371 posts

Re: Face ID and Touch ID for the Web

#71
post #50
post #33

Earlier quoted context omitted.

"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)

> I would definitely stay away from any "Sign in with Apple". I would stay away from any "Sign in with.." service as a user and as a product owner. You're affectively giving away a major control of your users to a third party.

As a product owner, why wouldn't I want to piggyback on the millions of dollars of R&D + security that the big companies have put in?

And as a user, why would I trust my password to the website that rolled their own authentication over the big companies?

Re: Face ID and Touch ID for the Web

#72

Earlier quoted context omitted.

That doesn't make sense. Username + Password is a cumbersome workaround because (so far) machines couldn't use biometrics to authenticate a user. Now they can, so we can let go of that very problematic and often insecure model. Think like this, when you go to visit your grandmother and knock on her door you don't have to provide a password. You don't have to provide anything, because the human brain is capable of det…

Biometrics fails every test for a password. 1) A password is secret 2) You don't leave copies of it lying around everywhere 3) You can change it periodically 4) If discovered, it can't be traced back to you No, biometrics can only be a username. It can never be an acceptable password.

You don't seem to be aware of what is under discussion here. You just raised a huge strawman.

Websites are not receiving your biometrics in this context, and your biometrics would be meaningless to the website if captured and somehow provided.

Your biometric signature is stored solely inside the Secure Enclave in the Apple device.

If and only if the Secure Enclave recognizes you via your biometrics will the Enclave uses a non-transferrable key stored only in the Enclave to attest to the website that you are the user "JoeAltmaier".

- The key is secret.

- The key is kept in only one place.

- The key can easily be discarded and a new one made.

- The key is never given to anything outside of the Enclave, so... I'm not sure how it could be traced to you, besides the whole fact that it is being used to authenticate you, which is necessary.

Sounds pretty acceptable to me as a password. The usability issue here is that a website needs to be able to accept a different password from each device you own, since the password is non-transferrable, and you might accidentally drop your iPhone to the bottom of the ocean.

Good news: FIDO2 is an entire standard built around this concept, originally intended for use on YubiKeys and similar FIDO2-compliant USB sticks.

Apple is building an implementation of FIDO2 that uses the iPhone that's already in the person's hand.

If the Secure Enclave is compromised (which does happen sometimes), then Bad Things could happen... but that's also what happens when a password manager tool is compromised.

Re: Face ID and Touch ID for the Web

#73
post #41
post #36

Earlier quoted context omitted.

Apple did not terminate Epic's SiwA account, and several journalists have sources within Apple that say that Apple never sent the message Epic claimed to receive that said access was going away.

https://developer.apple.com/forums/thread/123774 Not the only ones that randomly gets their accounts terminated. Based on how apple has -insane- fragmentation and security for different aspects of the company, I would doubt any employee that isn't directly tied into the store accounts would know the whole details. (Source: GF worked for the department that did art/design for the apple stores, no one had access to the…

I use Sign In with Apple everywhere I can (so many of my passwords are in haveibeenpwned datasets), and if Apple blacklisted a provider I use, I’d expect the service to email me to migrate to their own email/password identity provider (if I didn’t hide my email from them with SIWA), with a link to the migration process in the email.

Re: Face ID and Touch ID for the Web

#74
post #41
post #36

Earlier quoted context omitted.

Apple did not terminate Epic's SiwA account, and several journalists have sources within Apple that say that Apple never sent the message Epic claimed to receive that said access was going away.

https://developer.apple.com/forums/thread/123774 Not the only ones that randomly gets their accounts terminated. Based on how apple has -insane- fragmentation and security for different aspects of the company, I would doubt any employee that isn't directly tied into the store accounts would know the whole details. (Source: GF worked for the department that did art/design for the apple stores, no one had access to the…

> Not the only ones that randomly

Not really random now right...

Re: Face ID and Touch ID for the Web

#75

I would never use this for anything sensitive. Bad actors can get your face and your fingerprint. Some of them already have it (governments, banks, Apple, Facebook, etc). And changing your face or fingerprint is practically impossible.

Apple has my face and fingerprint? I haven't heard this before and Google turns up nothing. Any source?

Re: Face ID and Touch ID for the Web

#76
post #28

These all seem to be examples that use faceID/touchID as a password. That’s not what biometrics should be though, they should be the username. I hope that this is supported as a flow as well. Identify who you are with biometrics, and prove your access with a correlated password.

First, the model in FIDO is that it's the piece of hardware (in this case, your laptop or iOS device) that is your authentication factor. The biometric is a local facility for unlocking that device and approving that specific action.

Second, the primary threat identity providers (and their users) deal with are remote, impersonal hijacking of accounts, where the password is either guessed (because it existed in a leak) or the user was phished.

That's the primary value of something like this. Attacks where someone can lift your fingerprints or has your device are real but much much less common.

Re: Face ID and Touch ID for the Web

#77
You can change a password but you can't change your fingerprint / palm / etc. Am I missing something? How is Face / Touch ID more secure that user + pass? What happens when biometric data is leaked?

Re: Face ID and Touch ID for the Web

#78

I would never use this for anything sensitive. Bad actors can get your face and your fingerprint. Some of them already have it (governments, banks, Apple, Facebook, etc). And changing your face or fingerprint is practically impossible.

This wouldn't just require them to have your face and fingerprint though - This would require them to

1. Have access to your phone

2. Be able to spoof the phone's authentication mechanisms (whether that be fingerprint / face)

In this regard, it passes the 2FA test (something that you own, and something that you are).

While it's true that you can't really change your face or fingerprint, this facilitates moving away from the "password repeated across multiple accounts" landscape of insecurity.

Re: Face ID and Touch ID for the Web

#80
post #50
post #33

Earlier quoted context omitted.

"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)

> I would definitely stay away from any "Sign in with Apple". I would stay away from any "Sign in with.." service as a user and as a product owner. You're affectively giving away a major control of your users to a third party.

I always leaned that way, but from the security and compliance side of things it's a heck of a lot easier for us when our staff can sign into 3rd party services with their company Google account that has strict security and 2 security keys in place vs whatever the luck of the draw may be with each service that we want to use. It's a nice alternative to the "SAML SSO only available with $10k / user enterprise account" routine.

But as long as that service has quality 2FA options with (ideally) Webauthn, it's much less of a concern.

Post reply on HN