Live data from Hacker News

Face ID and Touch ID for the Web

webkit.org

201–210 of 371 posts

Re: Face ID and Touch ID for the Web

#201

Earlier quoted context omitted.

This doesnt really surprise me - Apple has a history of implementing, or moving to, standards for their platform features in Safari. I think about Apple Pay for web - it started out as a proprietary API, and then the Payment Request API standard was developed and they added support for that. It's in Apple's interest to help develop and support standards like this because they mean more adoption of their platform feat…

I am still waiting for them to move to USB-C

> I am still waiting for them to move to USB-C

What do you mean? All Mac models introduced since 2016 support USB-C.

https://support.apple.com/en-us/HT201736

Re: Face ID and Touch ID for the Web

#202

Earlier quoted context omitted.

I use Sign In with Apple everywhere I can (so many of my passwords are in haveibeenpwned datasets), and if Apple blacklisted a provider I use, I’d expect the service to email me to migrate to their own email/password identity provider (if I didn’t hide my email from them with SIWA), with a link to the migration process in the email.

Same except that, if Apple blacklisted a provider, I'd want to know why they got blacklisted. At this point, I trust Apple as a neutral third party more than I trust most other companies since Apple isn't incentivized to sell my info.

Agreed, with the caveat that we need some regulation through legislation to codify safeguards around identity providers, their responsibilities, etc.

Re: Face ID and Touch ID for the Web

#203
post #183

I've come to appreciate DigitalOcean's approach on the matter. Until you configure a 2FA device (TOPT in my case) they'll send you a temporary code to your email address. So password alone is worthless, and mailbox ownership is verified on every login. Also, I made a point never to use the "login with X" feature, no matter what X is. I always sign up with my own email.

I really hate the "we're going to send a code to your email" approach because it so often breaks. Case in point, I tried to log into Patreon earlier today, they insisted on sending a code, and it never arrived. I tried several times, no email. I have a record of every email sent to my address for the past several years regardless of spam status so I can be 100% positive they simply never sent it. In the end I had to…

I'm curious -- do you host your own email, or use a lesser-known email provider?

I am increasingly seeing failures where sites seem to be blackholing outgoing email, I suspect based on the destination domain, and unaware that they are even doing this / extremely insistent that they are not. I've gotten login-email failures like you describe from a couple of sites, and seemingly similar failures from those "email your kid this story" sharing systems on two news sites my mother uses. In all these cases, the messages simply never arrive at the destination SMTP server.

Re: Face ID and Touch ID for the Web

#204
post #137

Earlier quoted context omitted.

> Since I have zero need to deliberately violate Apple's App Story policy, I don't worry about this overmuch. That may be true today, but their policies are a moving target. Who knows what they'll be like in a year's time?

It isn’t productive to establish defense against an arbitrary future that turns on you. Spend those brain cycles focusing on your user and building a great product. Choosing Sign in with Apple is great for Apple users.

Maybe so. But how is this different than saying, "I have nothing to hide, so I'm not worried about having my car searched?" It's a somewhat pragmatic point of view but I wonder if it is a good idea in the limit.

Re: Face ID and Touch ID for the Web

#206

Earlier quoted context omitted.

For what it's worth, it's been said (by anonymous sources, no one on the record) that Apple did not threaten to terminate Epic's "Sign in with Apple" accounts/features, and they spent extra effort to maintain their access to that after their account was terminated. I do not know if other terminated accounts get this "luxury".

Epic did say it was going to be terminated, presumably as part of the overall account termination. They then updated that it would continue to work. https://www.theverge.com/2020/9/10/21431396/epic-sign-in-wit... Apple commented they weren’t doing anything to stop Sign In with Apple working, but I have to wonder if there’s a lie of omission in there. Like “We aren’t doing anything deliberate to stop it, but it’s goin…

Considering the court itself has said Epic has lied about other details, I’d lean towards that.

Re: Face ID and Touch ID for the Web

#207

Earlier quoted context omitted.

You could say that about anything -- nothing is completely static -- but it's worth mentioning that Apple vs. Epic is a counterexample; Epic wants apple to change their policies (lower than 30% cut) while Apple wants to maintain the same structure since the inception of their app store.

> You could say that about anything -- nothing is completely static 1. Contracts are a thing. You can draft a contract with your vendor that guarantees certain terms for a certain duration. 2. You should be wary of wandering into commitments (including de facto commitments e.g. "vendor lock-in")--there are plenty of good reasons to do so, but one should make sure to properly consider the cost. The problem is that doi…

It is more of an monopsony[1] than a monopoly. If you are looking to buy a smartphone there are still options. If you are looking to sell software for smart phones, Apple is by far the most lucrative platform and they have a lock on publishing software for iOS. It is very difficult in the US to survive as a software developer for Android only.

The anti-trust frameworks in the US are based largely on monopolies and there is little in the way of legal precedence for protecting sellers in a monopsony market. If Epic wins their legal battle, it will likely set precedence for later cases.

Google and Facebook are also largely in weird legal ground. They have more or less exclusive access to large networks of users which is hugely disruptive to the advertising market.

[1] A monopoly is a market where there is only one provider. A monopsony is a market where there is only one buyer.

Re: Face ID and Touch ID for the Web

#208
post #137

Earlier quoted context omitted.

> Since I have zero need to deliberately violate Apple's App Story policy, I don't worry about this overmuch. That may be true today, but their policies are a moving target. Who knows what they'll be like in a year's time?

It isn’t productive to establish defense against an arbitrary future that turns on you. Spend those brain cycles focusing on your user and building a great product. Choosing Sign in with Apple is great for Apple users.

> It isn’t productive to establish defense against an arbitrary future that turns on you.

It isn't?

Isn't that like, the hallmark of intelligence?

Re: Face ID and Touch ID for the Web

#209
post #101
post #77

You can change a password but you can't change your fingerprint / palm / etc. Am I missing something? How is Face / Touch ID more secure that user + pass? What happens when biometric data is leaked?

Biometric data is never leaked because it never leaves the secure enclave in the device.

Your face can easily be mimicked. Biometric data is not stored in the phone, it is stored in you.

See: https://www.macrumors.com/2018/12/16/3d-printed-head-android...

Re: Face ID and Touch ID for the Web

#210
post #112

Earlier quoted context omitted.

The risks of forced unlocking with FaceID have been discussed, including in court: https://appleinsider.com/articles/19/01/14/face-id-touch-id-... The main alternative to biometric ID is a PIN. Those are seldomly changed, and are relatively easily shoulder-surfed. I've seen children who can't even read yet learn their parent's iPad PINs. If you're afraid of the police, surveillance needs to be your threat model. Ther…

I didn't know you could disable face ID by squeezing your phone. Thanks for the info, and for the court case as well. I think a strong password on my phone is important, rather than a simple PIN, given it's my second factor for nearly everything.

Just as an FYI for anyone reading this thread: Android has a similar feature called "lockdown", that can be triggered by holding down the power button for a second and then selecting the option.
Post reply on HN