Live data from Hacker News

Face ID and Touch ID for the Web

webkit.org

231–240 of 371 posts

Re: Face ID and Touch ID for the Web

#231

Earlier quoted context omitted.

No, there's no world where Apple blocks access to an account because they're showing derogatory content towards Apple products, and a company gets a judge to overturn that block because it's not technically libel. Apple has the right to block you from their sign-in for any reason. Short of pulling a move like Epic and suing them for antitrust, a court of law is never going to enter into the equation. None of these ar…

> Apple gets to decide what they mean. (IAAL, this is not legal advice.) That's not how contract law works. There's a whole body of law around how to construe language in contracts, and it's subject to litigation and dispute if the definition isn't made clear in the contract itself. > no court of law is going to rule that they don't have the right to block Then you don't know courts very well. Such clauses are still…

> But yeah, if you use someone's services and then publicly talk trash about them? Why should they be forced to continue to do business with you?

Nobody said they have to, just that it's very dangerous to depend on such a service. I say bad things about companies all the time!

Re: Face ID and Touch ID for the Web

#232
post #101

Earlier quoted context omitted.

Biometric data is never leaked because it never leaves the secure enclave in the device.

Your face can easily be mimicked. Biometric data is not stored in the phone, it is stored in you. See: https://www.macrumors.com/2018/12/16/3d-printed-head-android...

Your face can easily be mimicked.

Article: "I was ushered into a dome-like studio containing 50 cameras [...] The final model took a few days to generate at the cost of just over £300."

I don't how that can be characterized as "easily." Possible, yes, but not easy. And it still didn't fool FaceID.

Re: Face ID and Touch ID for the Web

#233

Earlier quoted context omitted.

Your face can easily be mimicked. Biometric data is not stored in the phone, it is stored in you. See: https://www.macrumors.com/2018/12/16/3d-printed-head-android...

Your face can easily be mimicked. Article: "I was ushered into a dome-like studio containing 50 cameras [...] The final model took a few days to generate at the cost of just over £300." I don't how that can be characterized as "easily." Possible , yes, but not easy. And it still didn't fool FaceID.

Maybe not easily in 2017, though there were other successful attempts to fool FaceID at the time [1], there are also successful and easier attempts to fool FaceID today [0] that can successfully bypass it.

[0] https://www.technologyreview.com/2020/02/29/905599/how-coron...

[1] https://www.forbes.com/sites/daveywinder/2019/08/10/apples-i...

Re: Face ID and Touch ID for the Web

#234
post #233

Earlier quoted context omitted.

Your face can easily be mimicked. Article: "I was ushered into a dome-like studio containing 50 cameras [...] The final model took a few days to generate at the cost of just over £300." I don't how that can be characterized as "easily." Possible , yes, but not easy. And it still didn't fool FaceID.

Maybe not easily in 2017, though there were other successful attempts to fool FaceID at the time [1], there are also successful and easier attempts to fool FaceID today [0] that can successfully bypass it. [0] https://www.technologyreview.com/2020/02/29/905599/how-coron... [1] https://www.forbes.com/sites/daveywinder/2019/08/10/apples-i...

Torture can extract an alphanumeric password.

Re: Face ID and Touch ID for the Web

#235
post #33
post #13

So happy Apple decided to go with an open standard here rather than something proprietary. This is good news for the FIDO2 ecosystem and I hope this leads to far greater support for FIDO2 authenticators of all types. There is another world in which Apple just pushed 'Sign in with Apple' and created yet another federated identity provider rather than true, 'secure element'-based FIDO2 authentication.

"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)

Except the 2FA is kinda stupid.

I have devices logged into my iCloud account at a datacenter, that end up getting my 2FA for my other devices.

I have a iPhone, iPad, Macbook, do you think any device I actually use all the time gets the 2FA code ?

Sometimes, the same computer i’m using to login gets the code which is kinda pointless.

I have to always use SMS to get my code because of this.

Re: Face ID and Touch ID for the Web

#236
post #101

Earlier quoted context omitted.

Biometric data is never leaked because it never leaves the secure enclave in the device.

Your face can easily be mimicked. Biometric data is not stored in the phone, it is stored in you. See: https://www.macrumors.com/2018/12/16/3d-printed-head-android...

This thread is about Apple. From the link:

> 3D Printed Head Fools Android Face Recognition, iPhone X 'Impenetrable'

Re: Face ID and Touch ID for the Web

#237
post #39

Neither sync nor keychain is mentioned in this post or in the WWDC presentation, so I'd like to ask if the credentials are synced between devices whatsoever, or if they're transferrable. While it'd be more secure to run it through a device's T2, a syncing/keychain-backed key would save a lot of the re-enrollment hassle for users who end up transferring their data to a new phone or need to enroll each of their devices…

They are no synchronized between devices. This is generally considered to be a no-no with FIDO (although Apple has not publicly announced whether they intend to be FIDO certified)

Apple is part of the FIDO alliance, I would assume they intend to be FIDO certified.

Re: Face ID and Touch ID for the Web

#238
post #13

So happy Apple decided to go with an open standard here rather than something proprietary. This is good news for the FIDO2 ecosystem and I hope this leads to far greater support for FIDO2 authenticators of all types. There is another world in which Apple just pushed 'Sign in with Apple' and created yet another federated identity provider rather than true, 'secure element'-based FIDO2 authentication.

Having just devoted about 12 hours to helping my wife migrate to a password manager from an ad-hoc collection of access control approaches (you don't want to know), I emerged horrified by the range and domain of what I can only call incompetence and a total lack of common sense and UI intelligence.

I wrote about it here (long post):

https://news.ycombinator.com/item?id=24827031

I haven't quite processed this entirely yet. Part of me feels one or more adults on the world stage need to get behind what I will call a canonical approach to login, authentication, account recovery, password policies, etc.

In some ways I equate this mess to what happened back when fire hydrants were not compatible with every hose coupling fire departments used. In other words, it was a mess and people got hurt.

Standardization is good. Or can be good. After this weekend I can't help but think that this is another area where the web needs to seek standardization. I get the feeling that every n-th developer is rolling their own approach and the result is an absolute mess.

Not advocating for an Apple solution, just saying that I had a revelation this past weekend and what I learned does not speak kindly of how this important aspect of online life is being handled.

Re: Face ID and Touch ID for the Web

#239
post #233

Earlier quoted context omitted.

Maybe not easily in 2017, though there were other successful attempts to fool FaceID at the time [1], there are also successful and easier attempts to fool FaceID today [0] that can successfully bypass it. [0] https://www.technologyreview.com/2020/02/29/905599/how-coron... [1] https://www.forbes.com/sites/daveywinder/2019/08/10/apples-i...

Torture can extract an alphanumeric password.

But is it the right password, or the duress one?

Re: Face ID and Touch ID for the Web

#240
post #136

Earlier quoted context omitted.

As a user I would prefer no account in most cases. As a distant second, I would prefer the convenience, security, and privacy of Sign in with Apple over Google, Facebook, or the headache of managing yet another web account . As a developer, I use my preferences as a user to steer my choices, but recognize that the world doesn't revolve around Apple so would allow other options. > Having saw Epic's developer account t…

I've had an issue with sign-in with Apple where using an autogenerated emails ruins certain support interactions. One of them was cancelling a subscription service that was eventually resolved (they required me to email their customer support, which I couldn't figure out how to do using the autogenerated email address created by "sign-in with Apple").

It would be helpful if you could let us know how you managed to send that e-mail.
Post reply on HN