Live data from Hacker News

Face ID and Touch ID for the Web

webkit.org

301–310 of 371 posts

Re: Face ID and Touch ID for the Web

#301

Earlier quoted context omitted.

You don't seem to be aware of what is under discussion here. You just raised a huge strawman. Websites are not receiving your biometrics in this context, and your biometrics would be meaningless to the website if captured and somehow provided. Your biometric signature is stored solely inside the Secure Enclave in the Apple device. If and only if the Secure Enclave recognizes you via your biometrics will the Enclave u…

All that's well and good until companies start implementing their own FaceID then forcing you to use it [0] on the back of trusting Apple, even CALLING it the same thing. This app linked above (my bank) contains NONE of the security you've mentioned above. And, incidentally, for me, biometrics STILL fail every test that matters to me: If I am dead, a bad actor can still gain access to my accounts. With a password, th…

Rather than downvote me for pointing out how companies abuse this, explain how this is an improvement.

Re: Face ID and Touch ID for the Web

#302

Earlier quoted context omitted.

All that's well and good until companies start implementing their own FaceID then forcing you to use it [0] on the back of trusting Apple, even CALLING it the same thing. This app linked above (my bank) contains NONE of the security you've mentioned above. And, incidentally, for me, biometrics STILL fail every test that matters to me: If I am dead, a bad actor can still gain access to my accounts. With a password, th…

Rather than downvote me for pointing out how companies abuse this, explain how this is an improvement.

Lol...

Re: Face ID and Touch ID for the Web

#303
post #299
post #171

Earlier quoted context omitted.

They could just have it say "example.com wants to use Touch ID to sign-in. Biometric data is not shared." with a help link that goes on to explain in laymens terms how your iPhone basically sends a password-ish thing to the website after you use Touch ID (similar to how Apple Pay sends a one-time use credit card number to a merchant).

Apple's UI designers would never tolerate such a helpful and wordy dialog box.

I don't understand why they even ask it as a popup. I mean, you already get "touch to login" kind of text next to Touch ID on Touch Bar, if you don't want to login that way, simply don't touch it. Am I missing something extra about the purpose of this popup?

Re: Face ID and Touch ID for the Web

#304

Earlier quoted context omitted.

Please please please be true. TouchID is objectively superior to FaceId, by a long shot. It is my soap box... but TouchID RARELY failed and could be activated BEFORE you had the phone in front of you. FaceID fails constantly and MUST be in view to start the unlock process. TouchID has a single failure mode (and a half) that isn't that common. Wet / dampness. Solution, dry your finger, try again. Gloves are the 'half'…

I live in a cold climate, so I was happy to be done with TouchID. Then coronavirus happened and now it doesn't recognize me with a mask on.

Just curiosity: does it start recognizing with the mask after some time?

Re: Face ID and Touch ID for the Web

#305
Why does it exactly show a popup saying "website wants to use Touch ID"?

It could just say "Touch ID to login" on the Touch Bar and wouldn't it be enough? If the user prefers otherwise, they simply won't touch. Doesn't the popup create extra friction (unless I'm missing something)?

Re: Face ID and Touch ID for the Web

#306

Earlier quoted context omitted.

That’s a pretty misleading interpretation of what Apple said or even what Tim Sweeney said in the tweet...

How so?

> Apple is entirely in its rights to terminate Epic Games’ developer account and all related functionality, but SIWA will continue to function for two weeks.

Ok, let’s translate it:

1) Apple believes it’s entirely in its rights to terminate Epic’s dev account and is doing so

2) Apple also believes it’s in their right to kill all related account functionally, but they aren’t, specifically with SIWA, for at least two weeks.

3) they don’t specify what will happen after two weeks, as that likely depends on several factors. We later learn that they extended it indefinitely.

So there’s multiple possible scenarios:

A) Apple really is just threatening as you indicated, but not being blatantly direct about it. Possible, but not the only possibility, and not usually their style from what I’ve seen for something like this, but who knows. I feel if Apple really wanted to threaten, they’d make the threat explicit and say “after two weeks of non-compliance, we will terminate everything”.

B) Apple is stalling making a decision over if SIWA will continue to be available to Epic’s users to ensure the SIWA team can support it when the dev account is deactivated. From other rumors where we hear folks saying SIWA team did have to make changes, I’m thinking this was the likely scenario. Don’t make a commitment to keep something going if you can’t deliver on it for sure yet, so “give them a two week extension” so you learn if you can actually keep SIWA up. If they can’t and Epic is still fighting with Fire, maybe you do terminate SIWA, but maybe not. Either way, Apple wins.

C) Apple is stalling a decision to scare Epic into compliance after Epic’s users backlash over word it might end. Possible, but I think Epic had well shown they were ready to play the Russian roulette game with Apple down to the last chamber, so I’m thinking less likely than A/B.

So if I was a betting man, I’d say it’s a mixed bag at best, but would likely go:

B > A > C

Apple doesn’t play checkers, they play chess. When they send a letter like that, they ensure there’s multiple positive outcomes for them for any potential scenario, from technical complications, to user perception, to legal proceedings, etc.

Re: Face ID and Touch ID for the Web

#307
post #266

Earlier quoted context omitted.

So what exactly is the concrete downside here, apart from the icky word "platform", that, in this context, means "a security chip that's not removable", ie as opposed to a Yubikey or such.

Websites will, at their option, be able to require Apple hardware to use them.

Attestation has allowed a website to lock to a specific vendor for 5+ years.

Re: Face ID and Touch ID for the Web

#308

Earlier quoted context omitted.

It's pretty clear Epic set out to intentionally get their Apple developer account terminated so they would have standing to sue, so I would not draw too much inference from that. That said, it's generally true that any dependence on a platform is a form of risk. There are documented examples of Google kicking people out of their ecosystem unexpectedly too. Federated sign-in schemes may be a good idea if they help you…

What if I'm running a site that is against apple's beliefs? E.g you run an adult site? Would you risk it?

Apple doesn't allow adult content in their App Store, but they don't do anything to prevent adult sites from loading in Safari, even on iOS--never have. They seem to draw a distinction between their walled gardens and the open web. I'll admit I'm not an expert on Face ID and Touch ID for the web, but to me it looks like a feature of the Safari browser, not a walled garden.

Re: Face ID and Touch ID for the Web

#309

Earlier quoted context omitted.

I live in a cold climate, so I was happy to be done with TouchID. Then coronavirus happened and now it doesn't recognize me with a mask on.

Just curiosity: does it start recognizing with the mask after some time?

In my anecdotal experience, it does not. Apple has made it easier to bring up the PIN prompt when it fails, though: https://www.theverge.com/2020/5/20/21265019/apple-ios-13-5-o...

Re: Face ID and Touch ID for the Web

#310

Last I checked Apple only supported U2F and similar in Safari - the WebKit exposed for the other iOS browsers use can’t access those features. Did that change in iOS 14?

According to the article > Like Face ID and Touch ID for the web, security key support is available in Safari, SFSafariViewController and ASWebAuthenticationSession.

Ok, looks like ASWebAuthenticationSession is the one Chrome for iOS uses, hopefully that means we’ll gain u2f, TouchID, and FaceTime then.
Post reply on HN