Live data from Hacker News

Apple Passkey

developer.apple.com

31–40 of 421 posts

Re: Apple Passkey

#31

What happens if you lose your device or it breaks or something? Do you lose access to anything tied to it?

It's tied to a key stored in your iCloud. So basically as long as you have a device tied to your iCloud you can get in. Presumably, if you lose access to iCloud you will have problems.

Apple is the face on the screen. There is no lady with a hammer.

https://youtu.be/OYecfV3ubP8

Re: Apple Passkey

#33
post #27

Earlier quoted context omitted.

I think Apple encrypts the pass keys locally on your device, then stores encrypted copies in iCloud, which you can download and decrypt on a new device. On the new device you would be prompted for the passcode of the device you lost or broke, to decrypt and access them.

iCloud (and anything on iCloud) is explicitly not encrypted, though [1]. [1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

That’s not universally true.

https://support.apple.com/en-us/HT202303

> If you forget your password or device passcode, iCloud Data Recovery Service can help you decrypt your data so you can regain access to your photos, notes, documents, device backups, and more. Data types that are protected by end-to-end encryption—such as your Keychain, Messages, Screen Time, and Health data—are not accessible via iCloud Data Recovery Service.

Re: Apple Passkey

#35
post #27

Earlier quoted context omitted.

I think Apple encrypts the pass keys locally on your device, then stores encrypted copies in iCloud, which you can download and decrypt on a new device. On the new device you would be prompted for the passcode of the device you lost or broke, to decrypt and access them.

iCloud (and anything on iCloud) is explicitly not encrypted, though [1]. [1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

Literally in the article:

> Instead of protecting all of iCloud with end-to-end encryption, Apple has shifted to focus on protecting some of the most sensitive user information, such as saved passwords and health data.

> But backed-up contact information and texts from iMessage, WhatsApp and other encrypted services remain available to Apple employees and authorities.

Re: Apple Passkey

#36
post #27

Earlier quoted context omitted.

I think Apple encrypts the pass keys locally on your device, then stores encrypted copies in iCloud, which you can download and decrypt on a new device. On the new device you would be prompted for the passcode of the device you lost or broke, to decrypt and access them.

iCloud (and anything on iCloud) is explicitly not encrypted, though [1]. [1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

This is false; some data is end-to-end encrypted, including Health and Keychain data. Photos, contacts, and Drive are "encrypted on server" which means Apple can read them.

https://support.apple.com/en-us/HT202303

Re: Apple Passkey

#37
Unless I can back it up and import it into a new device from a competitor, then there is no way I am going to use this unless forced. I do not trust one company anymore.

Re: Apple Passkey

#38

Does anyone know if this is different to Webauthn? You can already login with touchid/faceid, with the private key stored in apples keychain. Lots of sites support it, I just added it as 2FA to Mailpace ( https://blog.mailpace.com/blog/why-we-use-webauthn-for-2fa/ ), making it passwordless login instead of 2FA is trivial and fully supported by webauthn. What’s different about this?

Reading the linked page, it certainly looks very similar. I've also implemented WebAuthn from scratch and the term "relying party" is burned into my brain, and this document also uses that term. It's a reasonable term to use in any authentication context, though, so not a smoking gun I guess.

WebAuthn continues to work great on iOS and Mac OS, so I'm not sure there's a good reason to add some other new standard. (Though I do have the controversial opinion of wanting Apple to share my credentials between all devices. I have my iPad, iPhone, Macbook, and portable security key all enrolled in SSO. I don't mind this but I feel like it probably hinders adoption over an easily-hackable pasword that you just remember.)

Re: Apple Passkey

#39
post #19

Earlier quoted context omitted.

They said in the event that everything is synced on iCloud so all your devices can use the keys, which makes me think no, it's just a password manager, without the password bit. Maybe they create a separate key for each device, but then why mention iCloud syncing at all.

It's a password manager with cryptographic vendor lockin . There are definitely some benefits though, such as immunity from phishing. Surely we as the industry can bring them about in a way that doesn't involve cryptographic vendor lockin.

The secrets can be exported - whether or not they will allow that though...

Re: Apple Passkey

#40
post #27

Earlier quoted context omitted.

I think Apple encrypts the pass keys locally on your device, then stores encrypted copies in iCloud, which you can download and decrypt on a new device. On the new device you would be prompted for the passcode of the device you lost or broke, to decrypt and access them.

iCloud (and anything on iCloud) is explicitly not encrypted, though [1]. [1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

[deleted]
Post reply on HN