Live data from Hacker News

Apple Passkey

developer.apple.com

121–130 of 421 posts

Re: Apple Passkey

#121

I think we need a browser level or OS level notification about which passwordless service we used last time. Did we use Gmail, Twitter, Signin with Apple, Github, Linkedin, or do I actually have something stored in my password manager associated with an email and if so, did I store it in the browser's password manager, the OS's password manager, or my third party password manager?

Why do you use more than one password manager? I have disabled all password managers in every app that I use except for the one I store things in. I have multiple folders with their own passwords too but they're all stored via the same solution.

Re: Apple Passkey

#122
Can I use a password manager like 1password it’s FIDO2 the way I currently can in iOS/macOS? iCloud Keychain is the most barebones of password manager

Re: Apple Passkey

#123
For those in the know, will I be able to export my private keys and data from Passkey somehow, so that if I wanted to, I could switch to another FIDO device or system?

I would speculate Apple is not going to support this, and Apple will retain control of the private keys, and do the request signing like an old-school USB FIDO device, but I don't know for sure.

Re: Apple Passkey

#124
post #113
post #100

Earlier quoted context omitted.

That seems like an enormous pain if you have dozens or hundreds of services. It could take hours to do this one at a time. (I'm assuming one minute per service, though that depends on how hard it is to find the "add another authenticator" page for each service.) It's possible I'm unaware that there is a simple protocol for this. Am I incorrect here?

Yeah this is absolutely not feasible, I have ~200 separate accounts in my password manager right now just for me personally.

I also have hundreds of accounts. But there are ~10 services that are far more important to me and where I care a lot about security beyond passwords (Fastmail, Dropbox, GitHub, Google Apps, Bank, government websites, etc.). I use most of them already with an U2F key and I’ll use them with Passkey.

The hundreds of other sites will probably take years to support Passkeys (they don’t support U2F either). I can convert them when they support it and I happen to do something else account-wise.

I don’t think it’s a huge issue.

Re: Apple Passkey

#125

I think we need a browser level or OS level notification about which passwordless service we used last time. Did we use Gmail, Twitter, Signin with Apple, Github, Linkedin, or do I actually have something stored in my password manager associated with an email and if so, did I store it in the browser's password manager, the OS's password manager, or my third party password manager?

Why do you use more than one password manager? I have disabled all password managers in every app that I use except for the one I store things in. I have multiple folders with their own passwords too but they're all stored via the same solution.

Because Google Chrome on iOS pops up asking to remember a password

Safari on iOS suggests a password even if I'm trying to paste on in from my password manager

OSX can be the same way

They all sync

and I never bothered to disable them because I never thought about it, but sometimes I'm in a rush with a service I think I'll never use again and use the suggested solution in one of the browsers

Re: Apple Passkey

#127
If this is about "[hardware devices] for generating and authenticating accounts" like WebAuthn FIDO et al what happens when I upgrade my Macbook. Do I revert back to password in order to associate the new private key (or hardware generate password) with my existing account?

Re: Apple Passkey

#128

How does this bode for anonymity and multiple identities? I'm imagining a world where all PCs/Macs/Smartphones have FIDO/WebAuthn and there's no other way to log in. Can I setup up multiple IDs on my iPhone and decide which services get to be associated with which id? I get that supposedly iPhone (etc) will (may?) give out a different number to each service but they'll still be associated with a single account at App…

FIDO logins are not shared across relying parties (sites), each site gets its own (that's what makes FIDO phishing proof). If you want a single identity that multiple sites know about you'd, login using a third party identity provider where you'd use your passkey.

FIDO2 resident keys do support multiple identities for a single relying party (site).

Re: Apple Passkey

#129

I can be onboard with this if Apple opens up an iCloud API for syncing, so I can sync a non-Apple device through iCloud, and if I leave Apple and iCloud behind, my non-Apple devices keep working, even if I never sync through iCloud again.

C'mon. Non-Apple devices aren't _even remotely_ a priority for them. Just look how bad Apple Music is on Android and web.

The AppleTV app on my LG TV is the best third party app on it, IMO. Looks and works great.

Re: Apple Passkey

#130
Hopefully this will be compatible with WebAuthN in practice and encourage web sites to implement it (in a compatible manner). It often does take Apple's heft to force a change across the web.

Most importantly, hopefully web sites will implement support for multiple authenticators, so you can actually use this safely without relying on a cloud-synced solution.

I hope this pushes out other, less secure and more tedious 2FA methods. However, once it becomes popular, sign in with WebAuthN only will likely not be enough, as attackers learn to attack it (e.g. stealing software-based tokens, adding a cloud-synced device, hijacking already-authenticated sessions from compromised machines)

Post reply on HN