I think we need a browser level or OS level notification about which passwordless service we used last time. Did we use Gmail, Twitter, Signin with Apple, Github, Linkedin, or do I actually have something stored in my password manager associated with an email and if so, did I store it in the browser's password manager, the OS's password manager, or my third party password manager?
Apple Passkey
121–130 of 421 posts
Re: Apple Passkey
#122Re: Apple Passkey
#123I would speculate Apple is not going to support this, and Apple will retain control of the private keys, and do the request signing like an old-school USB FIDO device, but I don't know for sure.
Re: Apple Passkey
#124Earlier quoted context omitted.
That seems like an enormous pain if you have dozens or hundreds of services. It could take hours to do this one at a time. (I'm assuming one minute per service, though that depends on how hard it is to find the "add another authenticator" page for each service.) It's possible I'm unaware that there is a simple protocol for this. Am I incorrect here?
Yeah this is absolutely not feasible, I have ~200 separate accounts in my password manager right now just for me personally.
The hundreds of other sites will probably take years to support Passkeys (they don’t support U2F either). I can convert them when they support it and I happen to do something else account-wise.
I don’t think it’s a huge issue.
Re: Apple Passkey
#125I think we need a browser level or OS level notification about which passwordless service we used last time. Did we use Gmail, Twitter, Signin with Apple, Github, Linkedin, or do I actually have something stored in my password manager associated with an email and if so, did I store it in the browser's password manager, the OS's password manager, or my third party password manager?
Why do you use more than one password manager? I have disabled all password managers in every app that I use except for the one I store things in. I have multiple folders with their own passwords too but they're all stored via the same solution.
Safari on iOS suggests a password even if I'm trying to paste on in from my password manager
OSX can be the same way
They all sync
and I never bothered to disable them because I never thought about it, but sometimes I'm in a rush with a service I think I'll never use again and use the suggested solution in one of the browsers
Re: Apple Passkey
#126Re: Apple Passkey
#127Re: Apple Passkey
#128How does this bode for anonymity and multiple identities? I'm imagining a world where all PCs/Macs/Smartphones have FIDO/WebAuthn and there's no other way to log in. Can I setup up multiple IDs on my iPhone and decide which services get to be associated with which id? I get that supposedly iPhone (etc) will (may?) give out a different number to each service but they'll still be associated with a single account at App…
FIDO2 resident keys do support multiple identities for a single relying party (site).
Re: Apple Passkey
#129I can be onboard with this if Apple opens up an iCloud API for syncing, so I can sync a non-Apple device through iCloud, and if I leave Apple and iCloud behind, my non-Apple devices keep working, even if I never sync through iCloud again.
C'mon. Non-Apple devices aren't _even remotely_ a priority for them. Just look how bad Apple Music is on Android and web.
Re: Apple Passkey
#130Most importantly, hopefully web sites will implement support for multiple authenticators, so you can actually use this safely without relying on a cloud-synced solution.
I hope this pushes out other, less secure and more tedious 2FA methods. However, once it becomes popular, sign in with WebAuthN only will likely not be enough, as attackers learn to attack it (e.g. stealing software-based tokens, adding a cloud-synced device, hijacking already-authenticated sessions from compromised machines)