Live data from Hacker News

Apple Passkey

developer.apple.com

131–140 of 421 posts

Re: Apple Passkey

#131
post #3

What standard is this using? The doc doesn't specify.

Under the covers, this is webauthn, which is based on FIDO2/U2F. I knew it was webauthn as soon as I read "relying party" and the two keypairs.

Re: Apple Passkey

#132

Earlier quoted context omitted.

You are 100% correct that you need to add it to each service. This is a consequence of an intentional decision (keys cannot be duplicated). Streamlining it would definitely be an improvement. That being said, it's not a problem in the real-world because FIDO is so sparsely supported. Hopefully PassKey speeds things along.

Streamlining would be an improvement, but it opens an attack vector. Unfortunately, security and usability are always in balance.

I should have been more specific. Test how many clicks it takes to add a key to one of your "mainstream" accounts. We would hope that services which support FIDO eventually gravitate to a single UX language, that also reduces the time taken to register new keys.

Re: Apple Passkey

#133
post #90

Earlier quoted context omitted.

> Also we still need ways of exporting keys and software (like 1password) needs to synchronize them, manage them securely. There's still a long ways to go on that front, which probably won't be handled until stuff like this has settled. That's the point of passkeys here: iCloud Keychain syncs them, and if you want to use your keys on a non-apple device you'll be able to scan a QR code, which initiates a new BLE conne…

I'm writing this on a non-Apple computer that doesn't have any radios. Now what?

Buy a cheap USB dongle for BLE?

Re: Apple Passkey

#134
post #82

Earlier quoted context omitted.

???? The goal of all this is to make auth tokens be single-factor , not one factor in MFA. If you read the Ars article linked elsewhere in the thread the people behind it are pretty clear about their desire to get rid of passwords.

The security of these tokens is still MFA as an end-to-end security model , insofar as you need a something-you-know [password, passcode] to unlock the device that serves as your something-you-have. So someone who just steals the device, can't use it to authenticate as you. (See also: smart cards having PINs.) And, once again, companies doing MFA properly , enforce MDM policies on such devices, such that they either…

No post body was provided.

Re: Apple Passkey

#135

I think we need a browser level or OS level notification about which passwordless service we used last time. Did we use Gmail, Twitter, Signin with Apple, Github, Linkedin, or do I actually have something stored in my password manager associated with an email and if so, did I store it in the browser's password manager, the OS's password manager, or my third party password manager?

Why do you use more than one password manager? I have disabled all password managers in every app that I use except for the one I store things in. I have multiple folders with their own passwords too but they're all stored via the same solution.

>Why do you use more than one password manager?

Work vs home is one driver.

And for some cases, "Login with Google" or similar is nice because it integrates Google pay, removes sign-up friction, etc. I'm aware it has downsides, but it remains useful in some niche areas.

Re: Apple Passkey

#136

Earlier quoted context omitted.

Why do you use more than one password manager? I have disabled all password managers in every app that I use except for the one I store things in. I have multiple folders with their own passwords too but they're all stored via the same solution.

Because Google Chrome on iOS pops up asking to remember a password Safari on iOS suggests a password even if I'm trying to paste on in from my password manager OSX can be the same way They all sync and I never bothered to disable them because I never thought about it, but sometimes I'm in a rush with a service I think I'll never use again and use the suggested solution in one of the browsers

Unfortunately, and I hate to "victim blame" (though you say you are not yet a victim), I think you have to take some responsibility and use a password manager with deliberation. IMHO the browsers all make this worse by giving you something that seems to work and your first notice that it doesn't anymore is when it stops, which is a terrible way for a security feature to work, but obviously they have incentives to lock you in, and boy oh boy is this one of the biggest ways that a browser can lock you in.

I think you should resist sooner rather than later and switch to something cross-browser and third-party.

But it's up to you, of course.

Re: Apple Passkey

#137

For those in the know, will I be able to export my private keys and data from Passkey somehow, so that if I wanted to, I could switch to another FIDO device or system? I would speculate Apple is not going to support this, and Apple will retain control of the private keys, and do the request signing like an old-school USB FIDO device, but I don't know for sure.

They allow export of everything else in iCloud keychain so I don’t expect this will be different.

Re: Apple Passkey

#138

I think we need a browser level or OS level notification about which passwordless service we used last time. Did we use Gmail, Twitter, Signin with Apple, Github, Linkedin, or do I actually have something stored in my password manager associated with an email and if so, did I store it in the browser's password manager, the OS's password manager, or my third party password manager?

[deleted]

Re: Apple Passkey

#139

I can be onboard with this if Apple opens up an iCloud API for syncing, so I can sync a non-Apple device through iCloud, and if I leave Apple and iCloud behind, my non-Apple devices keep working, even if I never sync through iCloud again.

Why not just use 1Password or a similar service?

Re: Apple Passkey

#140
post #63

How do I leave the Apple ecosystem if I go all in on this? Sounds like major vendor lock in under a deceptive title of “open standards” but I’m hoping I’m wrong here. Does anybody happen to know yet?

[deleted]
Post reply on HN