This is based on the open standards WebAuthn and FIDO2, where the credentials (“passkeys”) are synced via iCloud Keychain. Currently you need remember to register at least 2 security keys, in case one is lost/misplaced. The syncing of passkeys in iCloud solves this backup problem. https://fidoalliance.org/apple-google-and-microsoft-commit-t...
> The syncing of passkeys in iCloud solves this backup problem. But then apple has your keys....
Apple Passkey
161–170 of 421 posts
Re: Apple Passkey
#162This is based on the open standards WebAuthn and FIDO2, where the credentials (“passkeys”) are synced via iCloud Keychain. Currently you need remember to register at least 2 security keys, in case one is lost/misplaced. The syncing of passkeys in iCloud solves this backup problem. https://fidoalliance.org/apple-google-and-microsoft-commit-t...
> The syncing of passkeys in iCloud solves this backup problem. But then apple has your keys....
Re: Apple Passkey
#163Earlier quoted context omitted.
Why do you use more than one password manager? I have disabled all password managers in every app that I use except for the one I store things in. I have multiple folders with their own passwords too but they're all stored via the same solution.
>Why do you use more than one password manager? Work vs home is one driver. And for some cases, "Login with Google" or similar is nice because it integrates Google pay, removes sign-up friction, etc. I'm aware it has downsides, but it remains useful in some niche areas.
Re: Apple Passkey
#164Earlier quoted context omitted.
> The syncing of passkeys in iCloud solves this backup problem. But then apple has your keys....
Passwords in iCloud Keychain are already E2EE, it seems reasonable the private passkeys would be too.
Re: Apple Passkey
#165It’s available at https://passwordless.dev
Note: We also maintain the open source fido2-net-lib, the API just lowers the friction for devs.
Re: Apple Passkey
#166Earlier quoted context omitted.
What happens when you're not using an apple device?
I saw a screenshot. Somehow a QR code is presented and you scan that with your phone. I’m not entirely sure what happens from there. But there was a picture of them using it with a Windows machine. So they’ve thought of it.
Re: Apple Passkey
#167Earlier quoted context omitted.
Passwords in iCloud Keychain are already E2EE, it seems reasonable the private passkeys would be too.
How could one verify that? like for compliance audit?
Introduction to Apple security assurance
As part of our commitment to security, Apple regularly engages with third-party organizations to certify and attest to the security of Apple’s hardware, software, and services. These internationally recognized organizations provide Apple with certifications that align with each major operating system release. …
Re: Apple Passkey
#168Earlier quoted context omitted.
> The syncing of passkeys in iCloud solves this backup problem. But then apple has your keys....
iCloud Backups != iCloud syncing iiuc. Passwords/Wifi/etc. syncing is a different E2EE system. You can disable iCloud Backups and still use iCloud
Re: Apple Passkey
#169Yes I've heard that there may be some Apple manifestation going on or something but to have every little Apple tidbit hoisted directly to the front page (at least 7 articles and counting) is a bit much imho.
Downvote me if you must, but I think it is important to have my opinion heard, and I don't think I am the only one.
Re: Apple Passkey
#170Earlier quoted context omitted.
Apple is the face on the screen. There is no lady with a hammer. https://youtu.be/OYecfV3ubP8
This is based on an open standard and is entirely optional. So your analogy makes absolutely no sense.
Semantics aside, holding private keys hostage with no recourse is Orwellian. A for-profit company has no business being a centralized identity authority.