Live data from Hacker News

Apple Passkey

developer.apple.com

271–280 of 421 posts

Re: Apple Passkey

#271
post #228

I don’t understand how passkeys aren’t stored on external servers and can’t be phished, and yet they sync via iCloud Keychain (which is a nice thing to have). How does that work? Or do you have to trust Apple not to get hacked?

It is webauthn under the hood if you want to do further googling.

When setting up a credential the secure enclave in your apple device generates a public/private keypair. The public key is sent to the web service for storage and the private key is stored securely and synced between apple devices using end to end encryption. When you want to login the website sends a message to be signed, the apple device prompts for finger or face id to unlock the private key and the message is signed and returned to the website. The website uses the public key to verify only you could have signed the message. If an attacker dumps the website database all they get is a public key which is useless without the private key.

It's unphishable since the browser checks the origin hostname before the faceid prompt. Spell-alikes like g00gle.com will prompt for their own unique key that you don't have since it was never created. Apple's security doesn't matter since they never had the private key; it is sent between Apple devices using end to end encryption.

Re: Apple Passkey

#272
post #227

I don't get what it's all about this passwordless. I make my browser (Firefox) generate strong password and store them in its password manager, this is synchronized with end to end encryption to all my devices, I have only to remember a master password. It's kind of the same but it works with every website. It is not complicated, doesn't require certificates that you may loose, and that sort of things.

I don’t get that too, you can already build such a system yourself quite trivially with gpg+rsync

Impossible to tell if this is serious or sarcasm, well done if it’s the latter.

Re: Apple Passkey

#273

I think we need a browser level or OS level notification about which passwordless service we used last time. Did we use Gmail, Twitter, Signin with Apple, Github, Linkedin, or do I actually have something stored in my password manager associated with an email and if so, did I store it in the browser's password manager, the OS's password manager, or my third party password manager?

I don’t actually know how many Reddit accounts I have for this reason.

Re: Apple Passkey

#274
post #234

Earlier quoted context omitted.

Same as the don't have access to your iMessage messages ... unless you happen to use iCloud which they purposefully make really inconvenient to not use.

Yes Apple is willingly staying quiet about your iMessage backup being accessible by them. But it does not change the fact that iCloud Keychain is end-to-end encrypted with Apple incapable of accessing your keychain.

When I first learned about the iMessage backups being accessible I was a bit let letdown by Apple. But I never believed they were best in class for privacy. The iPhone's true strengths lie in the OS support and FaceID.

iMessage itself is pretty slick but if I want privacy, I use Signal. It also gives me a crossplatform messenger as I prefer Windows and iOS.

Same as with Microsoft Edge. It's my favorite browser now, but I do give up a bit of privacy for convenience. If I want the best privacy I use Tor Browser. Which I always keep installed with Signal.

Re: Apple Passkey

#275
post #73

Earlier quoted context omitted.

What happens when you're not using an apple device?

I saw a screenshot. Somehow a QR code is presented and you scan that with your phone. I’m not entirely sure what happens from there. But there was a picture of them using it with a Windows machine. So they’ve thought of it.

My understanding is the QR code is used to establish a quick BLE connection. The phone then pretends to to be a simple FIDO2 key. After that things proceed like any other FIDO2 workflow.

Re: Apple Passkey

#276
post #46

This is based on the open standards WebAuthn and FIDO2, where the credentials (“passkeys”) are synced via iCloud Keychain. Currently you need remember to register at least 2 security keys, in case one is lost/misplaced. The syncing of passkeys in iCloud solves this backup problem. https://fidoalliance.org/apple-google-and-microsoft-commit-t...

It's strange and rather unfortunate to see this constant reinvention of authentication methods. Asymmetric encryption as used in things like SSH keys and TLS client authentication have been around for decades, are very much standard, and the only changes to those have been stronger algorithms and longer keys. Smartcards as hardware secure elements have also been around for a long time. I'm not sure how much of a cons…

Its absolutely not a conspiracy theory, but it is a bit more complex than that there is was a coordinated push - there was a big push a while back from the likes of Microsoft to e.g. eradicate ssh credentials - in favor of stuff like AD (ugh, why?), specifically wrt to git clients. I know, GitHub still takes ssh (they'd break too many people otherwise), but places started moving towards AD, or "password manager integration" clients.

Part of that is on the "security contractors", who are objectively snake-oil salesmen (when you make a living selling people publicly, freely available, publicly supported software, and charging 6 figures for it, that is the definition of a swindler), especially since they started propagating their whole "security regimen" as a set of tasteless, mostly useless "security awareness" trainings. They harped a lot on choosing good passwords, caused a lot of bad password security practices on almost every website (I still see this everywhere online - please use 10 characters with one symbol from (!$./ ... etc) and 1 number - no - use entropic password measurement and maybe don't assume your site is important enough to warrrant a high-entropy password).

So, once we were all left with an unsustainable bag of crappy passwords for every buytoothpaste.com website out there... well we all had to try to invent something else. There was SSO OAuth, that failed because it was overcomplex (or got rolled into a banal corporate policy system which was horridly complex to deploy and the security contractors got paid to audit the bad systems).

Then pile on the other heap of bad password strenghtening abstractions (2FA), etc., you get to today. We never had SSH for the browser, GPG/PGP remained meh, so the result is a constant stream of "new solutions" to a problem which could have been solved by a) Not caring as much about passwords, communicate risk to the users instead b) fixing ssl/ssh.

And why did nobody do a) or b)? Again, I blame "security contractors" for a) and b) people not being paid to do it.

Yeah, profit-seekers will always try to capitalize on chaos, that's hardly conspiracy, that's just business.

Re: Apple Passkey

#277

I don't get what it's all about this passwordless. I make my browser (Firefox) generate strong password and store them in its password manager, this is synchronized with end to end encryption to all my devices, I have only to remember a master password. It's kind of the same but it works with every website. It is not complicated, doesn't require certificates that you may loose, and that sort of things.

Try explaining a password manager to your nana, and having her use it. Then explain to her how she can install it on her phone and have it synchronised across all her devices. Password managers are awesome, but way too technical to become mainstream. You shouldn't have to install 3rd party software for something so fundamental. The password system really needs an overhaul and hopefully this will go along way towards…

Sometimes I wonder how bright nana or papa really is as a result.

If you won't dig into even an iPhone's settings to learn what's available, what it can do, good luck to you. That curiosity and willingness to play around, accompanied with Google searches when they don't know what something does, is critical in making it in the world today. Or if you remain a rube, and they will, you'll get scammed someday because you're not on the top of your game mentally. Just lazying it up.

I've come to two solutions. Either Bitwarden or KeePass with only a mobile client to begin with. If they are managing that, then I graduate them to clients on multiple systems and the integration advantages that brings.

I'm a KeePass Windows and Strongbox Pro user on iOS myself. Prefer to keep that database where I want it. Bitwarden is probably the ticket for most people though. If you start them on mobile only, it helps a lot.

Re: Apple Passkey

#278
post #85

My wife signed up for calm.com using Sign in with Apple. Thanks to this, I am not able to occasionally use her login to listen to the wonderful music. There's just no way in hell I'm paying the $60 a year or whatever they're asking to listen to a couple songs every now and then. In a normal setting, she'd add her login to her 1password and I'd be able to use Calm.com, and who knows, I would've grown to love it, and g…

Consider paying the developers and artists for their work. It’s hard out there and it’s about to get a lot worse for both.

Re: Apple Passkey

#279
post #19

Earlier quoted context omitted.

They said in the event that everything is synced on iCloud so all your devices can use the keys, which makes me think no, it's just a password manager, without the password bit. Maybe they create a separate key for each device, but then why mention iCloud syncing at all.

It's a password manager with cryptographic vendor lockin . There are definitely some benefits though, such as immunity from phishing. Surely we as the industry can bring them about in a way that doesn't involve cryptographic vendor lockin.

There is no password so it can't be a password manager. Without a password it avoids all the downsides of passwords like having to store them securely on both ends, rainbow tables, credential reuse, weak password choice, and having to remember them. It's a cryptographic keypair manager. Key management is always the barrier to really good real world cryptography, so I'm heartily in favour. Anything that makes it possible for regular people to use strong cryptography is a huge win.

Since it's all just FIDO2/webauthn under the hood it's hardly lockin. It's a bit of Apple UI tinsel to make life simple and their excellent icloud keychain sync.

Re: Apple Passkey

#280
post #263

Unless I can back it up and import it into a new device from a competitor, then there is no way I am going to use this unless forced. I do not trust one company anymore.

There's nothing to backup/import. If you have an iPhone, you use your fingerprint or Face ID. If you sell your iPhone and buy an Android, you use your fingerprint or face recognition on that device.

I haven't dug into the docs yet, but I don't quite follow this. How does it know that the ex-iPhone owner and current Android owner are the same person (and should have access to the same account)?
Post reply on HN