Live data from Hacker News

Apple Passkey

developer.apple.com

411–420 of 421 posts

Re: Apple Passkey

#411
post #410

Earlier quoted context omitted.

Because your iCloud Keychain has nothing to do with your SIM card. https://support.apple.com/guide/security/secure-icloud-keych...

I know it does not. It's in the Cloud. I was referring to SIM and phone number when I was thinking potential way to recover. Can you explain how a person can login into their iCloud and recover their iCloud Keychain after they have lost their only Apple device (iPhone) if Apple Passkey needed to access iCloud?

Passkey is not required to access iCloud. You're thinking of 2FA on an Apple ID.

https://support.apple.com/kb/HT204974

Re: Apple Passkey

#412
post #100

Earlier quoted context omitted.

That seems like an enormous pain if you have dozens or hundreds of services. It could take hours to do this one at a time. (I'm assuming one minute per service, though that depends on how hard it is to find the "add another authenticator" page for each service.) It's possible I'm unaware that there is a simple protocol for this. Am I incorrect here?

You should always add at least two keys for every service in case you lose the first anyway. That was the case even before Apple passkey so just keep doing the same.

This isn't a great solution, as in order to enrol in new services you have to either retrieve your backup key from its safe storage location, or keep the backup key with you at all times (which defeats its purpose).

And if you do move away from Apple's Passkey to your second key, you'll want to buy and set up a new backup key. So have to do the tedious mass-enrollment anyway.

Re: Apple Passkey

#413
post #100

Earlier quoted context omitted.

That seems like an enormous pain if you have dozens or hundreds of services. It could take hours to do this one at a time. (I'm assuming one minute per service, though that depends on how hard it is to find the "add another authenticator" page for each service.) It's possible I'm unaware that there is a simple protocol for this. Am I incorrect here?

Well, realistically not all services will support WebAuthn… spending an hour to handle a dozen important ones doesn't sound like a big deal to me.

The goal of the recent initiatives is to create widespread passwordless authentication, so it seems likely that the number of services that support WebAuthn will grow dramatically over the next few years.

Re: Apple Passkey

#414
post #234
post #208

Earlier quoted context omitted.

It’s end to end encrypted. Apple doesn’t have access.

Same as the don't have access to your iMessage messages ... unless you happen to use iCloud which they purposefully make really inconvenient to not use.

No it's not. Apple has the key for iMessages. Does NOT have it for Keychain.

Re: Apple Passkey

#415
post #410

Earlier quoted context omitted.

I know it does not. It's in the Cloud. I was referring to SIM and phone number when I was thinking potential way to recover. Can you explain how a person can login into their iCloud and recover their iCloud Keychain after they have lost their only Apple device (iPhone) if Apple Passkey needed to access iCloud?

Passkey is not required to access iCloud. You're thinking of 2FA on an Apple ID. https://support.apple.com/kb/HT204974

Thanks. As I expected. You need to have your SIM (to get access into iCloud)

https://support.apple.com/en-us/HT213305

>To recover a keychain, a user must authenticate with their iCloud account and password and respond to an SMS sent to their registered phone number.

In other words. If you lose your iPhone (containing your SIM) you can't get access to iCloud or iCloud keychain until you have a new SIM with the same phone number from your carrier.

If you travel in a foreign country and lose your iPhone you are locked out of "everything Apple".

Re: Apple Passkey

#416
post #415

Earlier quoted context omitted.

Passkey is not required to access iCloud. You're thinking of 2FA on an Apple ID. https://support.apple.com/kb/HT204974

Thanks. As I expected. You need to have your SIM (to get access into iCloud) https://support.apple.com/en-us/HT213305 >To recover a keychain, a user must authenticate with their iCloud account and password and respond to an SMS sent to their registered phone number. In other words. If you lose your iPhone (containing your SIM) you can't get access to iCloud or iCloud keychain until you have a new SIM with the same ph…

You can register VoIP and landline numbers as well, and nothing says the number must be yours; you can also add the number of a trusted family member or friend.

You can choose which preregistered number to send a message to (or to be called with a recorded voice) in the event you need access to your account in an emergency.

This also implies you have no other Apple devices which are signed into your account, as they will receive a code by default.

SMS or voice fallback is "plan B".

Re: Apple Passkey

#417
post #415

Earlier quoted context omitted.

Thanks. As I expected. You need to have your SIM (to get access into iCloud) https://support.apple.com/en-us/HT213305 >To recover a keychain, a user must authenticate with their iCloud account and password and respond to an SMS sent to their registered phone number. In other words. If you lose your iPhone (containing your SIM) you can't get access to iCloud or iCloud keychain until you have a new SIM with the same ph…

You can register VoIP and landline numbers as well, and nothing says the number must be yours; you can also add the number of a trusted family member or friend. You can choose which preregistered number to send a message to (or to be called with a recorded voice) in the event you need access to your account in an emergency. This also implies you have no other Apple devices which are signed into your account, as they…

SMS works with password access as 2FA it's part of plan A in recovery.

None of the methods you mention are something that should be expected from normal users. Or they don't work when traveling. I travel a lot.

"There is a way you could set it up" does not mean Apple has a good solution. As I'm a person without family and only one iPhone I stay away. People who don't pay attention are fucked.

Re: Apple Passkey

#418
post #417

Earlier quoted context omitted.

You can register VoIP and landline numbers as well, and nothing says the number must be yours; you can also add the number of a trusted family member or friend. You can choose which preregistered number to send a message to (or to be called with a recorded voice) in the event you need access to your account in an emergency. This also implies you have no other Apple devices which are signed into your account, as they…

SMS works with password access as 2FA it's part of plan A in recovery. None of the methods you mention are something that should be expected from normal users. Or they don't work when traveling. I travel a lot. "There is a way you could set it up" does not mean Apple has a good solution. As I'm a person without family and only one iPhone I stay away. People who don't pay attention are fucked.

No, the first 2FA step is for Apple to send your Apple devices a TOTP code, which is not delivered via SMS. This is the case in every situation.

Only if you have no access to any device do you need to fall back to account recovery via SMS or phone call, to any pre-registered number.

Re: Apple Passkey

#419

What I would like to know is if this takes off, will I finally be able to use my Yubikey on all the same sites that suppprt Apple Passkey?

Probably. Google and GitHub already support WebAuthn for 2FA so it's relatively trivial for them to ditch passwords altogether and use WebAuthn as the single credential.

Re: Apple Passkey

#420
post #407

Earlier quoted context omitted.

FIDO2 resident keys (the thing people are now calling passkeys) allow for multiple credentials for a single site. If you have a device that supports resident keys you can try this for yourself on https://webauthn.io . There is also no way for a site to know if two sets of credentials belong to the same physical hardware device or not. Sites can request the attestation certificate, but that is not unique per device (t…

Got "failed to register" on your website on my phone after doing the os level fingerprint auth

Thanks for the heads up, it should be fixed now for android platform authenticators.
Post reply on HN