Live data from Hacker News

Apple’s Killing the Password. Here’s Everything You Need to Know

wired.com

21–30 of 99 posts

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#21
post #16
post #4

One thing I never understood about this passkeys thing is: how will the passkeys database be kept in sync between your iPhone, your Windows desktop, your Linux laptop and your Android tablet? I've tried to research the topic a bit but everything I've been able to find has been about exporting and importing between ecosystems, but most people don't use only a single company's products.

The passkeys are only synced across Apple devices, via iCloud keychain. Trying to sign in on another device (e.g. Windows laptop, Android phone) will require scanning a QR code. The devices then establish a secure channel using FIDO caBLE v2 (introduced by Google/Chrome, I believe) to perform the authentication. This ensures the passkeys never leave your Apple device, but can still be used on other devices. You can s…

Aha, so you get a significantly worse experience if you're not 100% in the Apple ecosystem, and you can't sign in at all if you don't have your Apple device on you.

I'll keep using passwords, thanks.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#22

Does this passwordless future still involve getting a cookie in your browser that can be stolen and used from an attackers machine? If so, we still have a problem to fix.

AFAIK Token binding was designed to solve this problem, but was removed from Google Chrome for being too complicated for the benefits it brought.

Not sure if there is anything else in the works.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#23
post #20

Does this passwordless future still involve getting a cookie in your browser that can be stolen and used from an attackers machine? If so, we still have a problem to fix.

How would you propose doing sessions instead?

This seemed promising but it doesn’t look like it had any traction https://www.rfc-editor.org/rfc/rfc8471

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#24
Which websites support passwordless authentication (FIDO2 WebAuth)?

Microsoft and eBay, AFAIK. The rest may use U2F as a second factor not the only one.

Also, for recovery you need multiple phones, and you need the websites to support that. It will probably take a while for websites to support this, and even then people are not going to buy and register several phones.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#25
Does anybody understand how passkeys protect against phishing more than OTP codes do? With OTP codes, an attacker can just ask the user to share their code ("please share your 2fa code to authenticate yourself"), surely with passkeys the same attacker could just ask the user to scan the login QR code ("please scan this QR code to authenticate yourself").

Edit: I looked into it a bit more, it seems like it only works if the browser and scanning phone are in bluetooth range. That's definitely pretty good in terms of phishing protection, but a hard dependency on bluetooth would mean this will not work at all on many desktop computers...

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#26
post #4

One thing I never understood about this passkeys thing is: how will the passkeys database be kept in sync between your iPhone, your Windows desktop, your Linux laptop and your Android tablet? I've tried to research the topic a bit but everything I've been able to find has been about exporting and importing between ecosystems, but most people don't use only a single company's products.

In words of Tim Cook on the last event: "Just buy an iPhone (or a Mac and an iPad)".

Making your experience bad on non-Apple devices is part of the design, not accident.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#27
post #10
post #6

Earlier quoted context omitted.

Apple has a long history of working best together with Apple. For example, the iPod music players only worked with iTunes. I think that Apple hopes that such features cause people to switch more of their electronics to Apple

Sure, but this is trying to replace passwords. As much as Apple would want it different, there's a whole lot of people who use one Apple device but has other devices from other manufacturers, and surely an industry effort like FIDO to replace passwords would take that into account?

Apple made talking to family, friends and other people a moat to keep people in their walled garden. Taking control of your passwords is extension of that strategy, not something they feel bad about.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#28
post #17

Earlier quoted context omitted.

I want to use my iCloud keychain as a password manager since the level of trust I've already given apple allows them to acquire most of my passwords (and 2 factor codes) anyway. Safari integrates with it, but there is no Firefox or chrome plugin to do domain based validation or to keep my clipboard sane. Apple has either failed to allow uBlock to function in safari (after which I would consider migrating to safari),…

> there is no Firefox or chrome plugin to do domain based validation or to keep my clipboard sane. That's Chrome's and Firefox' fault for not using the password autofill APIs: https://developer.apple.com/documentation/security/password_... Chrome issue: https://bugs.chromium.org/p/chromium/issues/detail?id=117006... Firefox issue: https://bugzilla.mozilla.org/show_bug.cgi?id=1650212 Btw, Chrome used to be able to rea…

[deleted]

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#29
post #21
post #16

Earlier quoted context omitted.

The passkeys are only synced across Apple devices, via iCloud keychain. Trying to sign in on another device (e.g. Windows laptop, Android phone) will require scanning a QR code. The devices then establish a secure channel using FIDO caBLE v2 (introduced by Google/Chrome, I believe) to perform the authentication. This ensures the passkeys never leave your Apple device, but can still be used on other devices. You can s…

Aha, so you get a significantly worse experience if you're not 100% in the Apple ecosystem, and you can't sign in at all if you don't have your Apple device on you. I'll keep using passwords, thanks.

If you are using passwords that you can remember without your phone then I assume it's pretty basic and insecure.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#30
post #26
post #4

One thing I never understood about this passkeys thing is: how will the passkeys database be kept in sync between your iPhone, your Windows desktop, your Linux laptop and your Android tablet? I've tried to research the topic a bit but everything I've been able to find has been about exporting and importing between ecosystems, but most people don't use only a single company's products.

In words of Tim Cook on the last event: "Just buy an iPhone (or a Mac and an iPad)". Making your experience bad on non-Apple devices is part of the design, not accident.

I worked at Apple and no one is deliberately making the experience bad on non-Apple devices.

They just have a million things they want to do, limited resources and so they simply don't prioritise it.

Post reply on HN