Live data from Hacker News

Apple’s Killing the Password. Here’s Everything You Need to Know

wired.com

31–40 of 99 posts

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#32
post #3

> Passkeys work in Apple’s Safari web browser as well as on its devices. I sure wish apple would be a little bit better of a citizen when it comes to interoperability. Safari only features (which is what I'm assuming this will be based on apples history and the quote) are upsetting. uBlock is the single most important piece of software on my computer and my devotion to it exceeds any and all possible other features.…

Google recently asked me to connect via Bluetooth to authorize my laptop with my phone. Just that Bluetooth was completely disabled from my laptop and it did not offer any other option.

For some reason the login on Gmail still offered the 'press ok on your phone' method. No idea what I should have done otherwise.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#33
post #26

Earlier quoted context omitted.

In words of Tim Cook on the last event: "Just buy an iPhone (or a Mac and an iPad)". Making your experience bad on non-Apple devices is part of the design, not accident.

I worked at Apple and no one is deliberately making the experience bad on non-Apple devices. They just have a million things they want to do, limited resources and so they simply don't prioritise it.

Potato, potahto. So they deliberately don't prioritise it.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#34

Does anybody understand how passkeys protect against phishing more than OTP codes do? With OTP codes, an attacker can just ask the user to share their code ("please share your 2fa code to authenticate yourself"), surely with passkeys the same attacker could just ask the user to scan the login QR code ("please scan this QR code to authenticate yourself"). Edit: I looked into it a bit more, it seems like it only works…

FIDO authentication, of which webauthn is the successor, works like this: your secret is a signing key for a digital signature cryptosystem. When you authenticate, it signs a message containing various things including the hostname of the site being authenticated to, and because this is under the control of the browser, a phishing site can't fake it easily (also the browser will throw a fit if you're not on https).

The result is that if you are tricked into entering your credentials into google.com.totallynotaphishingsiteipromise.evilsite.com which is doing a man-in-the-middle attack against the real site - maybe with a let's encrypt cert so they can do https on their own domain name - then the authentication token they send to the real google will have the correct signature, but the wrong domain name.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#35
post #21

Earlier quoted context omitted.

Aha, so you get a significantly worse experience if you're not 100% in the Apple ecosystem, and you can't sign in at all if you don't have your Apple device on you. I'll keep using passwords, thanks.

If you are using passwords that you can remember without your phone then I assume it's pretty basic and insecure.

You can use password manager that is cross platform. You can even use something like KeePassXC and sync the database between devices. All encrypted and secure without even having a phone if you want. You don't need to remember passwords without or with your phone.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#36
post #26

Earlier quoted context omitted.

In words of Tim Cook on the last event: "Just buy an iPhone (or a Mac and an iPad)". Making your experience bad on non-Apple devices is part of the design, not accident.

I worked at Apple and no one is deliberately making the experience bad on non-Apple devices. They just have a million things they want to do, limited resources and so they simply don't prioritise it.

This is still quite bad, just like omitting the truth is a form of lying.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#37

Does anybody understand how passkeys protect against phishing more than OTP codes do? With OTP codes, an attacker can just ask the user to share their code ("please share your 2fa code to authenticate yourself"), surely with passkeys the same attacker could just ask the user to scan the login QR code ("please scan this QR code to authenticate yourself"). Edit: I looked into it a bit more, it seems like it only works…

FIDO authentication, of which webauthn is the successor, works like this: your secret is a signing key for a digital signature cryptosystem. When you authenticate, it signs a message containing various things including the hostname of the site being authenticated to, and because this is under the control of the browser, a phishing site can't fake it easily (also the browser will throw a fit if you're not on https). T…

I was more worried about attacks where the attacker takes a screenshot of the QR code and sends it to the user while pretending to be a support agent. So the user never even opens any evil site in their browser.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#38
post #26

Earlier quoted context omitted.

In words of Tim Cook on the last event: "Just buy an iPhone (or a Mac and an iPad)". Making your experience bad on non-Apple devices is part of the design, not accident.

I worked at Apple and no one is deliberately making the experience bad on non-Apple devices. They just have a million things they want to do, limited resources and so they simply don't prioritise it.

> limited resources

haha, oh really?

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#39
post #3

> Passkeys work in Apple’s Safari web browser as well as on its devices. I sure wish apple would be a little bit better of a citizen when it comes to interoperability. Safari only features (which is what I'm assuming this will be based on apples history and the quote) are upsetting. uBlock is the single most important piece of software on my computer and my devotion to it exceeds any and all possible other features.…

But can the private key be exported or can I login only with the help from my Apple™ iPhone? What they describe isn't interoperability, it is 2FA using a phone. Interoperability means they implement a standard and I could migrate my key to an android phone. Is it the case?

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#40
post #26

Earlier quoted context omitted.

In words of Tim Cook on the last event: "Just buy an iPhone (or a Mac and an iPad)". Making your experience bad on non-Apple devices is part of the design, not accident.

I worked at Apple and no one is deliberately making the experience bad on non-Apple devices. They just have a million things they want to do, limited resources and so they simply don't prioritise it.

Using "limited resources" while talking about Apple is surely a joke, right?
Post reply on HN