Live data from Hacker News

Apple’s Killing the Password. Here’s Everything You Need to Know

wired.com

81–90 of 99 posts

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#81
post #12
post #7

Earlier quoted context omitted.

Passwords are synced to Windows via iCloud, i suppose these keys would be synced like that as well: https://support.apple.com/en-gb/guide/icloud-windows/icwd3c1...

Right, but all software which uses passwords would need to support it too, right? I'm not confident that all of the Windows ecosystem will adopt iCloud for passkeys, nor am I confident that Apple will tightly integrate into whatever system thing Microsoft puts in Windows to manage FIDO keys... This isn't like a password manager after all, where getting the key in your clipboard is a universal way to use it anywhere y…

Apple says they are working with Microsoft and Google to meet all FIDO standards on this. It's still early days, but FIDO as a standards body does seem to be working towards standards for working with heterogenous keychains. Given how many users use Chrome on Windows and have an iOS device, I think heterogenous keychains are going to be critical to mass adoption and everyone says they are working towards that. A lot of this may be on FIDO to truly coordinate.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#82
post #39
post #3

> Passkeys work in Apple’s Safari web browser as well as on its devices. I sure wish apple would be a little bit better of a citizen when it comes to interoperability. Safari only features (which is what I'm assuming this will be based on apples history and the quote) are upsetting. uBlock is the single most important piece of software on my computer and my devotion to it exceeds any and all possible other features.…

But can the private key be exported or can I login only with the help from my Apple™ iPhone? What they describe isn't interoperability, it is 2FA using a phone. Interoperability means they implement a standard and I could migrate my key to an android phone. Is it the case?

It's based on Webauthn and other FIDO standards. Private keys can't be exported (because it would defeat some of the features of a "secure enclave"), but other keys can be added to keychains. You should be able to migrate between devices/device-types across the Webauthn and FIDO standards. It's still early days that some of that isn't easy or "complete" yet, but the standards are being built and Apple and Google and Microsoft have all agreed to cooperate on them.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#83

Earlier quoted context omitted.

You should read the Mythical Man-Month. You can't just add unlimited developers to a project and expect it to be productive or sustainable. No different at Meta, Spotify, Netflix etc.

I don’t see how an extra program built for windows or linux can in any way stall whatever project limits Apple faces for macos. They’re effectively independent projects.

> They’re effectively independent projects.

Unless you care about interoperability, which for a product like this is essential.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#84
post #46

Earlier quoted context omitted.

If you are using passwords that you can remember without your phone then I assume it's pretty basic and insecure.

Presenting this as a choice between using Apple's closed solution or using easy-to-remember passwords is disingenuous. Please don't participate in the discussion if you're going to be this bad faith.

You literally said you would keep using passwords. The dichotomy was established by you.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#85
post #46

Earlier quoted context omitted.

Presenting this as a choice between using Apple's closed solution or using easy-to-remember passwords is disingenuous. Please don't participate in the discussion if you're going to be this bad faith.

You literally said you would keep using passwords. The dichotomy was established by you.

> I'll keep using passwords, thanks.

> If you are using passwords THAT YOU CAN REMEMBER WITHOUT YOUR PHONE then I assume it's pretty basic and insecure.

> Presenting this as a choice between using Apple's closed solution or using EASY-TO-REMEMBER passwords is disingenuous.

All caps to indicate how sbuk changed the meaning of what mort96 said.

The dichotomy was between using using Apple's solution and using passwords. Deciding the latter must mean using easy to remember passwords and not acknowledging the existence of password managers and complex password generators is at best ignorance or forgetfulness and at worst dishonesty.

Unlike mort96, I didn't automatically assume dishonesty, but sbuk posted this in response to mort96's accusation:

> You have been equally as disingenuous and based on your responses, acted in bad faith from the beginning in a bid to start a flamewar. How what you are doing is anything but basic bullying is beyond me.

This implies that they were aware of what they were doing and, rather than call mort96 out on what they believed to be an attempt at a flamewar, decided to contribute to it by deliberately altering the meaning of mort96's message.

I believe mort96 and sbuk were both accusatory and rude, but what sbuk appears to have done would be worse in my view. Rather than just assume the worst of who I'm communicating with, I'd rather give them the benefit of the doubt by inquiring for more information, attempting to inform, or possibly explaining how I interpreted a passage.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#86
post #39

Earlier quoted context omitted.

But can the private key be exported or can I login only with the help from my Apple™ iPhone? What they describe isn't interoperability, it is 2FA using a phone. Interoperability means they implement a standard and I could migrate my key to an android phone. Is it the case?

It's based on Webauthn and other FIDO standards. Private keys can't be exported (because it would defeat some of the features of a "secure enclave"), but other keys can be added to keychains. You should be able to migrate between devices/device-types across the Webauthn and FIDO standards. It's still early days that some of that isn't easy or "complete" yet, but the standards are being built and Apple and Google and…

I am not sure I understand the nuance between exporting a key and migrating the key between devices. Surely if you can do one you can do the other (at least technically/in term of security).

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#87
post #24

Which websites support passwordless authentication (FIDO2 WebAuth)? Microsoft and eBay, AFAIK. The rest may use U2F as a second factor not the only one. Also, for recovery you need multiple phones, and you need the websites to support that. It will probably take a while for websites to support this, and even then people are not going to buy and register several phones.

Best Buy already supports it.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#88
Oh, cool, Apple developed a new technology it calls "passkeys". I wonder how they work.

> Under the hood, Apple’s passkeys are based on the Web Authentication API (WebAuthn), which was developed by the FIDO Alliance and World Wide Web Consortium (WC3).

Okay, so Apple didn't develop it.

It's good to see Apple getting on board with web standards like WebAuthn considering how much they are dragging their heels on web standards on iOS but I just wish we could stop reporting on them without framing everything they do as groundbreaking innovation just because a man in a turtleneck sweater would have said so.

Alternative headline:

Apple brings WebAuthn support to iOS 16 and macOS Ventura

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#89

Earlier quoted context omitted.

I don’t see how an extra program built for windows or linux can in any way stall whatever project limits Apple faces for macos. They’re effectively independent projects.

> They’re effectively independent projects. Unless you care about interoperability, which for a product like this is essential.

Nah not really - there is already a proprietary API in iCloud that they use to synch keys between devices, that will be internally documented.

Re: Apple’s Killing the Password. Here’s Everything You Need to Know

#90
post #26
post #4

One thing I never understood about this passkeys thing is: how will the passkeys database be kept in sync between your iPhone, your Windows desktop, your Linux laptop and your Android tablet? I've tried to research the topic a bit but everything I've been able to find has been about exporting and importing between ecosystems, but most people don't use only a single company's products.

In words of Tim Cook on the last event: "Just buy an iPhone (or a Mac and an iPad)". Making your experience bad on non-Apple devices is part of the design, not accident.

As a person who isn't in the Apple ecosystem, this has always been what kept me off iOS.

If I have an Android device, I can use Linux or Windows (or macOS for that matter) on my laptop/desktop. If I have an iOS device, not using macOS just doesn't make sense and the only way to get a macOS legally is buying Apple hardware.

When the Apple watch came out, I was interested to see what Apple brings to the space but my interest was killed when I realized it will for all intents and purposes be an iOS companion device, not a true standalone product. So buying an Apple watch would have meant replacing my phone with an iPhone, which would have meant replacing my laptop with a macbook and my Android tablet with an iPad.

On paper there's nothing stopping anyone from using iOS devices and keeping their desktop/laptop on Windows or Linux. But the path of least resistance is buying into the entire Apple ecosystem (including iCloud, iTunes, etc) and getting any non-Apple alternative to occupy any of the slots Apple provides its own options for is an uphill battle (e.g. even when Apple provided a Windows version of iTunes it was notoriously bad, slow and lagging behind).

This irks me not only because it means you'll want to replace every digital device and every app Apple provides a stock solution for, you'll also find it nearly impossible to leave because there's no clear migration path if you have come to rely on iCloud, Keynote, Facetime, iMessage, your Apple wallet, your Apple credit card, or even Apple maps. If you want to add any "foreign" device, it will instantly be a worse experience than if you had picked the Apple alternative. Instead you'd have to either go cold turkey or wean yourself off by using alternative cross-platform apps when available (and willingly accepting the worse experience).

I think there are plenty of disingenuous criticisms of Apple (especially about their devices being "overpriced" when they're really just "too expensive" compared to equivalent consumer products available with more affordable specs) but I think it's extremely fair to describe their practices as an extreme example of vendor lock-in.

Post reply on HN