Live data from Hacker News

Apple passwords deserve an app

cabel.com

321–330 of 414 posts

Re: Apple passwords deserve an app

#321
I'm all for this, a better cross-platform Keychain app would be awesome.

To get my Credit Card details, I need to go Settings > Safari > AutoFill > Saved Credit Cards.

To get 2FA / Password details, I need to go Settings > Passwords.

In a lot of cases, they auto-fill without issue. But to manage these is a bit of a flimsy process.

Re: Apple passwords deserve an app

#322
post #80

What the actual flying fuck, the apple password thing supports TOTP! That's great! (And a sad testament to how poorly the discoverability is on some ios features)

Not just that, they will detect QR code images to work around sites which assume that TOTP is only available by scanning your desktop screen from your phone.

Step Two[1] also does this, which is one of the reasons I've been using it for TOTP for the past few years. Nice to see that the built-in TOTP support can do that now too.

[1]: https://steptwo.app

Re: Apple passwords deserve an app

#323

Am I the only person on Earth that needs sharing of passwords among my family? Any time folks bring up password solutions, they are always missing this requirement for me. 1Password is a life-saver in this regards. All my kids have their own vaults but for the little ones I have them use a shared vault between my wife and me so we have access to their passwords. I can also easily share passwords for services like Net…

Not at all. Bring on the shared family iCloud Note. lol

Re: Apple passwords deserve an app

#324

Earlier quoted context omitted.

> allow this application to access all saved passwords I'd like to see finer granularity, perhaps multiple web password vaults and a mechanism to allow certain browsers to use certain vaults. It might also be nice to specify which passwords could be accessed with which kind of authentication. Unfortunately the current system password dialog is easily spoofable - it really looks like a questionable javascript popup.

What would that look like? Do you expect a prompt for every website you visit (Would you like to allow permission for Firefox/Chrome/whatever to view/store your password for "abcd.example.com"?) Would the permission be tied to the name of the app or the hash of the app? How do you securely identify the browser? Signed apps? Signed via a developer key -- trust the developer so that you can use Chrome as well as Chrome…

> Do you expect a prompt for every website you visit (Would you like to allow permission for Firefox/Chrome/whatever to view/store your password for "abcd.example.com"?)

This is pretty much exactly how macOS Safari prompts, and has for several years, at least in Touch ID scenarios. It shows a suggested username/identity with a Touch ID icon next to it, presented just like a normal autofill suggestion otherwise.

The per-site prompt and the inclusion of username/identity are really good signals, and feel like they reinforce the opposite of Windows UAC. They definitely gate access in a similarly repetitive way which encourages repetitive acceptance. But they demonstrate prior authorization that would have to be manual at least once at some point before the prompt, and you won’t be promoted the same way for sites you didn’t manually authorize first.

It’s a good enough signal that I generally use it as my first line of defense against phishing/domain spoofing. If I don’t get promoted for credentials for a service I expect to have an account with, I’m immediately suspicious. That doesn’t mean I automatically trust or distrust on that alone, but it’s a pretty decent sniff test.

Re: Apple passwords deserve an app

#325
post #4

I tried going all-in on using iCloud Keychain (correct term?) for my passwords from having previously used LastPass. In short. 1. The experience on Windows is terrible. They can claim it's cross-platform but it's truly a sub-par product. 2. On Mac it's tied specifically to Safari. I use Safari a lot but if I'm in a different browser then my passwords are unavailable. 3. The GUI is buried in System Settings. Heaven fo…

That's all by design. They want you 100% on Apple products to get the full experience.

The full experience for their shareholders you mean :P

Re: Apple passwords deserve an app

#326

I might argue instead that simply having Passwords as another item inside Settings is appropriate for what functionality it exposes. It's a feature, not a product, doesn't do everything that Keychain Access does in macOS, and doesn't need (or deserve) to be in your face all the time. Do keyboards/wallpaper/voip apps/whatever really need to have their own app icon on your homescreen? Probably not, but Apple's conditio…

Do you really need to go back to your car, open your trunk, get the wallet just to show your ID?

Passwords are my ID, sometimes I have to enter them onto another computer or app or just share them with someone; I shouldn’t need to hunt my ID in the trunk of my car.

Keychain Access did this right decades ago, so there’s some logic behind it. The issue is that the app is not built for this decade and its UI is lacking.

Re: Apple passwords deserve an app

#327
post #159

I'd never use a password manager built by Apple for the same reason I don't use Chrome's password manager or Firefox's password manager. All these passwords managers have strong incentives for "working best on ™". I want a password manager independent from any platform like Bitwarden or 1Password, because it's actually valuable for THEM to target all the platforms they can.

The problem is that the integrated managers really do work best on platform, i.e. alternatives aren’t nearly as well-integrated.

So here I am using Safari on my computer and phone.

Re: Apple passwords deserve an app

#328
post #311
post #159

I'd never use a password manager built by Apple for the same reason I don't use Chrome's password manager or Firefox's password manager. All these passwords managers have strong incentives for "working best on ™". I want a password manager independent from any platform like Bitwarden or 1Password, because it's actually valuable for THEM to target all the platforms they can.

I don't understand. Chrome and Firefox don't have platforms. Which means they run pretty much everywhere they're allowed to. Apple is the only one of those three that restricts their software to hardware that only they sell. So in that case I do understand your position.

> they run pretty much everywhere they're allowed to.

Yep, they’re allowed to run on Chrome, that’s Google’s platform.

Good luck using your Chrome/Google passwords outside Chrome/Google apps.

Firefox at least does (or used to) offer a Lockbox app to use the password on your phone.

Re: Apple passwords deserve an app

#329

Earlier quoted context omitted.

> 1. The experience on Windows is terrible. They can claim it's cross-platform but it's truly a sub-par product. Like a lot of other Apple stuff, I'm only able to use it because I don't use anything non-Apple for anything "serious" that involves a GUI. Windows is for gaming, Linux is my file storage and docker-service-running server that I only interact with over SSH and Web. Ditto Notes, all their Office-type progra…

> Yeah, this is super fucking weird. You'd think this would be connected in some fashion to "keychain", but nope. Other browsers used to be able to use it. I do think it’s a really thorny issue—“allow this application to access all saved passwords?” is a pretty damn scary permission to include. Up there with the “allow this application to control your computer” permission that is used for accessibility apps (which ap…

Isn't this the exact thing that got MS in trouble with anti-trust for Explorer? How is apple getting away with it?
Post reply on HN