What standard is this using? The doc doesn't specify.
Apple Passkey
131–140 of 421 posts
Re: Apple Passkey
#132Earlier quoted context omitted.
You are 100% correct that you need to add it to each service. This is a consequence of an intentional decision (keys cannot be duplicated). Streamlining it would definitely be an improvement. That being said, it's not a problem in the real-world because FIDO is so sparsely supported. Hopefully PassKey speeds things along.
Streamlining would be an improvement, but it opens an attack vector. Unfortunately, security and usability are always in balance.
Re: Apple Passkey
#133Earlier quoted context omitted.
> Also we still need ways of exporting keys and software (like 1password) needs to synchronize them, manage them securely. There's still a long ways to go on that front, which probably won't be handled until stuff like this has settled. That's the point of passkeys here: iCloud Keychain syncs them, and if you want to use your keys on a non-apple device you'll be able to scan a QR code, which initiates a new BLE conne…
I'm writing this on a non-Apple computer that doesn't have any radios. Now what?
Re: Apple Passkey
#134Earlier quoted context omitted.
???? The goal of all this is to make auth tokens be single-factor , not one factor in MFA. If you read the Ars article linked elsewhere in the thread the people behind it are pretty clear about their desire to get rid of passwords.
The security of these tokens is still MFA as an end-to-end security model , insofar as you need a something-you-know [password, passcode] to unlock the device that serves as your something-you-have. So someone who just steals the device, can't use it to authenticate as you. (See also: smart cards having PINs.) And, once again, companies doing MFA properly , enforce MDM policies on such devices, such that they either…
Re: Apple Passkey
#135I think we need a browser level or OS level notification about which passwordless service we used last time. Did we use Gmail, Twitter, Signin with Apple, Github, Linkedin, or do I actually have something stored in my password manager associated with an email and if so, did I store it in the browser's password manager, the OS's password manager, or my third party password manager?
Why do you use more than one password manager? I have disabled all password managers in every app that I use except for the one I store things in. I have multiple folders with their own passwords too but they're all stored via the same solution.
Work vs home is one driver.
And for some cases, "Login with Google" or similar is nice because it integrates Google pay, removes sign-up friction, etc. I'm aware it has downsides, but it remains useful in some niche areas.
Re: Apple Passkey
#136Earlier quoted context omitted.
Why do you use more than one password manager? I have disabled all password managers in every app that I use except for the one I store things in. I have multiple folders with their own passwords too but they're all stored via the same solution.
Because Google Chrome on iOS pops up asking to remember a password Safari on iOS suggests a password even if I'm trying to paste on in from my password manager OSX can be the same way They all sync and I never bothered to disable them because I never thought about it, but sometimes I'm in a rush with a service I think I'll never use again and use the suggested solution in one of the browsers
I think you should resist sooner rather than later and switch to something cross-browser and third-party.
But it's up to you, of course.
Re: Apple Passkey
#137For those in the know, will I be able to export my private keys and data from Passkey somehow, so that if I wanted to, I could switch to another FIDO device or system? I would speculate Apple is not going to support this, and Apple will retain control of the private keys, and do the request signing like an old-school USB FIDO device, but I don't know for sure.
Re: Apple Passkey
#138I think we need a browser level or OS level notification about which passwordless service we used last time. Did we use Gmail, Twitter, Signin with Apple, Github, Linkedin, or do I actually have something stored in my password manager associated with an email and if so, did I store it in the browser's password manager, the OS's password manager, or my third party password manager?
Re: Apple Passkey
#139I can be onboard with this if Apple opens up an iCloud API for syncing, so I can sync a non-Apple device through iCloud, and if I leave Apple and iCloud behind, my non-Apple devices keep working, even if I never sync through iCloud again.
Re: Apple Passkey
#140How do I leave the Apple ecosystem if I go all in on this? Sounds like major vendor lock in under a deceptive title of “open standards” but I’m hoping I’m wrong here. Does anybody happen to know yet?