If passwords are the original sin, then Face ID and Touch ID are Sodom and Gomorrah. Authentication is something you KNOW. Strong authentication is something you KNOW, and something you HAVE. Something you ARE is great for identification, but terrible for authentication. Something you are cannot be changed like a password.
Face ID and Touch ID for the Web
151–160 of 371 posts
Re: Face ID and Touch ID for the Web
#152Earlier quoted context omitted.
At least, in the case of biometric authentication on device, the ability to use biometrics expires automatically when the device is turned off (and other times), so biometric credential theft has a limited window of vulnerability. This contrasts with many fixed biometric authentication systems that aren't used as often as a cell phone.
Maybe... but if I steal your fingerprint, I have it forever. And the courts can't yet force you to reveal secrets from your mind. But you can be compelled to use your fingerprint to unlock things.
Re: Face ID and Touch ID for the Web
#153Earlier quoted context omitted.
> Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". If you don't renege on your agreements with Apple as part of a public pissing contest, and you aren't in the business of misleading customers and creating deceptive apps, it's unlikely they'll revoke your developer account.
unilateral agreements that one side can change on a whim is not something that one would call a fair agreement in the first place.
Contracts of adhesion are just a part of life. We agree to them practically every day whenever we do business with a third party. And if you were in the other party's shoes, you'd do the same thing; otherwise you couldn't practically run a business.
Re: Face ID and Touch ID for the Web
#154Earlier quoted context omitted.
You're missing the point of biometrics. Something you are is a form of authentication that only you can use. Your face, fingerprints, blood, retinas are all public but try as you might you can't make another living human with the same features. If your view of fingerprint auth is "a picture of your face is the password" then of course it sounds stupid. It's actually "a face with the correct features attached to an al…
That's trivially refutable. Fingerprints are left everywhere, and can be lifted and reproduced with common household substances (tape, glue etc). A face can be photographed, printed and presented trivially. And so far, biometrics falls far short of a 4/5 digit lock passcode. The entropy in most fingerprint sensors is a few bits. They are famously defeatable. Nothing will change the fact that you cannot keep your face…
That means that you're left with really unusual situations like someone stalking you with drones with 3-D infrared scanners who can't figure out how to have the same drone record your password when you type it in many times per day.
1. https://support.apple.com/en-us/HT204587 https://support.apple.com/en-us/HT208108
Re: Face ID and Touch ID for the Web
#155So happy Apple decided to go with an open standard here rather than something proprietary. This is good news for the FIDO2 ecosystem and I hope this leads to far greater support for FIDO2 authenticators of all types. There is another world in which Apple just pushed 'Sign in with Apple' and created yet another federated identity provider rather than true, 'secure element'-based FIDO2 authentication.
"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)
I do not know if other terminated accounts get this "luxury".
Re: Face ID and Touch ID for the Web
#156Earlier quoted context omitted.
As a user I would prefer no account in most cases. As a distant second, I would prefer the convenience, security, and privacy of Sign in with Apple over Google, Facebook, or the headache of managing yet another web account . As a developer, I use my preferences as a user to steer my choices, but recognize that the world doesn't revolve around Apple so would allow other options. > Having saw Epic's developer account t…
> Since I have zero need to deliberately violate Apple's App Story policy, I don't worry about this overmuch. That may be true today, but their policies are a moving target. Who knows what they'll be like in a year's time?
Re: Face ID and Touch ID for the Web
#157If I can use FIDO2 on my yubikeys in more places, it would be fantastic.
You can already use NFC and Lightning yubikeys on your iPhone. On iPad Pro there are issues using USB-C still in my experience. Being able to use FaceID on there now will be nice.
Re: Face ID and Touch ID for the Web
#158So happy Apple decided to go with an open standard here rather than something proprietary. This is good news for the FIDO2 ecosystem and I hope this leads to far greater support for FIDO2 authenticators of all types. There is another world in which Apple just pushed 'Sign in with Apple' and created yet another federated identity provider rather than true, 'secure element'-based FIDO2 authentication.
I think about Apple Pay for web - it started out as a proprietary API, and then the Payment Request API standard was developed and they added support for that.
It's in Apple's interest to help develop and support standards like this because they mean more adoption of their platform features.
Re: Face ID and Touch ID for the Web
#159So happy Apple decided to go with an open standard here rather than something proprietary. This is good news for the FIDO2 ecosystem and I hope this leads to far greater support for FIDO2 authenticators of all types. There is another world in which Apple just pushed 'Sign in with Apple' and created yet another federated identity provider rather than true, 'secure element'-based FIDO2 authentication.
This doesnt really surprise me - Apple has a history of implementing, or moving to, standards for their platform features in Safari. I think about Apple Pay for web - it started out as a proprietary API, and then the Payment Request API standard was developed and they added support for that. It's in Apple's interest to help develop and support standards like this because they mean more adoption of their platform feat…
Re: Face ID and Touch ID for the Web
#160Earlier quoted context omitted.
> I would definitely stay away from any "Sign in with Apple". I would stay away from any "Sign in with.." service as a user and as a product owner. You're affectively giving away a major control of your users to a third party.
I think "Sign in with Apple" is unique that Apple allows the users to hide their email address https://support.apple.com/en-us/HT210425 which makes it extremely hard to migrate away, unlike other federated login system where you can at least get users' email addresses, allowing you to create a proper email+password login later on.