Live data from Hacker News

Apple Passkey

developer.apple.com

161–170 of 421 posts

Re: Apple Passkey

#161
post #46

This is based on the open standards WebAuthn and FIDO2, where the credentials (“passkeys”) are synced via iCloud Keychain. Currently you need remember to register at least 2 security keys, in case one is lost/misplaced. The syncing of passkeys in iCloud solves this backup problem. https://fidoalliance.org/apple-google-and-microsoft-commit-t...

> The syncing of passkeys in iCloud solves this backup problem. But then apple has your keys....

iCloud Keychain is end-to-end encrypted.

Re: Apple Passkey

#162
post #46

This is based on the open standards WebAuthn and FIDO2, where the credentials (“passkeys”) are synced via iCloud Keychain. Currently you need remember to register at least 2 security keys, in case one is lost/misplaced. The syncing of passkeys in iCloud solves this backup problem. https://fidoalliance.org/apple-google-and-microsoft-commit-t...

> The syncing of passkeys in iCloud solves this backup problem. But then apple has your keys....

Passwords in iCloud Keychain are already E2EE, it seems reasonable the private passkeys would be too.

Re: Apple Passkey

#163
post #135

Earlier quoted context omitted.

Why do you use more than one password manager? I have disabled all password managers in every app that I use except for the one I store things in. I have multiple folders with their own passwords too but they're all stored via the same solution.

>Why do you use more than one password manager? Work vs home is one driver. And for some cases, "Login with Google" or similar is nice because it integrates Google pay, removes sign-up friction, etc. I'm aware it has downsides, but it remains useful in some niche areas.

Most password managers allow you to separate work from home, though. You don't need to store them in different platforms to have them in different places.

Re: Apple Passkey

#164

Earlier quoted context omitted.

> The syncing of passkeys in iCloud solves this backup problem. But then apple has your keys....

Passwords in iCloud Keychain are already E2EE, it seems reasonable the private passkeys would be too.

How could one verify that? like for compliance audit?

Re: Apple Passkey

#165
This is wonderful news! If anyone is interested in experimenting we built an API that makes it very simple to add WebAuthn (passkeys) to your existing web app.

It’s available at https://passwordless.dev

Note: We also maintain the open source fido2-net-lib, the API just lowers the friction for devs.

Re: Apple Passkey

#166
post #73

Earlier quoted context omitted.

What happens when you're not using an apple device?

I saw a screenshot. Somehow a QR code is presented and you scan that with your phone. I’m not entirely sure what happens from there. But there was a picture of them using it with a Windows machine. So they’ve thought of it.

interesting, but it still needs an iPhone> -- I was kind of burned hard when trying to migrate my iCloud keychain passwords to something else so I'm curious how smooth it actually is

Re: Apple Passkey

#167

Earlier quoted context omitted.

Passwords in iCloud Keychain are already E2EE, it seems reasonable the private passkeys would be too.

How could one verify that? like for compliance audit?

https://support.apple.com/guide/sccc/introduction-sccccea618...

Introduction to Apple security assurance

As part of our commitment to security, Apple regularly engages with third-party organizations to certify and attest to the security of Apple’s hardware, software, and services. These internationally recognized organizations provide Apple with certifications that align with each major operating system release. …

Re: Apple Passkey

#168
post #159

Earlier quoted context omitted.

> The syncing of passkeys in iCloud solves this backup problem. But then apple has your keys....

iCloud Backups != iCloud syncing iiuc. Passwords/Wifi/etc. syncing is a different E2EE system. You can disable iCloud Backups and still use iCloud

ahhh so they already have what they need to do iCloud E2EE, they just decide not to use it for your data....

Re: Apple Passkey

#169
Sorry for the somewhat but not quite off topic post, but can we please prevent HN from becoming yet another Apple billboard? There are more than enough of those already. Thank you.

Yes I've heard that there may be some Apple manifestation going on or something but to have every little Apple tidbit hoisted directly to the front page (at least 7 articles and counting) is a bit much imho.

Downvote me if you must, but I think it is important to have my opinion heard, and I don't think I am the only one.

Re: Apple Passkey

#170

Earlier quoted context omitted.

Apple is the face on the screen. There is no lady with a hammer. https://youtu.be/OYecfV3ubP8

This is based on an open standard and is entirely optional. So your analogy makes absolutely no sense.

It's a metaphor.

Semantics aside, holding private keys hostage with no recourse is Orwellian. A for-profit company has no business being a centralized identity authority.

Post reply on HN