The UI probably needs to be more explicit about what's going on. I would imagine most non-technical users aren't well-versed in how Apple's Secure Enclave (or other competing solutions) manage authentication, and so I wouldn't be surprised if "allow example.com to use TouchID" would give many the impression that the website is asking to access their biometric data. Ideally, the prompt should reflect the actual model,…
Face ID and Touch ID for the Web
171–180 of 371 posts
Re: Face ID and Touch ID for the Web
#172Earlier quoted context omitted.
Apple didn't just roll their own though, they improved upon it by allowing them to easily revoke attestation for a particular implementation without affecting all other devices out there. So if an attacker tampers with the physical device, they can revoke the key for that particular device so that it is no longer trusted (the way I am reading it) vs yubikey where if an attacker has messed with one key, there is no go…
> So if an attacker tampers with the physical device, they can revoke the key for that particular device so that it is no longer trusted (the way I am reading it) vs yubikey where if an attacker has messed with one key, there is no good way to revoke attestation for that one device. Attestation is a statement that the hardware and firmware are genuine, with the trust model being based on genuine hardware/software. Yo…
Instead of "This site requires IE6" we'll have "To log back into your account, please buy an iPhone 12 Pro Max and re-register".
I'm imagining an undesirable future where having access to different sites requires carrying around multiple different pieces of authentication hardware, and the user has to keep track of which device is needed for each site. Still, that might be better than a future where all sites mandate using an authenticator made by a specific monopoly company/government, assuming we can avoid that.
Re: Face ID and Touch ID for the Web
#173Earlier quoted context omitted.
No, there's no world where Apple blocks access to an account because they're showing derogatory content towards Apple products, and a company gets a judge to overturn that block because it's not technically libel. Apple has the right to block you from their sign-in for any reason. Short of pulling a move like Epic and suing them for antitrust, a court of law is never going to enter into the equation. None of these ar…
> Apple gets to decide what they mean. (IAAL, this is not legal advice.) That's not how contract law works. There's a whole body of law around how to construe language in contracts, and it's subject to litigation and dispute if the definition isn't made clear in the contract itself. > no court of law is going to rule that they don't have the right to block Then you don't know courts very well. Such clauses are still…
Do you really not see how saying, "businesses should be allowed to sever ties with people who say mean things" is different from saying, "the courts will decide whether or not you committed libel"?
> For example, no competent court is going to allow anyone to use an escape clause to terminate a contract with someone because of their race, age, or gender.
Do you think there's a difference between a court saying, "we're not going to allow you to sever a business relationship because of a protected characteristic", and "we're going to regulate what does and doesn't count as disparagement"?
Can you point me at an example of a business fighting a disparagement clause in a contract with language like this and winning, based on a court deciding that what they said didn't count as disparagement?
This is like the people who say they're going to sue Facebook for taking down posts because their definition of "misleading information" isn't specific enough. You can sue anyone for anything, but you're not going to win that case. Companies with contract language like this have broad leverage to wield their power in whatever way they see fit -- because for the most part courts have not ruled that escape clauses boiling down to "we can decide to ban you at any time for any reason" are illegal or unenforceable.
Re: Face ID and Touch ID for the Web
#174This comes 3 days after a leak that alleged that iPhone 13 will bring back Touch ID via in-screen fingerprinting https://www.techradar.com/uk/news/move-over-iphone-12-apples...
Hasn't this been leaked for like the past 3 years?
I do miss Touch ID, but that had its own problems (gloves, wet fingers). So one would hope there is a solution that has both. I'd personally be just peachy with a fingerprint sensor on the back just like the Pixel line used to have. I mean, how much is a fingerprint sensor manufacturing cost? $5?
Re: Face ID and Touch ID for the Web
#175Earlier quoted context omitted.
> Since I have zero need to deliberately violate Apple's App Story policy, I don't worry about this overmuch. That may be true today, but their policies are a moving target. Who knows what they'll be like in a year's time?
You could say that about anything -- nothing is completely static -- but it's worth mentioning that Apple vs. Epic is a counterexample; Epic wants apple to change their policies (lower than 30% cut) while Apple wants to maintain the same structure since the inception of their app store.
1. Contracts are a thing. You can draft a contract with your vendor that guarantees certain terms for a certain duration.
2. You should be wary of wandering into commitments (including de facto commitments e.g. "vendor lock-in")--there are plenty of good reasons to do so, but one should make sure to properly consider the cost.
The problem is that doing business with Apple can make or break a company--companies can scarcely afford not to do business with Apple. I'm not an economist, but this seems pretty monopolistic (which isn't to say Apple should be broken up, but perhaps more tightly regulated).
Re: Face ID and Touch ID for the Web
#176Earlier quoted context omitted.
I've had an issue with sign-in with Apple where using an autogenerated emails ruins certain support interactions. One of them was cancelling a subscription service that was eventually resolved (they required me to email their customer support, which I couldn't figure out how to do using the autogenerated email address created by "sign-in with Apple").
While it’s frustrating and worth pointing out of course - what really happened there was a bug in the service provider’s support process!
Re: Face ID and Touch ID for the Web
#177Earlier quoted context omitted.
"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)
For what it's worth, it's been said (by anonymous sources, no one on the record) that Apple did not threaten to terminate Epic's "Sign in with Apple" accounts/features, and they spent extra effort to maintain their access to that after their account was terminated. I do not know if other terminated accounts get this "luxury".
https://www.theverge.com/2020/9/10/21431396/epic-sign-in-wit...
Apple commented they weren’t doing anything to stop Sign In with Apple working, but I have to wonder if there’s a lie of omission in there. Like “We aren’t doing anything deliberate to stop it, but it’s going to stop as a side effect of terminating their developer account.”
Either that or Epic was lying outright.
Re: Face ID and Touch ID for the Web
#178Earlier quoted context omitted.
> I would definitely stay away from any "Sign in with Apple". I would stay away from any "Sign in with.." service as a user and as a product owner. You're affectively giving away a major control of your users to a third party.
As a product owner, why wouldn't I want to piggyback on the millions of dollars of R&D + security that the big companies have put in? And as a user, why would I trust my password to the website that rolled their own authentication over the big companies?
Re: Face ID and Touch ID for the Web
#179Earlier quoted context omitted.
The fingerprint sensor found on most phones doesn't always require intent, either.
Interestingly, touch ID launched 1 year after Apple refused to unlock an iPhone for the FBI.