Live data from Hacker News

Face ID and Touch ID for the Web

webkit.org

171–180 of 371 posts

Re: Face ID and Touch ID for the Web

#171

The UI probably needs to be more explicit about what's going on. I would imagine most non-technical users aren't well-versed in how Apple's Secure Enclave (or other competing solutions) manage authentication, and so I wouldn't be surprised if "allow example.com to use TouchID" would give many the impression that the website is asking to access their biometric data. Ideally, the prompt should reflect the actual model,…

They could just have it say "example.com wants to use Touch ID to sign-in. Biometric data is not shared." with a help link that goes on to explain in laymens terms how your iPhone basically sends a password-ish thing to the website after you use Touch ID (similar to how Apple Pay sends a one-time use credit card number to a merchant).

Re: Face ID and Touch ID for the Web

#172
post #48

Earlier quoted context omitted.

Apple didn't just roll their own though, they improved upon it by allowing them to easily revoke attestation for a particular implementation without affecting all other devices out there. So if an attacker tampers with the physical device, they can revoke the key for that particular device so that it is no longer trusted (the way I am reading it) vs yubikey where if an attacker has messed with one key, there is no go…

> So if an attacker tampers with the physical device, they can revoke the key for that particular device so that it is no longer trusted (the way I am reading it) vs yubikey where if an attacker has messed with one key, there is no good way to revoke attestation for that one device. Attestation is a statement that the hardware and firmware are genuine, with the trust model being based on genuine hardware/software. Yo…

> allowing someone to authenticate into a lower security level until they re-register the phone after upgrading their operating system.

Instead of "This site requires IE6" we'll have "To log back into your account, please buy an iPhone 12 Pro Max and re-register".

I'm imagining an undesirable future where having access to different sites requires carrying around multiple different pieces of authentication hardware, and the user has to keep track of which device is needed for each site. Still, that might be better than a future where all sites mandate using an authenticator made by a specific monopoly company/government, assuming we can avoid that.

Re: Face ID and Touch ID for the Web

#173

Earlier quoted context omitted.

No, there's no world where Apple blocks access to an account because they're showing derogatory content towards Apple products, and a company gets a judge to overturn that block because it's not technically libel. Apple has the right to block you from their sign-in for any reason. Short of pulling a move like Epic and suing them for antitrust, a court of law is never going to enter into the equation. None of these ar…

> Apple gets to decide what they mean. (IAAL, this is not legal advice.) That's not how contract law works. There's a whole body of law around how to construe language in contracts, and it's subject to litigation and dispute if the definition isn't made clear in the contract itself. > no court of law is going to rule that they don't have the right to block Then you don't know courts very well. Such clauses are still…

> But yeah, if you use someone's services and then publicly talk trash about them? Why should they be forced to continue to do business with you?

Do you really not see how saying, "businesses should be allowed to sever ties with people who say mean things" is different from saying, "the courts will decide whether or not you committed libel"?

> For example, no competent court is going to allow anyone to use an escape clause to terminate a contract with someone because of their race, age, or gender.

Do you think there's a difference between a court saying, "we're not going to allow you to sever a business relationship because of a protected characteristic", and "we're going to regulate what does and doesn't count as disparagement"?

Can you point me at an example of a business fighting a disparagement clause in a contract with language like this and winning, based on a court deciding that what they said didn't count as disparagement?

This is like the people who say they're going to sue Facebook for taking down posts because their definition of "misleading information" isn't specific enough. You can sue anyone for anything, but you're not going to win that case. Companies with contract language like this have broad leverage to wield their power in whatever way they see fit -- because for the most part courts have not ruled that escape clauses boiling down to "we can decide to ban you at any time for any reason" are illegal or unenforceable.

Re: Face ID and Touch ID for the Web

#174

This comes 3 days after a leak that alleged that iPhone 13 will bring back Touch ID via in-screen fingerprinting https://www.techradar.com/uk/news/move-over-iphone-12-apples...

Hasn't this been leaked for like the past 3 years?

Yes, this has been a perennial rumor which is probably propagated by how much people don't like Face ID all that much. Face ID is fine when it works, and sucks when it doesn't. And mask wearing has really accelerated it being much worse, and we'll be wearing masks as a standard piece of dress for another two years I guess.

I do miss Touch ID, but that had its own problems (gloves, wet fingers). So one would hope there is a solution that has both. I'd personally be just peachy with a fingerprint sensor on the back just like the Pixel line used to have. I mean, how much is a fingerprint sensor manufacturing cost? $5?

Re: Face ID and Touch ID for the Web

#175
post #137

Earlier quoted context omitted.

> Since I have zero need to deliberately violate Apple's App Story policy, I don't worry about this overmuch. That may be true today, but their policies are a moving target. Who knows what they'll be like in a year's time?

You could say that about anything -- nothing is completely static -- but it's worth mentioning that Apple vs. Epic is a counterexample; Epic wants apple to change their policies (lower than 30% cut) while Apple wants to maintain the same structure since the inception of their app store.

> You could say that about anything -- nothing is completely static

1. Contracts are a thing. You can draft a contract with your vendor that guarantees certain terms for a certain duration.

2. You should be wary of wandering into commitments (including de facto commitments e.g. "vendor lock-in")--there are plenty of good reasons to do so, but one should make sure to properly consider the cost.

The problem is that doing business with Apple can make or break a company--companies can scarcely afford not to do business with Apple. I'm not an economist, but this seems pretty monopolistic (which isn't to say Apple should be broken up, but perhaps more tightly regulated).

Re: Face ID and Touch ID for the Web

#176
post #136

Earlier quoted context omitted.

I've had an issue with sign-in with Apple where using an autogenerated emails ruins certain support interactions. One of them was cancelling a subscription service that was eventually resolved (they required me to email their customer support, which I couldn't figure out how to do using the autogenerated email address created by "sign-in with Apple").

While it’s frustrating and worth pointing out of course - what really happened there was a bug in the service provider’s support process!

It was actually a dark pattern, not a bug.

Re: Face ID and Touch ID for the Web

#177
post #33

Earlier quoted context omitted.

"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)

For what it's worth, it's been said (by anonymous sources, no one on the record) that Apple did not threaten to terminate Epic's "Sign in with Apple" accounts/features, and they spent extra effort to maintain their access to that after their account was terminated. I do not know if other terminated accounts get this "luxury".

Epic did say it was going to be terminated, presumably as part of the overall account termination. They then updated that it would continue to work.

https://www.theverge.com/2020/9/10/21431396/epic-sign-in-wit...

Apple commented they weren’t doing anything to stop Sign In with Apple working, but I have to wonder if there’s a lie of omission in there. Like “We aren’t doing anything deliberate to stop it, but it’s going to stop as a side effect of terminating their developer account.”

Either that or Epic was lying outright.

Re: Face ID and Touch ID for the Web

#178
post #71
post #50

Earlier quoted context omitted.

> I would definitely stay away from any "Sign in with Apple". I would stay away from any "Sign in with.." service as a user and as a product owner. You're affectively giving away a major control of your users to a third party.

As a product owner, why wouldn't I want to piggyback on the millions of dollars of R&D + security that the big companies have put in? And as a user, why would I trust my password to the website that rolled their own authentication over the big companies?

[deleted]

Re: Face ID and Touch ID for the Web

#179
post #148
post #106

Earlier quoted context omitted.

The fingerprint sensor found on most phones doesn't always require intent, either.

Interestingly, touch ID launched 1 year after Apple refused to unlock an iPhone for the FBI.

Did you mean FaceID? The iPhone 5c in the San Bernardino shooter case was released at the same time as the iPhone 5s, which introduced TouchID.

Re: Face ID and Touch ID for the Web

#180
Does anyone know why Webauth does not support a message associated with the authentication? Shouldn't the user be informed in a secure way what they are authenticating for? Currently only site and user name are supported to be shown to the user. For payments (PSD2 for instance) it is a requirement to also provide information about the transaction for instance.
Post reply on HN