1Password users can already have effectively the same experience.
This is making a friendly version of Yubikeys (using Apple devices) and password vaults for Apple users.
21–30 of 274 posts
1Password users can already have effectively the same experience.
This is making a friendly version of Yubikeys (using Apple devices) and password vaults for Apple users.
1Password users can already have effectively the same experience.
Apple users will get this natively without having to acquire 1Password. If you’ve bought into the Apple ecosystem and don’t have needs outside of it (Windows, Linux), you can eliminate the need for a separate password manager. Similar to how iCloud Files is moving towards (but likely won’t meet, while not needing to) Dropbox parity. This is making a friendly version of Yubikeys (using Apple devices) and password vaul…
This isn't that revolutionary: LastPass already allows you to use biometric ID to authenticate and it works without any changes to the website.
Biometric data must always stay on your personal device in order to be secure from replay attacks, not to mention finding out more about you.
https://amp.theguardian.com/world/2019/sep/04/smile-to-pay-c...
Of course, in Apple’s implementation, the data never leaves the device. Which is far better than, say, how facial recognition is used in China for payment where the merchant is the one operating the machine which scans your face.
Earlier quoted context omitted.
Apple users will get this natively without having to acquire 1Password. If you’ve bought into the Apple ecosystem and don’t have needs outside of it (Windows, Linux), you can eliminate the need for a separate password manager. Similar to how iCloud Files is moving towards (but likely won’t meet, while not needing to) Dropbox parity. This is making a friendly version of Yubikeys (using Apple devices) and password vaul…
so one more instance of Apple effectively rendering a third party app useless. As an apple user, I love that I do not need to install an additional app but something does not feel right from an ethical standpoint. Or maybe I'm just being too touchy.
Competition and a free market has perils. May the best solution win.
Giving my finger and face prints to the browser, the software with the biggest attack surface in the world, connected to internet no less, feels off to me.
Giving my finger and face prints to the browser, the software with the biggest attack surface in the world, connected to internet no less, feels off to me.
Giving my finger and face prints to the browser, the software with the biggest attack surface in the world, connected to internet no less, feels off to me.
This isn't that revolutionary: LastPass already allows you to use biometric ID to authenticate and it works without any changes to the website.
Password managers do make it more difficult to get phished, since they will not know what password to autofill on phishing.example.com... but on the other hand, password manager users are used to having to force-fill a password. I have to take my password out of LastPass to log into Battle.net or Fusion 360, and websites like the Wall Street Journal create your account on dowjones.com but require you to log in on wsj.com (or maybe it's the opposite, I forget).
With WebAuthn, more care is required for both the site operator and the user (have more than one way of logging in in case you lose your phone, make sure the enrollment and login origins are the same), but you are then open to fewer attacks.