Live data from Hacker News

Apple passwords deserve an app

cabel.com

201–210 of 414 posts

Re: Apple passwords deserve an app

#201
post #154

I have been using the Apple manager since LastPass got hacked recently. Hot take , but … I like the lack of integration in other operating systems/ browsers. I see my phone as a Secure Enclave, and my passwords should be disconnected from potentially insecure systems. I see the phone as those keychain one time passwords where you have to press a physical button to get a key. Is it inconvenient to get a password, yes.…

This was precisely what drove me off Apple password manager. If your iPhone were compromised, such as in those iPhone unlocking scams[1] (something quite common here in Brazil at least since 2021), it's game over for your entire password database. I've been using KeePass apps (MacPass on macOS, KeePassium no iOS), with a different, unique master password, unlogged by default on iPhone, plus DB locks automatically aft…

Absolutely. Given these reports, Apple's security model isn't close to being sophisticated enough to warrant trusting them with passwords or (even more critically, arguably) WebAuthN passkeys.

I recently saw it with my own eyes as a family member was able to reset their iCloud password and gain full access to their account on a new device, including iCloud Keychain, using nothing but their iPad and the corresponding unlocking code. No iCloud password, no SMS-2FA (not that it would help much in the case of a stolen iPhone), nothing else.

Re: Apple passwords deserve an app

#202
This is unnecessary because it's a problem that's already solved.

- BitWarden - for personal use, stores 2FAs and acts as an iOS password source. (The claimed attacks were mitigated)

- Keeper - for enterprise use, stores 2FAs and acts as an iOS password source

- Duo - for 2FA for enterprise use with backup text mechanisms. Edit: Duo's primary app mechanism is similar to Google Gmail app's mechanism of a yes/no popup to approve a 2FA request

^ The above are cross-platform and extend beyond Apple.

Re: Apple passwords deserve an app

#203

Earlier quoted context omitted.

I hope not. I'm patiently waiting on 1Password to release their implementation of passkeys so I can have it work on all my devices, Apple or not.

Just use Passkeys. Any account that allows 2FA allows multiple second factors. You should be setting up backup second factors anyway if you don't want to risk getting permanently locked out of all of your accounts. Plus, putting second factors in the same location as your first factor (e.g., 1Password) seems to pretty much defeat the entire purpose of having a second factor. If you're using strong passwords with 1Pas…

Isn’t the whole point of Passkeys that you can’t ever lose them, since they’re tied to your biometrics..

Re: Apple passwords deserve an app

#204

I follow Ricky Mondello, who works on the Apple password keeper functionality — they post interesting tidbits pretty regularly. https://twitter.com/rmondello https://hachyderm.io/@rmondello

That iOS supports multiple password sources from other apps already largely solves the case of using a cross-platform app to provide or store passwords.

Re: Apple passwords deserve an app

#205

Earlier quoted context omitted.

I believe Apple only lets you use certain APIs (like Keychain) if you distribute only through the App Store. That policy has really killed a lot of functionality on macOS. I suspect it will cause fiction on iOS when the EU forces them to allow alternative install sources. Personally, it grates me when Apple cripples functionality this way to try to keep us stuck in their platform. Can't use Firefox with Keychain. You…

Is there a reason Chrome, Edge, and Firefox aren't on the Mac app store? I know the yearly dev account costs can be an issue for small developers but Google, Microsoft, and Mozilla are already paying that as they release apps on the iOS App Store.

If I had to guess, the review process would just be a hindrance to them for nearly no benefit (is there anything besides the keychain API that would entice them?).

Re: Apple passwords deserve an app

#206

Earlier quoted context omitted.

I hope not. I'm patiently waiting on 1Password to release their implementation of passkeys so I can have it work on all my devices, Apple or not.

Just use Passkeys. Any account that allows 2FA allows multiple second factors. You should be setting up backup second factors anyway if you don't want to risk getting permanently locked out of all of your accounts. Plus, putting second factors in the same location as your first factor (e.g., 1Password) seems to pretty much defeat the entire purpose of having a second factor. If you're using strong passwords with 1Pas…

> Plus, putting second factors in the same location as your first factor (e.g., 1Password) seems to pretty much defeat the entire purpose of having a second factor.

Not quite! 1password itself counts as two factors: something you know (the master password), and something you have (the additional secret key).

Passkeys in 1password would eliminate phishing as a problem.

Re: Apple passwords deserve an app

#207
I've been using Keychain since 2003. Only now am I aware that it does TOTP. I've been avoiding TOTP like the plague this whole time because I don't trust the other apps not to somehow get me locked out.

Re: Apple passwords deserve an app

#208

Earlier quoted context omitted.

Apple had (has?) Cocoa ported on Windows actually, so whatever they could so on macOS, they could do on Windows as well. Cocoa as such is cross-platform.

Any link to the port of Cooca to Windows?

Looking at the Apple Music app for Windows quickly, it does appear Apple has done some porting of their APIs to Windows.

https://i.imgur.com/tdr6XTO.png

Re: Apple passwords deserve an app

#209
post #201
post #154

Earlier quoted context omitted.

This was precisely what drove me off Apple password manager. If your iPhone were compromised, such as in those iPhone unlocking scams[1] (something quite common here in Brazil at least since 2021), it's game over for your entire password database. I've been using KeePass apps (MacPass on macOS, KeePassium no iOS), with a different, unique master password, unlogged by default on iPhone, plus DB locks automatically aft…

Absolutely. Given these reports, Apple's security model isn't close to being sophisticated enough to warrant trusting them with passwords or (even more critically, arguably) WebAuthN passkeys. I recently saw it with my own eyes as a family member was able to reset their iCloud password and gain full access to their account on a new device, including iCloud Keychain, using nothing but their iPad and the corresponding…

Can you explain how this hack would work ?

Would someone need to steal two of your devices ?

I was under the assumption that you need to be logged in with touchid/faceid/pin code to get the unlock code

Re: Apple passwords deserve an app

#210

Earlier quoted context omitted.

> 1. The experience on Windows is terrible. They can claim it's cross-platform but it's truly a sub-par product. Like a lot of other Apple stuff, I'm only able to use it because I don't use anything non-Apple for anything "serious" that involves a GUI. Windows is for gaming, Linux is my file storage and docker-service-running server that I only interact with over SSH and Web. Ditto Notes, all their Office-type progra…

> Yeah, this is super fucking weird. You'd think this would be connected in some fashion to "keychain", but nope. Other browsers used to be able to use it. I do think it’s a really thorny issue—“allow this application to access all saved passwords?” is a pretty damn scary permission to include. Up there with the “allow this application to control your computer” permission that is used for accessibility apps (which ap…

Something could pop up saying "Fill password for HSBC Bank?" or similar and you click one button.
Post reply on HN