Live data from Hacker News

Face ID and Touch ID for the Web

webkit.org

211–220 of 371 posts

Re: Face ID and Touch ID for the Web

#211

Earlier quoted context omitted.

Epic did say it was going to be terminated, presumably as part of the overall account termination. They then updated that it would continue to work. https://www.theverge.com/2020/9/10/21431396/epic-sign-in-wit... Apple commented they weren’t doing anything to stop Sign In with Apple working, but I have to wonder if there’s a lie of omission in there. Like “We aren’t doing anything deliberate to stop it, but it’s goin…

unnamed sources have said that Epic was outright lying https://daringfireball.net/linked/2020/09/29/epic-games-unre... > multiple sources at Apple told me Epic’s claims were simply false. There was never a September 11 deadline for their SIWA support to stop working, and in fact, Apple’s SIWA team performed work to make sure SIWA continued working for Fortnite users despite the fact that Epic Games’s developer accoun…

So the other question, is this a standard behavior, or a special circumstance because of Epic's high profile?

Or more to the point, if Apple terminates your developer account, do you think Apple's SIWA team will "perform work to make sure SIWA continues working" for your users?

If work is actually required, I'm not optimistic.

Re: Face ID and Touch ID for the Web

#212
post #201

Earlier quoted context omitted.

I am still waiting for them to move to USB-C

> I am still waiting for them to move to USB-C What do you mean? All Mac models introduced since 2016 support USB-C. https://support.apple.com/en-us/HT201736

Not OC, but they probably mean iPhones. I wish iPhones would switch to USB-C too; my iPhone is now the only device I own that isn't USB-C.

Re: Face ID and Touch ID for the Web

#213

Earlier quoted context omitted.

Sure works when you have only one computer in your life (aka almost nobody). It’s especially bad with Apple with 3 different usb standards. Contactless is the future.

What's stopping you from linking more than just one physical FIDO-enabled device to a particular site/service? Most MFA implementations I've seen already allow this, and it seems especially important if you want to minimize the pain of losing/damaging that one sacred card.

I don't carry any keys so those massive dongles would be pain. Plus must is not ALL which breaks everything.

Re: Face ID and Touch ID for the Web

#214
post #101

Earlier quoted context omitted.

Biometric data is never leaked because it never leaves the secure enclave in the device.

Your face can easily be mimicked. Biometric data is not stored in the phone, it is stored in you. See: https://www.macrumors.com/2018/12/16/3d-printed-head-android...

> The final model took a few days to generate at the cost of just over £300. "easily"

Re: Face ID and Touch ID for the Web

#215
post #101
post #77

You can change a password but you can't change your fingerprint / palm / etc. Am I missing something? How is Face / Touch ID more secure that user + pass? What happens when biometric data is leaked?

Biometric data is never leaked because it never leaves the secure enclave in the device.

Biometric data is leaked whenever you touch a doorknob.

Re: Face ID and Touch ID for the Web

#216
Any bullying or power abuse situation may easily exploit biometric authentication against the victim. Kids bullying other kids, domestic abuse, authorities etc.

Now, if biometric authentication becomes the norm, how will a wife suffering domestic abuse justify using a password?

Re: Face ID and Touch ID for the Web

#217

Earlier quoted context omitted.

I really hate the "we're going to send a code to your email" approach because it so often breaks. Case in point, I tried to log into Patreon earlier today, they insisted on sending a code, and it never arrived. I tried several times, no email. I have a record of every email sent to my address for the past several years regardless of spam status so I can be 100% positive they simply never sent it. In the end I had to…

I'm curious -- do you host your own email, or use a lesser-known email provider? I am increasingly seeing failures where sites seem to be blackholing outgoing email, I suspect based on the destination domain, and unaware that they are even doing this / extremely insistent that they are not. I've gotten login-email failures like you describe from a couple of sites, and seemingly similar failures from those "email your…

I have a custom domain that uses Gmail as its mail provider (for legacy reasons related to the other users of this domain), and my Gmail account is configured to never mark anything as spam and to forward everything to Fastmail. This means that no matter what I do with my email, I can log into the gmail account and see every email I've received for years sitting in my inbox.

I don't really recommend this setup, I'd really prefer to cut Google out of the path entirely, but I can't do that without abandoning my email address.

Re: Face ID and Touch ID for the Web

#218
post #134

Earlier quoted context omitted.

It doesn't matter since your fingerprint isn't secret. It's not enough to have a picture of my fingerprint, you have to produce a convincing enough fake of a real human with the right fingerprint. Take this to meatspace for a second. If you had a security guard sitting at a desk inspecting your hands and taking fingerprints you couldn't trick them with pictures. You can't hold up a picture of my face to a guard and e…

Let's suppose biometrics can be made nearly foolproof. Then somebody goes to all the effort to duplicate one. What then? Suicide I guess.

Let's suppose someone goes to all the effort to duplicate your biometrics in a real world scenario (e.g., going to the DMV). They put on their mask and their fake fingerprint and get a new driver license with your name and picture. Then they open bank accounts with it, get loans, and buy cars. What then? Suicide I guess.

Re: Face ID and Touch ID for the Web

#219

Any bullying or power abuse situation may easily exploit biometric authentication against the victim. Kids bullying other kids, domestic abuse, authorities etc. Now, if biometric authentication becomes the norm, how will a wife suffering domestic abuse justify using a password?

I agree with you, but am not sure a password works too well in such situations either - the abuser would presumably just beat the victim until they enter their password?

Re: Face ID and Touch ID for the Web

#220

Earlier quoted context omitted.

It isn’t productive to establish defense against an arbitrary future that turns on you. Spend those brain cycles focusing on your user and building a great product. Choosing Sign in with Apple is great for Apple users.

Maybe so. But how is this different than saying, "I have nothing to hide, so I'm not worried about having my car searched?" It's a somewhat pragmatic point of view but I wonder if it is a good idea in the limit.

"I have nothing to hide, so I'm not worried about having my car seized"
Post reply on HN