Live data from Hacker News

Apple Passkey

developer.apple.com

401–410 of 421 posts

Re: Apple Passkey

#401
post #314

Earlier quoted context omitted.

I expect people to do their best, within their capabilities. Nana and Papa are not technologically literate enough to perform the kinds of configurations you suggest. In depth custom password manager configuration isn't for them. They are not at fault for that. We simply cannot expect all of humanity to be that technologically literate. There are many, many roles in life that don't involve electronic devices that are…

My view is best stated that I think people are more capable than they think they are. And I'm unsure people even attempt a try at most things. Maybe that's a negative view but I feel that's what I've observed. I don't worry too much because most of the most important entities, such as say Social Security in the US forces 2FA on users. I just signed up on that site the other day, and they simply force you to do everyt…

My issue is that I've seen people attempt to do these things. And fail miserably.

One project I've worked on, something like 5-10 out of every 200 people successfully misspelt their own name in text forms.

Non-professionals create human error. The more details the non-professional has to configure, the higher the percentage of human errors across your userbase.

The issue is, in device security, human error is not acceptable.

Re: Apple Passkey

#403

I don't get what it's all about this passwordless. I make my browser (Firefox) generate strong password and store them in its password manager, this is synchronized with end to end encryption to all my devices, I have only to remember a master password. It's kind of the same but it works with every website. It is not complicated, doesn't require certificates that you may loose, and that sort of things.

How does apple get your data that way?

Re: Apple Passkey

#404
post #357
post #263

Earlier quoted context omitted.

There's nothing to backup/import. If you have an iPhone, you use your fingerprint or Face ID. If you sell your iPhone and buy an Android, you use your fingerprint or face recognition on that device.

That's not how it works. If you lose your only iPhone, you lose the keys. Using your face is different device does not get you access to your old keys.

> If you lose your only iPhone, you lose the keys.

But they're in your iCloud Keychain. You should just log in to iCloud and have them again.

Re: Apple Passkey

#405
post #357

Earlier quoted context omitted.

That's not how it works. If you lose your only iPhone, you lose the keys. Using your face is different device does not get you access to your old keys.

> If you lose your only iPhone, you lose the keys. But they're in your iCloud Keychain. You should just log in to iCloud and have them again.

"just log in"?

How you do that after you use Apple Passkey and lose your phone? (and SIM)

Re: Apple Passkey

#406

Earlier quoted context omitted.

Your choice is to allow people to be phished for credentials, then. Gullible people will cheerfully complete any attacker-described PC syncing process, ignoring every security warning presented to them, in order to give away the keys to their accounts. They’ll use a friend’s PC, or a library PC, or anything under the sun, if the phished promises to give them something for nothing.

Apple is already remotely backing up passkeys off-device . We are having a debate about an Apple policy that doesn't exist. Apple is not following the "keys never leave your device" model, so that security model has nothing to do with whether or not Apple will engage in vendor lock-in. We're not making the choice to leave users vulnerable to phishing attacks, Apple made that choice , and we're arguing that because th…

As far as I know, Apple requires iCloud password and PIN entry on an Apple hardware device being paired to iCloud to access Keychain data, and tends to block Apple devices by hardware ID when they’re associated with bulk login attacks. The attacker surface for phishers is exorbitantly expensive, since they’d need to have a shipping container full of iPhones to even begin harvesting credentials, assuming that they could convince users to turn over their iCloud password (which half of my friends don’t even know).

This is how vendor lock-in allows protections against phishing that a naive data export would bypass. No one has yet suggested how this level of protection can be offered to end users without lock-in, across many such posts and threads, for many years now. I remain hopeful that there’s another way, but I’m not going to demand Apple do insecure exports at the expense of users in the meantime.

Re: Apple Passkey

#407

Does anyone know how this/FIDO/Webauthn affect privacy? How well supported are alt accounts? Are they easy to tell they're from the same signer? I figure privacy is fine as long as the implementations allow you to select which account to login with. Is this currently a thing? From everything I read it seems like the current implementations are only meant to support one identity? EDIT: These are great responses, also…

FIDO2 resident keys (the thing people are now calling passkeys) allow for multiple credentials for a single site. If you have a device that supports resident keys you can try this for yourself on https://webauthn.io . There is also no way for a site to know if two sets of credentials belong to the same physical hardware device or not. Sites can request the attestation certificate, but that is not unique per device (t…

Got "failed to register" on your website on my phone after doing the os level fingerprint auth

Re: Apple Passkey

#408
post #321

Earlier quoted context omitted.

Password managers are already pretty easy to use from a nana's perspective. The main problem is that nana does not know that password managers exit itself. Most of them just input password as 'nana1234' and store it in their browser password manager (usually chrome password manager) and use chrome's autofill. Eg., I was telling a middle aged person (50 years) about password managers and were unable to grasp the idea…

> I was telling a middle aged person (50 years) about password managers and were unable to grasp the idea of it. This is more than a little ageist, don’t you think? > Why would you store passwords in cloud based password manager from a company I have never heard of? This is actually a very valid question; hope you didn’t just dismiss it due to “the oldie doesn’t understand.”

>This is more than a little ageist, don’t you think?

It was not meant in that way, same thing could be said about 20 year old, who have no idea (or unable to grasp) about password manager but more importantly about Authenticator Apps (Micorosft Authenticator, Authy, Aegis).

>This is actually a very valid question; hope you didn’t just dismiss it due to “the oldie doesn’t understand.”

You are reading my comment from a wrong angle.

Re: Apple Passkey

#409
post #405

Earlier quoted context omitted.

> If you lose your only iPhone, you lose the keys. But they're in your iCloud Keychain. You should just log in to iCloud and have them again.

"just log in"? How you do that after you use Apple Passkey and lose your phone? (and SIM)

Because your iCloud Keychain has nothing to do with your SIM card.

https://support.apple.com/guide/security/secure-icloud-keych...

Re: Apple Passkey

#410
post #405

Earlier quoted context omitted.

"just log in"? How you do that after you use Apple Passkey and lose your phone? (and SIM)

Because your iCloud Keychain has nothing to do with your SIM card. https://support.apple.com/guide/security/secure-icloud-keych...

I know it does not. It's in the Cloud. I was referring to SIM and phone number when I was thinking potential way to recover.

Can you explain how a person can login into their iCloud and recover their iCloud Keychain after they have lost their only Apple device (iPhone) if Apple Passkey needed to access iCloud?

Post reply on HN