Live data from Hacker News

Apple unveils 'Passwords' manager app at WWDC 2024

zdnet.com

471–480 of 767 posts

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#471

Earlier quoted context omitted.

I think you might be making some assumptions about how this stuff works without looking into it. - A lot (most?) people’s Apple Account name is actually their main email address (e.g. Gmail), so they would still control their email address even if their Apple Account was compromised. - You can still recover your Apple Account and iCloud Keychain without any devices (e.g. if phone broke like in your scenario). - Your…

> - A lot (most?) people’s Apple Account name is actually their main email address (e.g. Gmail), so they would still control their email address even if their Apple Account was compromised. But the login for the Gmail address is a passkey that's on the Apple account... > - You can still recover your Apple Account and iCloud Keychain without any devices (e.g. if phone broke like in your scenario). So what's the point…

> But the login for the Gmail address is a passkey that's on the Apple account...

A passkey is just a replacement for a password. Google (and other apps/websites) have account recovery processes for users who get locked out of their accounts. The way you get back into your Google account doesn’t change much just because you’re signing in with a passkey vs. a password.

Account recovery is a problem that service providers have to solve (and do solve) regardless of whether a user authenticates to their account with a password or a passkey.

> So what's the point of passkeys if you can get access to them without passkeys?

Some huge benefits are:

1. They are highly phishing resistant. Unlike passwords and popular forms of 2FA (TOTP and SMS), users can’t be tricked into sending their credential to a fake/malicious server. A passkey is bound to the server domain at the time the credential is created, and your OS/browser will simply not send it to the wrong place.

2. There is no credential for attackers to steal from servers in the case of server breach. This is because only a public key is stored on the server, instead of password hashes (or worse, plaintext, if the app/website developers don’t know what they’re doing).

3. Passkeys are guaranteed to be unique and secure. The same cannot be said for passwords. Even a password manager cannot guarantee that every single credential stored in the password manager is both unique and secure. And password complexity requirements often make it a painful game of trial and error to create a secure password, even when using a password manager.

4. Because of annoying password complexity requirements, the process of creating a new password can be annoying and take up to a minute or two of fiddling around, even when using a password manager. With a passkey, the process takes as long as Face ID or Touch ID (or equivalent on other platforms) every time. Every single credential creation and authentication is a fantastic user experience (both fast and easy).

I suggest watching Apple’s WWDC videos. There you will find a very very in-depth answer to this question.

All of the points I’ve made above (and more) are covered in the linked videos.

Move beyond passwords: https://developer.apple.com/videos/play/wwdc2021/10106/

Meet passkeys: https://developer.apple.com/videos/play/wwdc2022/10092/

Deploy passkeys at work: https://developer.apple.com/videos/play/wwdc2023/10263/

If you won’t watch any of the above then you should at least read the FAQ on passkeys on the FIDO website here, which should answer many of your questions:

https://fidoalliance.org/faqs/#PasskeysFAQs

> How can something be protected when the thing that controls access to it has been compromised?

This is answered in the article I already linked above. Here is the link again.

About the security of passkeys: https://support.apple.com/en-us/102195

Specifically, carefully read the following sections titled “Synchronization security” and “Recovery security”. The short answer is that gaining access to the user’s iCloud Keychain contents requires more than just having access to the Apple Account.

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#472

Earlier quoted context omitted.

But have you thought to ask why that is? The general mechanism for free software to be developed is for the individual users to make modifications. Not all of them, of course, but the ones who know how to. Someone sees something wrong, fixes it. Apple interferes with this. If you don't like an app on your iPhone, even if it's open source, you can't just make a minor change because for that you have to pay $100/year a…

Not sure of your reality, but my apple ecosystem just works . I spend nearly zero time fiddling with my rig just to get to a point of productivity but see Linux using peers in a constant state of tweaking trying to achieve and failing of what I have by just opening a box.

Same. The only issues I ever have are with non-Apple hardware, like Sony headphones, Acer monitor, etc.

Do I wish they worked better? Of course. Have I experienced those same problems with Android / PC? No, but different problems existed.

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#473
My brother convinced me to try a 1Password family account, since it would be cheaper. Ever since, the Chrome plugin takes forever to login. Sometimes up to 5-6 seconds. And it really annoys me that they have so many resources and money, and it's still this expensive for a very very basic application, and slow to boot.

I tried out passwords, and combined with Safari, it's an absolute godsend compared to 1Password. That does mean that I switched from Brave to Safari, and thus have YouTube ads, and so I'm now paying for YouTube haha

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#474
post #473

My brother convinced me to try a 1Password family account, since it would be cheaper. Ever since, the Chrome plugin takes forever to login. Sometimes up to 5-6 seconds. And it really annoys me that they have so many resources and money, and it's still this expensive for a very very basic application, and slow to boot. I tried out passwords, and combined with Safari, it's an absolute godsend compared to 1Password. Tha…

Just to rub it in your face :) (teasingly and with respect) I got Android/LastPass/Firefox and only pay for the LastPass annually (I got it on all my devices), so there you have it ;)

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#476
post #168

Here's Apple's big problem: it's not a replacement for so many alternatives because it isn't supported on all platforms. Safari? Not on Windows. Apple Music? This actually has a Windows client. I'm not sure how good it is. But Spotify supports Windows and even Linux. Apple Password Manager? Will this be tied to iCloud? Will I be able to use it on Android? If I no longer have an iPhone will it be a pain to maintain an…

>> People don't want everything tied to one identity, one service, one login. I think this is exactly what _most_ people want. With password management specifically, Apple has had a Chrome extension available for a while now which has allowed me to use it on other browsers/platforms. Not ideal, but good enough for most. On top of that, they don't lock you in with passwords. You can easily import and export your passw…

> I think this is exactly what _most_ people want.

I see many comments replying to the above statement, and I am no exception.. what about the saying that goes: "Don't put all your eggs in one basket"?

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#477

Earlier quoted context omitted.

I have yet to notice a site asking me a passkey.

I've found them to be a real pain in the arse because they're implemented so inconsistently. Only the biggest sites are offering them, but it's those big sites where I'm worried about locking myself out because of setting it up wrong.

I've locked myself out of Squarespace by setting up then subsequently removing a passkey. Doing so triggered a bug which "updated" the TOTP (that was already set up) and the backup codes. Support was absolutely deaf to the whole thing being a bug, absolutely impossible to report, and I'm sure it'll keep being an issue for years to come.

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#478
post #127

I've been an avid 1Password user for over 10 years, but since they gone full-throttle targeting the enterprise market, I'm getting more and more annoyed. It's increasingly buggy (right now, it thinks I haven't migrated from 1p7 which causes annoying interstitials that I can't close. Over a month and no fix yet.). They killed standalone vaults. Obvious feature requests (e.g archive an entire vault) sit there for years…

I suspect you won't be satisfied with Apple's offering if you enjoy stable software, unfortunately. I agree regarding 1pass, but at least it's still firmly trying to solve the password management problem. Apple is trying to solve the vendor lock-in problem (i.e. how can they lock more users in to their platform).

My last password manager got sold to some guy in Morocco and my passwords put behind a pay wall, and then lost. Bring on the vendor lock in, I’m so done with all that other shit.

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#479
post #342
post #311

Earlier quoted context omitted.

Windows app will certainly help adoption. An Android app would be nice as well, but I doubt that many people use both iOS and Android devices[1] (or concern themselves whether they will be able to switch platforms easily). [1] Android devices as in devices where password manager is desired, not as in 3 Billion Devices Run Java

I wonder what the number of people who use Macs and Android is. I would guess that it’s a tiny fraction of the marketplace (and likely entirely populated by people with Kindle Fires, not Android phones).

Actually now I'm thinking that there are probably quite a few developers with Macs + Android phones.

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#480

Earlier quoted context omitted.

>> People don't want everything tied to one identity, one service, one login. I think this is exactly what _most_ people want. With password management specifically, Apple has had a Chrome extension available for a while now which has allowed me to use it on other browsers/platforms. Not ideal, but good enough for most. On top of that, they don't lock you in with passwords. You can easily import and export your passw…

> I think this is exactly what _most_ people want. I see many comments replying to the above statement, and I am no exception.. what about the saying that goes: "Don't put all your eggs in one basket"?

> what about the saying that goes: "Don't put all your eggs in one basket"?

I think it's a lot more important to decide who you want to trust.

The problem is that there are a lot of small apps that end up being scams. Or they end up selling their software to scammers. Or they just don't have the ability to properly secure their system (LastPass).

Apple has kind of made a name for themselves as a big company that cares about privacy and is serious about security. And they don't have the reputation for totally screwing over their customers randomly like Google.

I can see a lot of people making the pragmatic decision to just keep trusting Apple instead of figuring out which other company to trust as well.

Post reply on HN