Earlier quoted context omitted.
The way Google's password manager covers websites anywhere I'm logged into Chrome plus native Android apps anywhere I'm logged into Google Play is super convenient though (albeit total lock-in, I won't argue that). Some apps are even developed well enough that a password originally stored via Chrome will be suggested for the app, I guess by cross-referencing the origins in some mutual way. And payment card details wi…
The security positive of a browser integration is you eliminate the human part of url validation; effectively stopping phishing.
Apple unveils 'Passwords' manager app at WWDC 2024
701–710 of 767 posts
Re: Apple unveils 'Passwords' manager app at WWDC 2024
#702Earlier quoted context omitted.
About using it for storing keys of other shell scripts/commands: What kind of special functionality this would require? Would you like to, for example, use passlane to extract the password of some script and then pipe it to that script? Perhaps adding that kind of functionality would make sense.
Well say I have U&P or API keys for some network service and I have a little shell script that automates it. I can save the auth info in the script or in a ~/.keys/ file or something and the file system permissions are all that's protecting them. If my script could retrieve a password from my KeePass DB if it's unlocked, or ask me to unlock it, that would be cool.
Re: Apple unveils 'Passwords' manager app at WWDC 2024
#703Earlier quoted context omitted.
keepassxc works for me on android, windows, and mac
keepassxc is incredible, truly slept on. I use safari keychain as well, as a copy. But my master store is keepass. It boggles my mind that people pay for 1password. Btw, is keepassxc on Android now or are you referring to one of the many Android keepass apps? I use keepassium on iOS. I pay for protonmail and also store a copy in protonpass. Proton pass has a nice web interface and doesn’t require me to copy a keepass…
Re: Apple unveils 'Passwords' manager app at WWDC 2024
#704If anything 1password has proved to me that an Electron application can eventually be pretty seamless. I have been very impressed in MacOS and Firefox.
Re: Apple unveils 'Passwords' manager app at WWDC 2024
#705Earlier quoted context omitted.
> But the login for the Gmail address is a passkey that's on the Apple account... A passkey is just a replacement for a password. Google (and other apps/websites) have account recovery processes for users who get locked out of their accounts. The way you get back into your Google account doesn’t change much just because you’re signing in with a passkey vs. a password. Account recovery is a problem that service provid…
Ok so let's assume passkeys are a form of saved generated password. > 1. They are highly phishing resistant. Unlike passwords and popular forms of 2FA (TOTP and SMS), users can’t be tricked into sending their credential to a fake/malicious server. A passkey is bound to the server domain at the time the credential is created, and your OS/browser will simply not send it to the wrong place. So why does my browser or pas…
Any kind of authentication method that relies on a string that can possibly be manually typed into a box by an end-user can never be made to be highly resistant to phishing.
> What has stopped developers from using irreversible transformations on stored passwords in the past? The math was there.
I don’t understand what point you’re making here. Are you saying “why didn’t people create a different standard than WebAuthn?” or are you saying “strong password hashing methods exist, so why do so many websites use bad ones”? Or are you saying something else?
> You become dependent on an easily stolen or destroyed device for authentication.
No, you don’t, because passkeys on Apple platforms are stored in iCloud Keychain, which syncs across all your devices with end-to-end encryption. They’re not solely on your phone.
> It is a fantastic user experience until you're a plane flight away from home, your phone gets stolen. Your passkeys are safe in the secure enclave.
They are stored in iCloud Keychain, not the Secure Enclave. And you can recover access to your iCloud Keychain is even if you lose your phone, and even if you lose all of your devices.
> The flight options are in an app that you don't have the passkeys any more for.
You could just go through the account recovery flow for the airline app to regain access to your account. Whether you use a password or a passkey as your primary credential for logging in has very little to do with account recovery logging into an airline app. The app needs to continue to handle users who get locked out of their airline account for a variety of reasons.
Re: Apple unveils 'Passwords' manager app at WWDC 2024
#706Earlier quoted context omitted.
keepassxc is incredible, truly slept on. I use safari keychain as well, as a copy. But my master store is keepass. It boggles my mind that people pay for 1password. Btw, is keepassxc on Android now or are you referring to one of the many Android keepass apps? I use keepassium on iOS. I pay for protonmail and also store a copy in protonpass. Proton pass has a nice web interface and doesn’t require me to copy a keepass…
Keepassxc has zero collaborative features and no online sync. I’m a big fan of keepassxc but these reasons are why I pay for 1P. I can add colleagues, guests, family members and have it run on all my devices.
KeepassXC does have collaborative features and online sync if you just drop the Keepass file in a shared cloud - I use it this way and it's easy to set up. Also, more importantly, the password database is not stored in some server God knows where.
Re: Apple unveils 'Passwords' manager app at WWDC 2024
#707Earlier quoted context omitted.
keepassxc is incredible, truly slept on. I use safari keychain as well, as a copy. But my master store is keepass. It boggles my mind that people pay for 1password. Btw, is keepassxc on Android now or are you referring to one of the many Android keepass apps? I use keepassium on iOS. I pay for protonmail and also store a copy in protonpass. Proton pass has a nice web interface and doesn’t require me to copy a keepass…
Keepassxc has zero collaborative features and no online sync. I’m a big fan of keepassxc but these reasons are why I pay for 1P. I can add colleagues, guests, family members and have it run on all my devices.
Re: Apple unveils 'Passwords' manager app at WWDC 2024
#708Earlier quoted context omitted.
Bitwarden + cross-platform + free as in beer + free and open-source software Can't really comment on convenience, I moved from LastPass, but it has worked well for me.
I think I checked this. The self hosted wallet was tricky if I remember right.
Re: Apple unveils 'Passwords' manager app at WWDC 2024
#709Earlier quoted context omitted.
In your thousands of free services, how do you resolve conflicts in edits done on multiple devices?
Shouldn't conflict resolution be in the program itself? It should ask me what to do and be able to keep both versions of the conflicting entry. And if I answer "keep both" or defer to later then it should pack both into the vault and upload that. (Also I didn't mean thousands of free services, I meant that each one will give you thousands of megabytes for free. Honestly just google and microsoft accounts, and icloud…
The program itself might not get information efficiently to do conflict resolution (or not at all): for example, you edit a file offline and sync, Dropbox and friends wouldn't be smart enough to just append both of a few bytes worth of data that a password-manager controlled service could since it would be aware of the data structure but would just dump both files, and then both on another conflict etc
So I guess it's just not the same type of sync service that you get for free in those many services
(also I think it's more than a sub-Mb, you have icons there, but also images of docs and what not)
Though maybe this is not an issue as you mention some of the keepass-based apps that go the "app-sync" route instead of manually placed file?
Re: Apple unveils 'Passwords' manager app at WWDC 2024
#710Earlier quoted context omitted.
No Linux or Android, which makes it useless for anybody having any devices running those. And since nobody wants to use two password managers, it remains a better solution to use a truly multi-platform one.
The Android one puzzles me a bit. We were Android + Mac for a very long time, more than a decade. I've switched to iOS over the last few years, but my wife remains a dedicated Android user. I don't really want to switch from BitWarden, but if I did Passwords would be a non-starter for us because of this. I suppose that Apple really considers the iPhone to be the center of its customer's lives, with a Mac or Windows c…
You actually care about your computer, and if software isn't available for your OS then you're unlikely to ever switch OS to use it.
But you could be persuaded to move to iPhone, and maybe if enough new Apple services (which aren't available on Android) tempt your wife then she might make her next phone an iPhone, too?
Apple cares more about persuading people to switch from Android to iPhone than about Windows to Mac. But I also suspect there are many more Windows+iPhone people than Mac+Android.