3 ms·
Completely agree about Apple's 2-factor implementation being completely ridiculous. If you don't have an iPhone it gets even weirder -- I've had it pop up auth
by FreakyT 9y ago
Completely agree about Apple's 2-factor implementation being completely ridiculous.
If you don't have an iPhone it gets even weirder -- I've had it pop up auth codes on the same laptop on which I'm logging into iCloud.
- dannyw 9y agoYour laptop may be trusted, your browser isn't.
- pfranz 9y ago:shrug: it makes sense to me for icloud.com Your laptop is trusted, but the browser you're using isn't. AFAIK there's no browser API for a trusted OS to bless a web browser and web request so this is kind of a workaround. Safari has the possibility of doing this without standards support--I don't know if it does. Pet-peeve, but I wouldn't say ridiculous. It's like how there's no Kerberos compatibility for web apps.
- hmahncke 9y agoCould you walk through that threat model? I don't quite get it. In what scenario is an antagonist in control of my (untrusted) browser but not also in control of my (trusted) laptop? Put another way, doesn't that antagonist always see the 2fa code, and then enter it?
- pfranz 9y agoYour browser doesn't know the laptop is trusted. I'm not aware of any standard API that a browser would use to confirm they're running on a trusted laptop (they'd have to implement an OS specific call for an OS specific feature...which doesn't often happen). In theory Safari could support it (I don't know if it does or doesn't). Apple could push for either a standards body or just Chrome/Firefox to implement macOS APIs--but I don't see any reason those browsers would make the effort.
- fpgaminer 9y agoEven better: I've had it pop up the auth codes on my laptop, but iCloud didn't actually ask for them.