5 ms·
The most disturbing thing about iCloud Keychain is that you can get access to all of your stored passwords just by unlocking a device linked to your Apple ID.
by RGS1811 9y ago
The most disturbing thing about iCloud Keychain is that you can get access to all of your stored passwords just by unlocking a device linked to your Apple ID. Not just the ability to log in with them, the actual plaintext.
- falcolas 9y agoUrm, if you have the ability to log in with a password to a website, you require the plain text password. Keychain also prompts for your user password before allowing plaintext access, not just the fact you're logged in. Not sure what else is expected in this case, you'd get the same behavior from most other password managers.
- RGS1811 9y agoKeychain doesn't prompt for your user password on iOS. Just your unlock code. That's what bothers me.
- jsjohnst 9y agoDon’t use a basic unlock code then. I use an XKCD style passcode to unlock mine.
- nextstep 9y agoBut iOS won’t reveal the plaintext password from the keychain to the user (it will only autocomplete forms).
- lotsofpulp 9y agoIt will if you go to settings->accounts and passwords.
- hrktb 9y agoyou still get a password or touch if prompt before showing the passwords.
- lotsofpulp 9y agoI assume RGS1811 was worried about someone using your finger for TouchID or face for FaceID, involuntarily. I also worry about that, especially if you get knocked out or black out or something, but I think the solution is to not have important login info in the keychain at all, such as access to money (bank apps), email, or other uses that can be used to verify your identity or steal from you.
- falcolas 9y agoIf that is a legitimate concern, then don't use Touch ID or Face ID. By using those a person is intentionally choosing convenience over security. By even saving passwords in an account-shared fashion (be it Keychain, LastPass, or 1Password), you're giving up some security for convenience. The latest iOS versions have also included a "five clicks on the power button" emergency option, which disables both TouchID and FaceID. It's not perfect, but if you're going into a questionable situation, it's a good way to avoid being coerced into using those to unlock your phone.
- RGS1811 9y agoWhat made me concerned was the discovery that, on an old iPad mini I rarely use (without touch id / face id), entering the standard four digit unlock code is enough to get access to the full list of logins/passwords stored by iCloud Keychain. I would like to have to at least re-enter my apple ID to get at this full list.
- gok 9y agoYou need a second factor (physical access to a device already in the circle) to add a device to the iCloud Keychain. Edit: I see you are worried about devices already linked
- matthewmacleod 9y agoI don't believe this is entirely accurate – a further auth prompt is always required before revealing plain-text passwords.
- geocar 9y agoThis isn't unique to Apple: Google has adopted the same policy. It's not clear what the best solution is here, or if the best way to have the conversation about it follows hyperbole like "the most disturbing thing". I think password managers are on the whole a good thing because people are using more (stronger) passwords. I also think the password manager could (at least on trusted hardware like an iPhone) provide some protection from the attacks you're alluding to, such as a tarpit that slows access to the password database, but they certainly won't offer any protection on a desktop machine without specialised hardware and it might be difficult to get right -- difficult enough that new security vulnerabilities are introduced instead. What exactly do you propose?
- discreditable 9y agoI think Firefox's solution is a little better. You can set a master password which is used to encrypt the password database. To unlock you have to enter the password. You can browse without unlocking.
- geocar 9y agoBoth the iPhone and Google Chrome ask for authentication before showing the passwords. Firefox works similarly: Once you unlock it, you see all the passwords. On an iPhone or Google Chrome, you have to click each password you want to see.
- sowbug 9y agoFortunately, Chrome for Linux and Chrome OS don't ask. Both OSes trust users to control access at the session level.