3 ms·
I believe there is a plan to support syncing private keys [0] (that you can turn on via the developer tab in Safari) announced at WWDC 2021 [1] and discussed in
by gilbertbw 4y ago
I believe there is a plan to support syncing private keys [0] (that you can turn on via the developer tab in Safari) announced at WWDC 2021 [1] and discussed in this blog post from Hanko [2]. But I have not heard any more about it in the last 10 months.
[0] https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication/supporting_passkeys https://developer.apple.com/documentation/authenticationserv...
[1] https://www.macrumors.com/2021/06/10/apple-icloud-keychain-passkeys/ https://www.macrumors.com/2021/06/10/apple-icloud-keychain-p...
[2] https://www.hanko.io/blog/passkeys-part-1 https://www.hanko.io/blog/passkeys-part-1
- tialaramex 4y agoSuch a technology looks to me like an attractive nuisance. It's the Bearer Bonds of security technology - benefits to legitimate users are minor, yet the costs from all the illegitimate uses accrue to everybody all the time. Don't get me wrong, it would be very useful (well, the Apple version not to me directly since I don't have an Apple device) but I think the security penalty is too high in practice.
- ArchOversight 4y agoIt'll be nice to allow access to websites I registered with my TouchID on my Mac on my iPhone without needing to re-enroll a new security token.
- jrockway 4y agoYeah, I don't see this as a big security disaster. I sync my SSH keys between machines manually. That increases the exposure risk, but not as much as using the same password on every site. Mobile devices have pretty good security (option to auto-wipe after using the wrong lock screen passcode a certain number of times). Desktop security is pretty bad (straightforward to steal the Windows Hello keys on some installs), but the rootkit that steals your WebAuthn keys will also just steal your Google session cookies or whatever.