4 ms·
Passwords in iCloud Keychain are already E2EE, it seems reasonable the private passkeys would be too.
by gpanders 4y ago
Passwords in iCloud Keychain are already E2EE, it seems reasonable the private passkeys would be too.
- djbusby 4y agoHow could one verify that? like for compliance audit?
- fnordpiglet 4y agohttps://support.apple.com/guide/sccc/introduction-sccccea61877b/web https://support.apple.com/guide/sccc/introduction-sccccea618... Introduction to Apple security assurance As part of our commitment to security, Apple regularly engages with third-party organizations to certify and attest to the security of Apple’s hardware, software, and services. These internationally recognized organizations provide Apple with certifications that align with each major operating system release. …
- znpy 4y agoAre such third parties listed? Can you inspect their reports? What testing methodologies are involved in order to issue such certifications? And can we see such certifications at all?
- TillE 4y agoIf you don't trust Apple, why would you trust a third party auditor? I can't think of any entity I would trust with securing truly sensitive information. For important stuff, do it yourself. For simple things, including bank accounts and such, I see no issue with trusting Apple.
- jupp0r 4y agoTrust requires transparency and a published security audit report created by a reputable independent author would definitely increase my trust in Apple because they show that they don't have anything to hide.
- fnordpiglet 4y agoBecause you’re trusting both apple and the third party jointly, each of whom have different incentives. I don’t know I buy the “for truly sensitive stuff do it yourself” line. That’s like saying for the truly lethal substances handle them yourself. Most people aren’t more skilled than the apple security folks. You’re almost certainly going to screw up your encryption or leave some vulnerability unpatched or unknown. Frankly I consider my iOS devices to be some of the most secure systems I have access to, and reading through their security documentation has informed that opinion.
- ee64a4a 4y ago> Because you’re trusting both apple and the third party jointly, each of whom have different incentives. The cynical view, of course, is that Apple's incentive and the Third Party's incentive can become very much aligned for the right amount of money.
- fnordpiglet 4y agoYou also have to consider the market value of their reputations jointly as well. It would have to be a huge incentive to risk their reputation, both apples with their security conscious customers and customers with high regulatory burden, and the auditor whose only asset of value is their reputation. Auditors typically poof out of existence (Anderson anyone?)
- fnordpiglet 4y agoYes, particularly if you have need to. But a lot of the details you mention are findable in that link
- ccouzens 4y ago> iCloud ... backup > E2EE If you can lose all your existing devices, and can still restore your data, then that data isn't end to end encrypted. I'm taking the "end" in e2ee to mean your devices. Nothing but your devices can decrypt your e2ee prospected data. If a new device can enter the circle of trust without an existing device's corporation then there is a backdoor. I imagine icloud keychain supports synchronization rather than backup
- systemz 4y agoMaybe usage of user account password would allow for E2E without any device?
- hoorible 4y agoThe password stored in your backup via iCloud Keychain use the passcode of your devices as a secondary encryption/lock method, which doesn’t have a password recovery mechanism like the Apple ID used to secure your iCloud backup. Not sure that meets the definition of E2EE but it’s not like the passwords are recoverable by another party (or even you, if you forget the passcode) just because they’re in your iCloud backup.
- deleted 4y ago[deleted]
- cycomanic 4y agoSo maybe I don't get it, but I always understood that 2FA means something you know and something physical you have. Now if I can get they keychain using something I know, does that not somewhat defeat the purpose of 2FA?
- judge2020 4y agoIn general it's "who you are" (biometrics) as well as "what you have", with the OS being the one ensuring that the phone itself was unlocked and having an extra biometric check when signing in with passkeys; this is how iOS currently works, it pops up face ID before it signs any Webauthn challenges. Also, ideally, your syncing passkey solution (whether that be 1password or iCloud Keychain) would itself be a combination of multiple factors before you can get in - in the case of iCloud Keychain, 2fa is on by default on your Apple account, and the keychain is also protected by your password plus the passcode of one of your devices. In general this is already immensely more secure than passwords because the website is verifying a signature instead of the correctness of a shared secret. So, it'd still be possible to have 2fa with the first factor being passkey and the second factor perhaps being another physical security key or maybe verification of an email code, but that would likely be reserved to enterprises and high-security applications. (I assume Apple themselves aren't going passwordless themselves anytime soon, especially with how that'd work on fresh devices).