6 ms·
>> ...For users who opt in, Security Keys strengthens Apple’s two-factor authentication by requiring a hardware security key... I hope they will support existi
by KindAndFriendly 4y ago
>> ...For users who opt in, Security Keys strengthens Apple’s two-factor authentication by requiring a hardware security key...
I hope they will support existing Yubi-Keys etc and not force users to get the dedicated Apple hardware key.
- yakkityyak 4y ago> force users to get the dedicated Apple hardware key I don't think there is one?
- ethanzh 4y agoI think your iPhone is the dedicated Apple hardware in this case
- zaroth 4y agoYou don’t have to guess the announcement actually tells you 3rd party keys can be used and NFC keys can be tapped on the iPhone.
- frizlab 4y agoThe iPhone and recent Macs are ones. But it would not make sense to you your iPhone to protect your iCloud I think.
- yakkityyak 4y agoIt was a rhetorical question :P The section of the announcement is emphatically about 3rd party security keys support, so the worry about lack of support of YubiKey over some push for some imaginary Apple Dedicated Key didn't make much sense to me. Also, security key (at least to me) implies a small, keychain sized device. I wouldn't think of calling my Mac Studio a security key. There is no device marketed as such, even though yes, the SEP can and has fulfilled these purposes.
- frizlab 4y agoGiven they already support standard WebAuthn (passkey or other), I think it’s a pretty safe guess to say they’ll support Yubikeys. I can’t find any written confirmation yet though.
- diebeforei485 4y agoWritten confirmation in WSJ (paywall) here: https://www.wsj.com/articles/apple-plans-new-encryption-system-to-ward-off-hackers-and-protect-icloud-data-11670435635 https://www.wsj.com/articles/apple-plans-new-encryption-syst... > [Apple] will now allow users to log in to their Apple accounts with hardware-based security keys made by other companies such as Yubico.
- lxgr 4y agoCurious to see how they will use it. I don‘t see an immediate way for FIDO/WebAuthN to help in an end-to-end encryption scenario.
- jackson1442 4y agoI don’t think this is directly related to the E2EE announcement, rather it is an option to replace the current MFA method of receiving codes on your Apple devices.
- lxgr 4y agoThat makes sense, thank you. It's also mentioned under the corresponding heading on the press release.
- technothrasher 4y agoThe linked page says yes. "users will have the choice to make use of third-party hardware security keys"
- deleted 4y ago[deleted]
- cguess 4y agoThe screenshot pretty clearly shows a yubikey outline.
- fmajid 4y agoThat's what I am most looking forward to. I hope they also allow you to disable the phone-based recovery scheme that is just a boulevard for SIM-swapping hackers to breach through.
- dang 4y ago(This comment was posted when the linked URL was https://www.apple.com/newsroom/2022/12/apple-advances-user-security-with-powerful-new-data-protections/ https://www.apple.com/newsroom/2022/12/apple-advances-user-s..., which contains the physical security key announcement as well as the E2EE stuff. If there's a better URL for the security key announcement, we can factor this topic into its own thread, since it's a minority topic in this one and mostly getting overlooked.)
- twobitshifter 4y agois apple making a hardware key?
- Obscurity4340 4y agoYes its called your iDevice/Mac etc. Trusted Circle devices are all security keys