3 ms·
question for those who know: for those of us in apple ecosystem, is just relying on their keychain an acceptable alternative to a third-party password manager c
by paultopia 4y ago
question for those who know: for those of us in apple ecosystem, is just relying on their keychain an acceptable alternative to a third-party password manager company?
- nebulous1 4y agoAlso how, say, firefox's password manager compares. I've tried to look up technical comparisons before but found them unconvincing (making clearly outdated or incorrect claims). You can get the standalone managers compared to each other, but the non-standalones are missing.
- rtev 4y agoI do know the answer to this - Firefox is not an acceptable alternative to a strong password manager. Local admin can dump any passwords from Firefox, and I think a user can even dump their own passwords from Firefox on windows and Linux.
- nebulous1 4y agoThey do have a "primary password" these days which I believe encrypts the locally stored passwords and the locally stored sync key.
- smallerfish 4y agoI don't think that matters. Local admin can also install a rootkit or a keylogger. Physical/admin access is game over no matter what you use.
- judge2020 4y agoIf your passcode(s) on your device are longer than 6 digits, sure. As it stands, you can recover your iCloud Keychain by either[0]: (A) signing into iCloud (Requires Apple ID Password) + approving the new device on an existing device that has Keychain access or (B) signing into iCloud (Requires Apple ID Password) + performing SMS 2FA + entering the device passcode of your primary device The threat model here is where a nation-state actor enlists the full cooperation of Apple and gets Apple to hand over your encrypted iCloud Keychain, then gets Apple to siphon your Apple ID password next time you sign in. They could then use those two pieces of information to brute force the passcode on your encrypted Keychain data. If you have an 8+ digit passcode, or an alphanumeric passcode, that makes it exponentially harder to brute force. With the long passcode, your only remaining threat would be Apple shipping malicious hidden code or an RCE in their product that allows them to force your device to approve new devices non-interactively, which would allow them to approve a malicious device the next time you approve your own new device for access to iCloud Keychain. Or perhaps it's more likely that, when you're setting up a new device, Apple sends over the name of your new device, but with the public key/CSR of their own device, since iOS doesn't show a key fingerprint during device approval or anything. 0: https://support.apple.com/guide/security/secure-icloud-keychain-recovery-secdeb202947/web https://support.apple.com/guide/security/secure-icloud-keych...
- DavideNL 4y ago> As it stands, you can recover your iCloud Keychain by either... I remember, a long time ago when i created an AppleID, there was a yes/no choice whether or not to upload [something related to the password] to Apple, so it would become possible to recover the AppleID password if needed in the future. Is that still a thing, or has it been replaced by new features now?
- rtev 4y agoGood question. Can local admin dump apple keychain passwords? If so, hashed or plaintext?
- pvg 4y agoRelying on your browser/OS password manager is, for the vast majority of people, a better alternative. These days you get pretty decent integration even if you use Chrome on macOS and want your passwords to show up on your iPhone.
- zeroonetwothree 4y agoSeems unnecessarily risky. Do they have an export flow? What if you get a non Apple device?