11 ms·
Safari 18 can automatically transition users to passkeys [video]
- deleted 2y ago[deleted]
- Animats 2y agoAll your passkeys are belong to us. The trouble is, Apple devices, which Apple can update remotely and for which no one external can see the source code, are trusted. There's this one huge single point of failure. Can you use this without iCloud? Can you avoid any iCloud involvement?
- hutattedonmyarm 2y ago> Can you use this without iCloud? Can you avoid any iCloud involvement? 1Password supports passkeys. So yes, you can
- wlesieutre 2y agoBitwarden too https://bitwarden.com/passwordless-passkeys/ https://bitwarden.com/passwordless-passkeys/
- realusername 2y agoThe only answer I found is this one https://1password.community/discussion/142696/will-it-be-up-to-apple-to-export-passkeys https://1password.community/discussion/142696/will-it-be-up-... So no, it seems you are locked in to the platform
- fiddlerwoaroof 2y agoLastPass definitely pops up as a usable passkey provider on iOS
- realusername 2y agoYes but can it sync passkeys created by Safari so that they are usable on Linux/Windows/Android?
- TheNewsIsHere 2y agoNo. You have to enroll the password managers independently.
- stouset 2y agoJust add new passkeys into 1Password or Bitwarden or whatever else. Every site I’ve seen that allows passkeys allows multiple. It really, really isn’t as big a problem as everyone seems to want to make it out to be.
- faeriechangling 2y agoYes because you can use 3rd party credential managers that use passkeys.
- deleted 2y ago[deleted]
- oidar 2y agoI'm hesitant about embracing passkeys. I think passkeys are poorly implemented at this point because of the inability to move them around like passwords - I don't want to be locked in. But I don't think what he is explaining is forcing an automatic upgrade for passwords, he is explaining that it can happen at the request of the user or application prompt. Notice that the diagram - The user in the app requests to upgrade (sure, let's call it an upgrade) from a password to a passkey.
- JakaJancar 2y agoThe lack of export scares me too, but is it really a problem? If I were to switch to Linux, I guess it just means that I'd have to go through the forgotten pass(key) flow on every site on first login?
- bigiain 2y agoYeah. For a while when I was mostly working on mobile apps, I'd switch between iOS and Android every year. I've almost like clockwork switched between macOS and Windows with every job change. I'm very much leaning into going all Linux for personal stuff based on MS and Apple's pushing Gen AI into the OS. I'll stick to Yubikeys and TOTP 2FA for as long as I can instead of jumping into passkeys.
- faeriechangling 2y agoI'm using exportable passkeys in .kdbx format right now. There's no reason conceptually why passkeys have to be non-exportable. Regular keys are only seldom implemented in that way.
- stpn 2y agoIt doesn't seem like it will i.e. _delete_ your username/password, but the behavior is actually automatic without user prompt. See 1:10-ish[0] for the demo - I found this at least somewhat surprising, though I submit this as a passkey advocate (for a while, my side business only-supported passkeys, but we backed away from that). [0]: https://developer.apple.com/videos/play/wwdc2024/10125/?time=70 https://developer.apple.com/videos/play/wwdc2024/10125/?time...
- cyberax 2y agoThis is straightforward illegal monopoly nightmare fuel right here. Apple passkeys are going to be locked-in into their infrastructure, with no possibility to easily switch devices. This doesn't have to be true, there are third-party password managers with Passkeys support (e.g. BitWarden), but they are not going to be able to access Passwords. It's specifically locked to only browser applications, Apple will not provide entitlement to access the keychain for any other app.
- fiddlerwoaroof 2y agoThis isn’t true as far as I can tell: when you create a passkey on iOS, the first screen prompts for which app to use to create the passkey and LastPass, at least, implements the necessary APIs
- cyberax 2y agoMost users will not have them installed. And once you start using iCloud for them, migrating passkeys out of it is impossible. You can't just install 1Password later and click "Import Passkeys".
- fiddlerwoaroof 2y agoMaybe not, but you can install 1Password later, go to the account with the iCloud passkey and use it once, then use 1Password to generate a new passkey for that account. This flow is also generally better than trying to port keys between accounts, which adds a lot of security concerns.
- cyberax 2y agoOnce you have hundreds of accounts? Yeah, sure.
- aeontech 2y agoI might not understand the tech as well as you do, but does BitWarden have rights to read 1Password vault, or 1Password have rights to read the Lastpass vault? Generally I thought with passkeys, the logic is that you provision one passkey per app you want to have access to a service? Ie, I can provision a separate passkey for GitHub, for instance, both in 1Password, and in Keychain if I like, and sign in to the service with either one? Or am I missing something?
- romwell 2y agoEDIT: I know many people love their Apple devices and take criticism of that company as a personal attack, but please consider that I speak from experience of a US person whose laptop and cellphone were stolen in Poland in 2022. Instead of downvoting, please help me understand: how would one re-gain access to services used with passkeys in this scenario? Note that T-Mobile won't ship a SIM card overseas. ----- Great reason to not use Apple ecosystem. Having a cellphone / laptop broken and/or stolen is enough hassle without all the authentication being tied to the device that you aren't likely to use for more than a couple of years anyway. And yes, things like that actually happen to people who are not CEO of Apple. Especially while traveling, when your other devices are far away. It sounds like someone decided to reinvent 2FA hardware in the worse way, combining the inconvenience of needing a physical key with all the hassles of password and adding a million ways for the key to self-destruct. Oh, the passkeys can be transferred through the cloud? Explain like I'm five how that's more secure than email/SMS OTP for authentication then (which are an awful thing too, but at least I can have my own email). So we have one more link in the security theater that I absolutely trust is more secure than having passwords.txt in Dropbox (how is it different, again?). From a user's perspective, passkeys sound like a solution in search of a problem. The only thing I can see passkeys doing for me is locking me out of my accounts when I need them most. Or facilitating other parties in that.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- lolinder 2y agoThis title is highly editorialized so as to be very misleading. The video doesn't mention Safari at all, it describes new APIs in iOS and in the web standards that allow developers to transition users to passkeys. Notably, these APIs work on iOS for whichever password manager the user has configured, not just the built in one. To the extent Safari is implicated in this at all it's that Safari implements CredentialsContainer.create [0], but that's a web standard that every major browser is implementing. I'm all for scrutinizing the rollout of passkeys to make sure it doesn't turn into a lock in situation, but editorializing a video title is particularly egregious because, as we see in this comment thread, people are even more likely than usual to read only the title. [0] https://developer.mozilla.org/en-US/docs/Web/API/CredentialsContainer/create https://developer.mozilla.org/en-US/docs/Web/API/Credentials...
- sakjur 2y agoYeah, it seems bad enough that Apple are seemingly encouraging developers to push their users into using passkeys without asking the user. It’ll still be the website or app that instructs the browser to create a passkey if possible, and Safari will oblige (other browsers might have the courtesy of asking which the demo didn’t seem to do for Safari on iPhone). I really hope that developers ask their users before installing a passkey on their behalf. The assumption that whatever happens to log in now should be trusted for future logins seems dangerous, and I’d hate for passkeys to get a reputation for something people use to hijack their exes accounts or whatnot.
- hedora 2y agoAssuming the Apple side of the API doesn't prompt the user before setting a passkey, sites will inevitably start using passkeys as tracking cookie replacements. I can't believe they'd be that shortsighted when designing up the APIs for this.
- sakjur 2y agoThat’s an interesting aspect. I’m not sure that’d be practical, but I’m not sufficiently read up on passkeys to say for sure. I don’t think passkeys are passed automatically and I really hope they’re not available via CORS? That should limit the utility of passkeys as tracking cookies. I also believe it informs the user when it’s used, based on the demo. And if that’s an attempt at circumventing the EU ePrivacy directive (“the cookie law”) it’s unlikely to work based on my reading (IANAL) of the paragraph in question: > Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service. from https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02002L0058-20091219 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
- meling 2y agoPasskeys are great. Me and my colleague are sharing a GitHub account that we use for managing a GitHub app on our autograder server. Previously we had to share the password. Six months ago we set up one passkey each on the GitHub account and no longer need to think about the password. (We are only using this GitHub account for this one thing, and we don’t use it for commits etc.)
- eddyg 2y agoThere is a lot of FUD around passkeys. Think about all the regular (read: non-Hacker News) users out there who fall for a phishing email/SMS, or who re-use passwords and get popped by a credential stuffing attack. Passkeys provide not only massively-improved security (they can’t be keylogged; they are linked to a specific domain so can’t be spoofed by look-alike fake login pages; they’re protected from replay attacks even if the transport mechanism is compromised), but a much nicer login flow as a bonus. Many people also don’t understand how easy it is to login from a different device: say an Android user created a passkey for a site with Chrome. Now that user needs to sign in to the same site on a Mac running Safari (where there is no passkey for the user). They can still use their Android device to login from the Mac by selecting “use a passkey from another device”. Safari will show a QR code that they scan using the Android phone, and verify with their screen lock. A one-time passkey signature is transferred to the Mac, which the website uses to authenticate the user. The two devices verify that they are in proximity with each other using Bluetooth. This cross-device, cross-operating-system mechanism of passkey authentication is standardized under FIDO; no additional work is needed by the website to enable this login flow. If you are “anti-Apple” or “anti-Google” and have strong aversions to them securely backing up things like passkeys (again, think of all the non-Hacker News readers where this is not the case), then go ahead and continue to use passwords. But we should be encouraging our parents, grandparents, siblings, friends, etc. to embrace passkeys to make all of their accounts more secure and phishing-resistant. The more passkey FUD they see, the longer people will have to deal with annoying (and still insecure) SMS codes, the longer passwords will be stolen/re-used, etc.
- threatofrain 2y agoWhy not encourage friends and family to use password managers instead?
- lolinder 2y agoWhy not encourage them to use password managers with passkeys? All the major players offer them.
- 2y ago