news.volyx.in

Face ID and Touch ID for the Web (developer.apple.com)

647 points by gok · 2293 days ago · 270 comments on HN

Article summary

Apple has implemented Face ID and Touch ID for the web, allowing users to log in to websites using biometric authentication. This feature is powered by the Web Authentication standard, which provides strong authentication through public key cryptography. The implementation uses a platform authenticator, which is a feature built into the device, and includes a Secure Enclave to manage private keys. This allows for a frictionless and secure login experience.

Main themes

  • Web Authentication standard
  • Biometric authentication
  • Vendor lock-in
  • Security and privacy
  • Platform authenticators
  • Roaming credentials

What commenters say

  • The implementation of Face ID and Touch ID for the web may suffer from vendor lock-in, but the use of the Web Authentication standard mitigates this risk.
  • The Web Authentication API provides a secure way to authenticate users without relying on passwords, but some commenters are concerned about the potential for vendor-specific implementations.
  • The use of biometric authentication for web login is a good idea, but it may not be suitable for all use cases, such as B2C sites that prioritize ease of use over security.
  • Some commenters believe that the Web Authentication standard should be extended to support roaming platform authenticators, which would allow users to access their credentials across multiple devices.
  • The implementation of WebAuthn on iOS and macOS devices may be limited by the requirement that private keys remain on-device, which could make it difficult to implement synchronized authentication across devices.
  • The use of WebAuthn may require developers to rethink their account recovery flows, as traditional methods such as email or knowledge-based authentication may not be secure enough.
  • Some commenters are concerned about the potential for WebAuthn to be used as a means of tracking users, but others believe that the use of anonymous attestation can mitigate this risk.