news.volyx.in

Apple Passkey (developer.apple.com)

817 points by samwillis · 1559 days ago · 398 comments on HN

Article summary

The article discusses Apple's Passkey feature, which uses WebAuthn under the hood to replace passwords with cryptographic keypairs. Passkeys are synced across devices via iCloud, allowing users to access their accounts from multiple devices. The feature aims to provide a more secure and convenient authentication method. However, the article's details are not available, and the discussion is based on the comments.

Main themes

  • Passkey feature
  • WebAuthn and FIDO2 standards
  • Vendor lock-in
  • Security implications
  • Convenience and usability
  • Interoperability and compatibility

What commenters say

  • Apple's Passkey feature uses WebAuthn and is a significant step towards replacing passwords with cryptographic keypairs.
  • The feature's reliance on iCloud syncing raises concerns about vendor lock-in and potential security risks.
  • Some commenters argue that the benefits of Passkey, such as immunity to phishing, outweigh the potential drawbacks of vendor lock-in.
  • Others believe that Apple's implementation of Passkey is not a significant improvement over existing password managers and may not be compatible with non-Apple devices.
  • There is a debate about the security implications of syncing passkeys to iCloud, with some arguing that it is a necessary compromise for convenience and others seeing it as a potential vulnerability.
  • The discussion also touches on the issue of exporting passkeys from Apple devices, with some arguing that it should be possible to transfer data to non-Apple devices without compromising security.
  • Some commenters are concerned about the potential for Apple to act as a centralized identity authority, holding private keys hostage with no recourse.
  • The use of WebAuthn and FIDO2 standards underlying Passkey is seen as a positive aspect, as it allows for interoperability and avoids proprietary solutions.