Apple just showed us how it will kill the password forever
tomsguide.com
tomsguide.com
If that device was the one source of her access to all of the accounts she has, she would have been completely unable to do anything until purchasing a new phone and porting her phone number to that phone.
I was under the impression it was very poor security to use something like a face or fingerprint as a password... Okay for a username, but should be avoided at all costs for passwords.
It's easy to use a mask (or occlusion) to prevent a system from detecting your real face, but spoofing a specific person's face is a much bigger task. Any decent modern face rec system is going to use liveness detection as part of its analysis.
But in case it wasn't clear: it's not an API key, but a public/private ECC P-256 key pair used for ECDSA signing. Apple only knows the public key (it doesn't much matter if the whole world knows the public key), whereas the private key never leaves the T2 chip. If any secrets have been exfiltrated from the T2 enclave there are bigger problems at hand, and generating a new key pair would be useless before fixing those problems.
If you prefer a pin or password to protect your phone you can use that instead.
Also what happens when you flash a Qr Code, is Apple involved at any point (which makes it a pretty big spof) ? Can Apple add/revoke login authorisations for individual devices, and if so is there really a fundamental difference between this and an Apple SSO with biometric checks ?
From a naïve point of view it resembles Github/lab/tea SSH key-based authentication with extra steps, a us-based third party cloud provider involved and a new sheen of consummate proprietarism
Credential stuffing, weak passwords, password database leaks, all solved for with passkeys and leveraging existing smartphone ecosystem security mechanisms. Over time, your casual user might not even need a password manager anymore: your mobile OS is the password manager.
1. Sharing accounts. If I want to share a subscription to the Economist with my wife, say, I give her the username/password. Does the Apple/Google/MS alternative support multiple authorised identities?
2. Single point of compromise -- if the identity system or the phone is compromised, everything is compromised.
3. What if the biometric doesn't work, or the biometric sensing system doesn't work. Say my phone camera has just stopped working (which it coincidentally has, as I write this) ... does it freeze me out?
Each registration and subscription is for the personal use of the Registered User or subscriber only. You may not share your log-in details or password with any other person. You may not share or transfer your subscription. https://www.economistgroup.com/terms-of-use
2. Most people already have a single point of compromise in their primary inbox, password manager, or browser storage. This doesn't solve the single point of compromise problem, and I'm not sure that any easy-to-use system could.
3. If the camera fails to recognise me currently when I use Apple Wallet, I am invited to enter a passcode. I'm not sure if this same fallback would be implemented, but I do see a photo which indicates that you can use an external security key instead of biometrics.
Choose freedom. Embrace the green SMS bubble.
But the adult thing is that 90% of the freedom to be had is outside of computers. The total calculus might very well give you more freedom if you go full Apple in 2022 compared to many of the other options.
FIDO seems to always require JS these days, too. Sucks that we're headed to a place where you won't even be able to log in without executing arbitrary server-provided code.