About Security Keys for Apple ID
support.apple.com
support.apple.com
> At least two FIDO® Certified
I'm glad to see that they not only support, but require the use of multiple keys.
> iOS 16.3, iPadOS 16.3, or macOS Ventura 13.3, or later on all of the devices where you're signed in with your Apple ID.
and
> During set up, you're signed out of inactive devices, which are devices associated with your Apple ID that you haven't used or unlocked in more than 90 days. To sign back into these devices, update to compatible software and use a security key. If your device can't be updated to compatible software, you won't be able to sign back in.
I'm not ready to set this up, since I still use a few Big Sur and Monterey machines.
Unless there will be a warning when adding the keys, this can lead to many support requests they will get from users who did not read this part.
Yes, and also that they support up to 6 of them. That's a very solid number enabling a lot of decent (if basic) backup practices. A number of keys for regular use, a few put in a safe deposit box or safe or the like. Or if (as I'd assume) keys can be reused between accounts, then a family could each have a key, with all keys registered to all accounts, and then 1 or 2 in a safe spot as backup. Everyone still is protected by their password, but if they lose keys/devices then any other family member could be their live backup (and having the majority of keys constantly under control and in active use is good in terms of immediately noticing if one is lost or breaks and so on).
While I know it's definitely not Apple to add extra complexity, if anything it'd be cool if they leveraged this a bit farther even. Would be neat for example to support m of n restore, where if key/password are lost (somebody dies in an accident for example) then any 4 of 6 (or 3 of 6 or whatever) remaining keys can be used to get access. That would be a useful hedge, while not needing to offer unlimited trust to any single person (there could also be a few other safety measures like it taking a week and sending the account owner alerts in the mean time).
>During set up, you're signed out of inactive devices, which are devices associated with your Apple ID that you haven't used or unlocked in more than 90 days. To sign back into these devices, update to compatible software and use a security key. If your device can't be updated to compatible software, you won't be able to sign back in.
My only real disappointment with this is that Apple didn't implement some sort of "Purchases Only"/"iCloud Lite" functionality for old devices. I've still got an iPhone 6 and a few others because a lot of cool apps (both productivity and games) I love were dropped by iOS quite a long time ago. The devices are dedicated app runners, no communications, no syncing needed, but not having them attached to the same Apple ID means the old purchases would all be gone which kinda negates the point. And you can't transfer purchases between IDs, nor purchase now gone apps, so there isn't anyway to just setup a new one not even for money. Maybe it's possible to remove them from the iCloud side while they have WiFi disabled and then keep them offline forever? Still, kinda shitty :(. Though perhaps that's more a symptom of continued from-the-start weaknesses in the Apple ID system. Not being able to move and consolidate purchases has been a huge damn stupid thorn in people's sides almost since it became possible to start purchasing stuff with them.
¹ https://discussions.apple.com/thread/254582672
² https://www.reddit.com/r/yubikey/comments/10jll3q/security_k...
Yeah, unable to use iCloud on Windows is a big show stopper for me right now. I appreciate what Apple software we get on Windows and I've heard the Windows 11-only previews of updated Apple software are getting pretty good now. (I don't have Windows 11 so can't try them for myself.) But I'm very aware they are always going to lag a bit compared to their i-device and macOS versions. Including apparently on security support.
Usernames and passwords are easy, if insecure. Type username, type password, done. Get admin to reset password if you forget. Put in password manager if one account is used by a team.
Security keys are hard. Needing a physical key around every time you have to log into something is annoying. Backups are hard, because off-site backups can't be done over the Internet. Self-service hardware tokens for services with infamously bad customer service is highly risky. Resetting an account if a key is lost or locked requires physically transferring hardware, which can be hard if someone is traveling, or can cause days of downtime. Team access is basically impossible if an account is secured with a physical key.
Authenticators are fine, except if you lose a couple of smartphones too close together, or you need a team to access one account. Password managers that let you securely store the QR code, or actually generate the key put the MFA in the same place as the rest of the credentials, which is not ideal but increasingly necessary for the same reason password managers came into existence in the first place.
Windows Hello and FaceID are actually pretty good, although fingerprint-based biometrics can be a little hit and miss. Not that a decent proportion of Windows users have Hello-compatible hardware. Interestingly, two TV shows in just the last few months (The Peripheral and, believe it or not, Mayfair Witches) have had a moment where a phone belonging to a dead or unconscious person was unlocked by showing it their face, so the shortcoming are entering public knowledge.
We can "all" agree that passwords are "bad", but we cannot agree on what to replace them with, mostly because the level of computer literacy for most solutions is much higher than just typing in a username and password. I can bang out the stuff above because, as an IT professional, I've experimented with KeePass, Windows Hello and Yubikeys in the last six months, buying my own hardware, to try to find some level of opsec that could be used by our customers. All I've done is highlight the lack of commitment to IT in general and training of all kinds in basically all of our customers.
When you enable TOTP with a service, you can extract the TOTP secret and do all of the above with it -- backup to storage, copy to new devices, distribute to multiple people, etc.
I have a couple of TOTPs trapped on crappy apps because I didn't care at the time and can't easily refresh them. However, now I use apps that parse the QR code and store the config in an exportable way.
As we change every damn password in our company LP account, moving it to Bitwarden at the same time, we will implement TOTP MFA wherever we can. If you screenshot the QR code and load it into the accound with the app, all the team with access can use it. It's our next best step. (Once the boss gets the new account sorted.)
Two-way for tech-savvy: https://news.ycombinator.com/item?id=34441697#34444676
In the consumer realm one has to deal with a gajillion different identity authorities so replacing keys or doing recovery because you lost one is a giant pain in the ass. Supposedly passkeys is targeted at that problem.
You cannot do that with a faceid device, unless the security have been downgraded. It will check for eye activity.
I wear glasses and it still check for activity in my face.
A password manager just helps you store your passwords, and automatically inputs passwords for you. This makes it easier to use a variety of strong passwords. Also the password manager can check for a domain name match before doing its automatic input, which helps provide phishing resistance.
"2nd factor" or "multifactor" essentially just means adding on something in addition to passwords. That could be in the form of:
* TOTP = "time-based one time password". Use an authenticator app on your phone to input a 6-digit code which changes every 30 seconds or so.
* "security keys" / "hardware security keys" -- a dedicated device that allows you to authenticate, e.g. via USB or NFC. Generally considered more secure than TOTP, because the code is more than 6 digits worth of entropy, and also it forces the website requesting the code to authenticate itself before it provides the code (again, helps with phishing resistance).
I don't know anything about passkeys or Windows Hello.
As for backup, you should be able to transfer all of your TOTPs from one phone to another by scanning a QR code. For hardware security keys, you can buy multiple keys, register all of them, and keep them in different places. Then if you lose one you just use one of the others (and register a replacement to maintain redundancy).
For the TOTP, if you're worried about losing your phone, usually when you set up a TOTP you can also copy down some single-use "scratch codes" that can work as a backup if your phone breaks or something like that.
Do I need to have all keys in my physical possession to register them with a new account?
I could imagine having some backup keys in different places, but if I need to collect them every time I want to register them for some new account or service, it sounds like a lot of trouble.
(And if the process is too much trouble, the result would be that: (1) I don't use the hardware keys for those accounts, which is less secure; (2) I only register my primary key that I keep nearby, which is dangerous if it would get lost or broken; or (3) my backup keys end up at the same place as the primary one, due to forgetting or being too lazy to put them back, which is also dangerous…)
Yeah I think so. Good points.
I made the effort to look into security solutions for my important accounts (password only is not that!) and chose a security key solutions but the various providers have very uneven support for that - for example Apple was one notable case. Several forcing you to use phone number based solution (including banks) if you opt for secure ways but that is inadequate and risky on a whole different way for my case. Unacceptable.
It is the strong password case all over again: I took the effort to build up a layered approach seting up memorable but strong password categories for the different categories of accounts I have just to be rejected by the odd ones: you are not allowed to use that character! And sometimes: your password must be shorter! Forcing me to their ways, hugely reducing security. Not enough choice.
The idea of a second factor is that "something you have" is hard for an attacker to also have, however, proof of having something usually means "proof that you know some secret" and that secret itself can often be copied.
The lazy "proof you have" something is SMS auth, i.e. proof you control a phone number. However this isn't great, since in some jurisdictions ringing your mobile provider is enough to get control over that number.
TOTP then says: let's assume you have some secret seed and I also know it. If I take a hash of it (HOTP) and include some time information I have a code valid for a small window that is hard to steal. The benefit is that everywhere this secret exists you can have an authenticator. The downside is that this is rarely a separate device to your computer. You also are going to enter your code into a website... and that might not be the right website, allowing capture of the code via phishing.
The standard for legal, qualified digital signatures in the EU is to have non-extractable keys generated on hardware devices and never backed up. Why? Well, if you lose the hardware token (or it is damaged) you don't lose access to encrypted data, just the ability to sign documents. At this point you have an annoying dance to do to be issued a new token, but allowing backup of the signing key means signatures may be repudiated (because someone else could have stolen the backup).
The same goal applies to U2F / FIDO certified security keys. U2F generates a unique key-pair per authentication target and that private key never leaves the authenticator. This gives you two things: 1) a binding between your target service and your device. Phishing becomes a lot more difficult unless you can present the right challenge-response to the authenticator, and 2) an authenticator you physically need to have present, but don't need a pin or awkward copy-paste of a code to use. You aren't using this key for encryption, but for authentication, so, the backup strategy is: have multiple keys. If you lose one, you can delete that entry from respective accounts.
Password managers exist because some websites are password-only and even if not, you can't always trust they employed argon2id as a password hash. It also saves you having to remember multiple passwords. Your password database is something you will need to keep backed up.
Personally I keep printed recovery codes of really important accounts, spare registered security keys, and a disk with my password database on in a safe place.
This feature is designed for users who, often due to their public profile, face concerted threats to their online accounts, such as celebrities, journalists, and members of government [1].
[1]: https://www.apple.com/newsroom/2022/12/apple-advances-user-s...
I think hardware security make a ton of sense for an enterprise environment, where you can go to IT and prove your identity to regain access. But, for something like Apple or Google - I'm sure the recovery process is not as easy.
For a hardware crypto wallets, people go to extremes - safety deposit boxes, fire-proof recovery phrases, etc. But, for me - losing access to my core online accounts would be more destabilizing than losing money on a hardware wallet. Yet, we don't have the ultra-reliable backup methods in place for web auth like we do for crypto wallets.
The Security Key here primarily replaces the 2FA authentication method for adding new devices to your account.
From Apple’s own documentation:
When you use Security Keys for Apple ID, you need a trusted device or a security key to:
- Sign in with your Apple ID on a new device or on the web
- Reset your Apple ID password or unlock your Apple ID
- Add additional security keys or remove a security key
I believe if you lose both you can still add another as long as you have access to a device that’s still logged in.
The biggest hole in Apple’s security model, and one which has been documented to have been exploited many times, is people using phishing tactics to get the 6-digit 2FA code to gain iCloud access, adding a new device, then downloading the unencrypted backup from the victims primary device from iCloud. Security Keys and E2EE now make this impossible.
A lot of services offer one-time backup codes and connecting multiple 2FA devices. Making Yubikey a single point of failure is certainly a bad idea.
Using the A and C nanos. Helped they were permanently in machines though. No mechanical risk.
> A modern web browser. If you can't use your security key to sign in on the web, update your browser to the latest version or try another browser.
It doesn't seem like Firefox 108 supports this. Does anyone know if Firefox beta or nightly work to sign into iCloud with hardware security keys for 2FA?
---
Just confirmed that Firefox beta (109) doesn't support iCloud's sign in, either.
However when I look at the JS code in appleid.apple.com there does seem to be code for U2F code surprisingly.
It only supports legacy U2F keys/mode, as far as I know, and Apple seems to require CTAP2.
I have tried adding my keys and macOS refused because my Mac had been activated on December 3rd last year so for security reasons I can add keys only after March 3rd. this year..
> Because this is a new device on your account, you cannot use it to add security keys until 03/04/2023. This waiting period helps protect your account.
On one hand, you can’t accidentally or absent-mindedly approve a request from someone else on your phone with a YubiKey. On the other hand, with device 2FA you generally need to be present (Face or Touch).
If someone were to steal your yubikey then they’d be able to perform a step that previously you’d have needed to be there for.
I’m guessing MFA (password + presence + YubiKey) is too much of a catastrophic lockout risk to be supported.
Several security keys are protected themselves with an additional factor. There are, for example, Yubikeys which are unlocked by your fingerprint: this now requires the thief to not only steal your Yubikey but also have the skills required to reproduce your fingerprint.
There are also several U2F devices protected by a PIN. The "Only key" uses one PIN to register a service (which you do once per service) and another PIN to authenticate to the service (so you cannot easily be tricked into registering instead of authenticating). The Ledger Nano U2F app is also protected by a PIN and has its own little screen so it displays the name (or the identifier) of the service you're either registering or authenticating to (and tells you if you're actually going to register or authenticate), is protected by a HSM and factory resets itself after three wrong PIN.
I'm using the later to SSH now (requires a moderately recent version of OpenSSH: latest Debian stable is sufficient for example).
Or the thief can “steal” a couple of your fingers too and have unlimited access to your fingerprints. Oh, wait, is that just a movie thing?
CTAP 2 compatible keys, e.g. FIDO 2 (certified or not). Older U2F-only keys won't support a PIN.
In the case of fingerprints, you leave them on pretty much everything you touch, meaning obtaining a copy of your fingerprint in most cases is just a question of stealing the glass you were drinking from at the bar.
It's the equivalent of leaving little notes with your password everywhere you go.
Yes. If you only have one key enrolled and no other recovery mechanism, you're now locked out forever. That's why Apple are pushing you to have two keys as a minimum.
You can choose a key that has an additional factor built in, such as a fingerprint reader.
If you lose one of the keys you can authorize a new one.
If you lose both of the keys and all the Apple devices that you can log into directly, e.g. with fingerprint sensor on a Mac, then you're SOL.
Having something like Touch ID on a device is often an indicator that the device has a trust module (or Secure Enclave), though that isn't a guarantee. The Touch ID itself isn't generally considered a part of the trust module, but instead is often used as an ID to unlock keys in the trust module that have been locked to that biometric data.
(Same generally applies to Face ID.)
The biggest distinction between the trust module (Secure Enclave) in a modern device and a physical hardware security key is proximity. Obviously, a trust module is "right next door" inside the device itself. This has benefits (only need to carry one device) and detriments: lose the device and lose all the keys/secrets inside the trust module (protection from exfiltration includes protection from 'backups'); it's more complicated to use one device with the locked keys on another device (this is shifting somewhat today with new Bluetooth LTE-based personal area network "Passkey" standards) versus standalone hardware security keys are designed to communicate with multiple devices (often anything that supports some combination of USB or NFC); the threat models for accessing keys from a trust module if you have access to a device are different from the threat models for accessing keys from a hardware security key if you have access to only a device or only the key or sometimes even both.
There's definitely cross-over between the hardware trust module on a modern device and hardware security key, but one is a dedicated device for it and the other is part of a larger device and has different threat models.
Apple confirmed that USB-C is coming to the iPhone last fall [1].
[1]: https://www.theverge.com/2022/10/26/23423977/iphone-usb-c-eu...
"Is Apple moving to USB-C"
If his response is "..obviously we will have to..." then I don't think it's unreasonable for the headline.
If he was asked "Is Apple going to comply with EU Law" and his response was the same then I think it leaves room for interpretation, but we're humans, not computers. He was asked a question and he provided an answer to that question and the headline reflects what a reasonable person would infer. If that's not the case then I think that speaks more to his trustworthiness than that of the articles writer.
The only potential problem for turning this on for my personal account is that you can't sign into iCloud using Windows, which isn't a problem in itself (I have no need to sync my photos to my gaming tower), but if it means I also can't sign into my Apple account that would be more troublesome since I like to use Apple Music from my Windows boxes occasionally.
That's exclusively iTunes (or soon the Apple Devices Windows 11 app), if I remember correctly.
> It can be used to sync files[...]
Right, there's also iCloud Drive.
To my understanding: wired backups are still done in iTunes (or the new Apple Devices app), but if you want an on-premises copy of a wireless iCloud backup you'd copy it from iCloud for Windows. Though glancing at it now I don't see that option/how to do it so either my understanding is wrong or I briefly glimpsed an A/B test at some point or I'm confusing something I saw on a different device than Windows.
https://support.yubico.com/hc/en-us/articles/360016649059-Us...
It's bad enough now if your house burns down with all your iOS devices in it.
The article actually says so:
>At least two FIDO® Certified* security keys that work with the Apple devices that you use on a regular basis.
>You must add and maintain at least two security keys. You can add up to six keys.
Edit: ok they come in NFC as well. There goes €100...
If cost is a concern, you're buying the wrong keys. You can get FIDO-certified CTAP2 tokens for much less these days (even Yubico's is only about €25 apiece).
And if I did care that much, I’d put one off site.
This rules out keeping the backup in an actually safe place, like a lockbox at a friend's, at the bank, etc. and means the safest option you have is a "fireproof" safe in the same home.
This is what recovery contacts are for.
There is a backup key also generated that you can either print or save elsewhere. You must retype the backup key to continue.
That’s actually pretty close to what they support, except that the OPTs are only sent to your trusted Apple devices (you can’t use an arbitrary TOTP app).
> since if I lose all my Apple devices I'm locked out
They also support a 28 digit recovery key you can print out and a method for trusted contacts to help recover your account.
Suggesting you shouldn't be required to have multiple keys?
Or maybe Apple is just deciding to require it from you for mysterious reasons. Your IP could have a bad reputation and they're not sure if it's you. Though I think they sometimes they require the password just to keep you from forgetting it.
I wouldn't be surprised if Apple starts selling the keys through it's own retail channels.
with Google branding slapped on them (of course)
The difference is just the 'Designed in California' part, which in the case of a security key should be negligible in terms of cost outlay.
> the Titan keys I have are white-label product made by a Chinese company called Feitian with Google branding slapped on them (of course)
”White label” implies that you can buy the same exact hardware with other branding slapped onto it from other places (https://en.wikipedia.org/wiki/White-label_product)
You can’t do that with most Apple products. Even if Apple didn’t design them themselves, you can only buy them from Apple
Disagree.
There are over 2 billion Apple devices deployed and tens of millions more get sold quarter, so market size isn't an issue.
There's no reason to believe Apple wouldn't be able to get their average margin of around 35% on a security device if they wanted to.
And what competition? The Apple branded security key would be the only one available via the online store that can be bundled with any Mac, iPad or iPhone purchase. And certainly the only one designed specifically for the Apple ecosystem.
It's just a matter of whether or not Apple can add features above and beyond what's typically available.
An easy one would be Find My integration like the AirPods Pro 2 case or the AirTag. Using Find My, the owner could periodically check (or Apple could automate it) that security key is where it's supposed to be, like a relative's house or bank deposit box.
Adding a U1 chip would allow the security key to be found if it were misplaced in a user's home… or in the event of a natural disaster like an earthquake.
And of course they could add TouchID to it, acting as a second factor so only the intended user could use it.
I'm sure I'm just scratching the surface of all the features Apple is uniquely positioned to add to a security key.
Further reading:
- Apple's passkey security doc: https://support.apple.com/en-us/HT213305
- I liked this overview of Passkeys vs Yubikeys, but of course it's a bit biased: https://www.yubico.com/blog/a-yubico-faq-about-passkeys/
If I lose my hardware key I reckon I am screwed?
> How to manage multiple MFA devices in IAM
> You can register up to eight MFA devices, in any combination of the currently supported MFA types, with your root users and IAM users.
To register an MFA device
Sign in to the AWS Management Console and do the following: For a root user, choose My Security Credentials.
For an IAM user, choose Security credentials. For Multi-factor authentication (MFA), choose Assign MFA device. Select the type of MFA device that you want to use and then choose Next. ——
Check the comments, looks like it's a screw-up on their end.
It seems to still be rolling out.
> Hey Andrew, a small number of AWS accounts require additional configuration changes on our end before customers can take advantage of the new feature. We are currently working on making the required configuration changes and we will notify you when your account configuration is updated. For additional support, please submit a support request or reach out to your designated technical account manager.
I do however have an unused Ledger X laying around. Does anyone knows if the Ledger X could act as a security key? Thanks in advance.
I don't have a X but I've got a S which I only use for U2F (well, webauthn now really). Chrome deprecated and now removed U2F support so moving forward it's webauthn but U2F devices are compatible with webauthn.
So yes it works. I use it to log on to several services and I use to log on using SSH.
Anyway here's a video showing how it works on a X:
https://support.ledger.com/hc/en-us/articles/115005198545-FI...
Now I don't know if it specifically work for this new AppleID "dual security keys" thing.
Maybe they also require CTAP2 (as opposed to U2F together with the browser‘s compatibility layer)?
I was hopeful that the Titan would be supported with AppleID, but reading the page it doesn’t look like it.
It’s kind of like how Google clearly states that you need to use Google Authenticator (tm) as 2FA for your Google account, but really any TOTP app will work.
I did this and it seems to be an ECDSA p-256 signature.
You can't enroll the keys through the WebUI; only use them. So enrollment is happening in the iPhone app. They use WebAuthn; an open standard for public key signatures.
I suppose the iPhone app uses https://developer.apple.com/documentation/authenticationserv... for key creation. As that's the native counterpart for creating WebAuthn keys
The only supported key-algorithm for this API is https://developer.apple.com/documentation/authenticationserv... (ES256). so I'm 99% sure they are indeed using ES256 keys
https://support.yubico.com/hc/en-us/articles/360016649059-Us...
I did get it set up correctly at some point but an OS upgrade wiped the settings. I’ll have to try it again, but the path for setup isn’t as easy as it seems.
In America I know only of https://mercury.com
Pity it is only for newest OS versions. : ((
Of course not