Apple passwords deserve an app
cabel.com
cabel.com
In short.
1. The experience on Windows is terrible. They can claim it's cross-platform but it's truly a sub-par product.
2. On Mac it's tied specifically to Safari. I use Safari a lot but if I'm in a different browser then my passwords are unavailable.
3. The GUI is buried in System Settings. Heaven forbid you need search it's only a simple 37 clicks away!
I think those were my big complaints. If you are 100% Mac then it's a good product. Going outside of the walled Apple garden leaves a lot to be desired.
I think Apple would consider this "working as designed."
Plus, putting second factors in the same location as your first factor (e.g., 1Password) seems to pretty much defeat the entire purpose of having a second factor. If you're using strong passwords with 1Password, your second factor is basically only defending against a leak of your password database. If you're storing your second factor in that same password database, what are you gaining?
But if you have backup second factors (you have backup second factors, right?) and you're worried about Passkey lock-in for whatever reason… just use that other second factor for AWS or any other account which supports only one.
> Now, you can add multiple MFA devices to AWS account root users and AWS Identity and Access Management (IAM) users in your AWS accounts. This helps you to raise the security bar in your accounts and limit access management to highly privileged principals, such as root users. Previously, you could only have one MFA device associated with root users or IAM users, but now you can associate up to eight MFA devices of the currently supported types with root users and IAM users.
— https://aws.amazon.com/blogs/security/you-can-now-assign-mul...
But if you lose all the devices with your passkeys on them, they are gone for good.
Not quite! 1password itself counts as two factors: something you know (the master password), and something you have (the additional secret key).
Passkeys in 1password would eliminate phishing as a problem.
Feels like these things are designed by Californians with no idea of how the world is.
My comment is targeted at someone who is savvy enough to: a) care about having "real" 2FA, and b) is concerned about lock-in, and c) is extremely sensitive to being locked out. For someone like that, you're already buying YubiKeys or some equivalent. And if you don't already have some, you're never prevented from using them later.
If you're using hardware 2FA, you should absolutely have backups. I've used YubiKeys for years and have one in my laptop, one on a keychain, and one in a safety deposit box.
Passkeys are just another instance of this. I have added Passkeys to all of my accounts with 2FA and it's somewhat more convenient (significantly more convenient for mobile devices). But every account also has all my YubiKeys attached as second factors.
There is no lock-in. And while it's inconvenient and annoying to have to add multiple keys to every account, that is already the reality if you're responsibly using hardware second factors.
I currently have a Microsoft (Work) account that I'm SSO logged on.
Incoming iTunes Password Manager, next event :P
Punishing us geeks who like using multiple different kinds of OS on their phones and computers. :(
It also works on Windows!
It‘s a view and editor for all kinds of stored keys. I don’t think its target audience ever were intended to be some random macOS users. That’s just not the target group. It‘s about power users that need to access or store all kinds of keys.
Chrome used to be tied into Keychain but they went their own way a long time ago, which is a damn shame.
That policy has really killed a lot of functionality on macOS. I suspect it will cause fiction on iOS when the EU forces them to allow alternative install sources.
Personally, it grates me when Apple cripples functionality this way to try to keep us stuck in their platform. Can't use Firefox with Keychain. You can only view your current Apple Card balance on an iOS device -- not even a macOS device. At the end of the day, I hate being manipulated so much that it actually pushes me away from the platform to see this scummy behavior.
Most macOS users don't use the app store. So directing folks there can be annoying for users, or even cause problems if they aren't signed into iCloud.
They'd likely end up with either an old version on the app store at all times, or with a massive, unpredictable day-or-week-long delay waiting for Apple's reviews before every release. Small wonder they don't bother.
That sounds especially annoying. An iPad next to you can auto-config itself as the umpteenth monitor of a Mac, but macOS can't pull Apple Card balance from your nearby iPhone?
Also, on iPhone it's ok-ish but on Mac the experience is a subpar too: Keychain, the app you use to view your passwords, feels like a 90s Visual Basic application. Plus you can't organize your accounts, and even if you prefix them to "sort by name", the special name you give is lost after using it.
On the other hand, I already have other Apple cloud stuff and kinda trust them, so I suffer through it. And other password managers aren't anything to write home about either to make me change :/
The other two have even less organization functionality than Keychain Access, so this probably doesn’t help you, but the blog post was talking about the System Settings version so I wanted to point it out.
However now that comex pointed me to the Password in the "System Settings" app, I at least can use it and it's fine if Keychain is left as is.
Huh, I never realised Keychain showed iCloud Passwords. I always just use Safari (which is inconvenient in its own way admittedly).
I honestly didn't know that was possible before that extension.
"DerpCo Derpolizer would like to access your stored cookies. This allows us to automatically log into your DerpCo account!" and then bam, they hoover up your login data in an instant and send it off as part of their telemetry.
Much better to have a system like (for example) sign in with Apple where you can easily click a button to have the system authenticate you, but no one gets access to anything without specifically asking for it.
Well, Apple Passwords on Windows is a good example of how that turns out in reality. I believe it's using WinUI. While the performance is nice, the experience is entirely unlike what you get on Mac and winds up making you wish you were using another service entirely.
I doubt they’d do much better using electron: I think their development model is that if it isn’t on one of their platforms, they pump out a minimum-effort, low quality app. I’d guess that electron ones would be just as clunky, except with a significantly higher memory and CPU footprint.
The root of the problem for Apple is that they cannot get away with doing what they used to in the past, they already have a plethora of platforms within their own umbrella to support, adding Windows native to the mix seems to result in maybe a handful of developers taking on enormous burdens by trying to catch up to their expected Mac apps.
If Apple were to seriously put its weight behind a cross-platform toolkit, this might change, especially as they want their services to grow. It's the very reason why their main service competitors can even compete.
But I agree that if they were to suddenly switch to Electron without a care it wouldn't turn out well, but likely have a better end user experience than their current reveals.
For Safari Windows they ported a portion of Cocoa.
Having an internal Windows version of SwiftUI would not be unthinkable!
No they weren't. They were notoriously awful. Apple resorted to bundling Safari with QuickTime to try to get you to use it but everyone still hated it.
300GB library around that time with no issue at all. Smart Playlists made all other players obsolete for me.
https://www.stone.com/dev/StonesThrow2/OneFoxTwoFox.html
Basically, it was called Yellowbox, but it didn’t officially survive the release of Mac OS X IIRC. But Apple was at least still using parts of it for some Windows ports back then I believe.
If you were a Windows user, why would you want an app that acts like a Mac app? Surely the benefit of having a dedicated Windows app is that the experience should be like other Windows apps.
If I'm using Spotify, I don't think "oh this doesn't use windows navigation component from winUI", I immediately know where the genre categories are because I've already used it on android or linux and expect it to be there. I know exactly how to add a song to my library, to shift around playlists, to manage folders, everything is as I learned it on [other platform].
Design development becomes this duplicated burden where every feature now has to go through the ringer twice (or more) to fit native components for their respective platforms. When you hit limitations on those native components, you're now having to make the decision to either hold back the feature entirely, or create fragile workarounds.
In an alternate timeline native components would have had far greater appeal, where people actually hate and boycott apps designed otherwise. But we don't. Even on iOS or mac, people regularly rely on apps that only vaguely interpret their native components. The situation is even worse on windows past 7, where the idea of a "windows app" is so jumbled there is nothing to "expect" from the experience - which is actually part of why I think these unified app designs have really taken off.
We're either very different people or we have different use cases :) It immediately feels jarring to me to be using macOS and suddenly presented with a non-native UI. But I only ever use macOS on the desktop, so I don't have this cross-platform issue. What I find strange is, I would have thought that was the 99% common case — it seems strange to me to optimise for individuals using multiple OSes rather than multiple apps on one OS.
> Design development becomes this duplicated burden
That sounds like an OS flaw if true. Of course, I accept that some design will be necessary, even with the finest SDKs available to humanity, but it should be so burdensome that going non-native is seen as the solution.
> Even on iOS or mac, people regularly rely on apps that only vaguely interpret their native components.
You're totally right. Every now and again, I say to myself "I really must use Safari for the 'more native' experience", but I always come running straight back to Chrome again.
> The situation is even worse on windows
This was one of the things I liked best about macOS when I first migrated — everything was so consistent, things didn't visually clash, etc. I still get the impression it's better on macOS, but heck, it's definitely not as good as it used to be.
Have you given Arc Browser a shot yet? It feels pretty great. Feels designed for Mac and has its own design language at the same time.
No, it's not. I alternate between Safari, Firefox, and Duck. If a password I use in Safari isn't stored in Firefox, I copy it from the Keychain program and paste it into Firefox. Firefox then asks to save it. No problem.
The GUI is buried in System Settings.
It has its own program. /Applications/Utilities/Keychain Access
Woah that's the same way I used password managers 10 years ago. Even back then it was considered barbaric. I had no idea people still lived like that.
The previous commenter said passwords were "unavailable" outside of Safari. I merely demonstrated that his statement was false.
Personally, I was taught to care about the future.
(e.g. Netscape vs Microsoft Internet Explorer)
EDIT: why the downvotes without a reply? If you don't agree, why not just respond why so that a health dialogue can occur.
Safari > Preferences > Passwords
Would love to have iCloud Keychain in other browsers, though.
On Mac, at any time, type: command-space passw <return>
On iOS tap <search> on any home screen, type passw, tap suggested result
https://www.icloud.com/shortcuts/71fea01c333341878e4355df52c...
For macOS, you can make the same shortcut open `/Library/Apple/System/Library/CoreServices/SafariSupport.bundle/Contents/PreferencePanes/Passwords.prefPane`.
A single shortcut can be used to accomplish this, using the OS check and an `if` condition.
Then add the shortcut to the home screen as an icon and it’ll also show up in Spotlight search.
That said, this also proves that for non-power users: it needs an app and it needs integration with other browsers if it wants to be as easy to use (for most people) as the popular password managers.
I just tapped the "search" field on the home screen, and typed "passw".
"Top Hit": A store link to the LastPass password manager (which I do not and have never used—the button has the text "get", it's not installed and doesn't have the cloud-icon for previously-installed apps)
From there, it's three suggested Siri web searches: "passwords", "password manager", and "password generator"
Then two safari-iconed links (I assume these would search with my default search engine in safari?): "passwords on iphone" and "passew"
Searching inside the "settings" app is only marginally better. It's all much, much worse than it was a few iOS releases ago.
Having to access something via a search incantation (or, alternatively, a ton of clicks) is not at all easily accessible. It’s buried alright.
Obviously you can find pretty much anything on macOS and iOS via search. That‘s how it‘s should be. But that doesn’t make things accessible or even just visible.
Agree the UI is terrible in iOS.
As for TOTP, if I lose my phone I don't know what will happen.
Most apps can use passwords from Chrome just fine, and you can also quickly open the native passwords window when encountering a password field using the key icon.
For TOTP, use apps like Authy which can be installed and used from multiple devices.
Like a lot of other Apple stuff, I'm only able to use it because I don't use anything non-Apple for anything "serious" that involves a GUI. Windows is for gaming, Linux is my file storage and docker-service-running server that I only interact with over SSH and Web. Ditto Notes, all their Office-type programs, et c. I'd probably be on a lot more Google shit if I needed more cross-platform access to that stuff.
> 2. On Mac it's tied specifically to Safari. I use Safari a lot but if I'm in a different browser then my passwords are unavailable.
Yeah, this is super fucking weird. You'd think this would be connected in some fashion to "keychain", but nope.
> 3. The GUI is buried in System Settings. Heaven forbid you need search it's only a simple 37 clicks away!
IDGAF about clicks because I search my way to everything in Apple's settings—what does bother me is that they've made search worse in the last couple versions of iOS, and that if I type "pass" in search, "Passwords" isn't even visible on the list yet. I can get all the way to "password" and it's still the fourth entry. The fucking name of the screen is "passwords"! I shouldn't have to get farther than "pas" for it to be the first entry on the list, "pass" in the worst-case! Even fully typing "passwords" still leaves it as the second entry (of three) on my device. WTF.
Other browsers used to be able to use it. I do think it’s a really thorny issue—“allow this application to access all saved passwords?” is a pretty damn scary permission to include. Up there with the “allow this application to control your computer” permission that is used for accessibility apps (which apps can abuse to read passwords, if I understand correctly).
Apple’s tradition. Make the platform more secure, add an exception for first-party apps, and let the other browsers fuck off.
I'd like to see finer granularity, perhaps multiple web password vaults and a mechanism to allow certain browsers to use certain vaults.
It might also be nice to specify which passwords could be accessed with which kind of authentication. Unfortunately the current system password dialog is easily spoofable - it really looks like a questionable javascript popup.
The above is not a critique but certainly a list of things that lead to the possibility of a repeat of the infamous Windows popup for every single action you want to do out of the box. This leads to either decision fatigue or a pre-programmed "yes, just do it" response from the vast majority of users.
I personally think it should be an all-or-nothing type of allowance for this reason. Maybe the better way would be tracking access to passwords in Keychain. ie: Chrome+Safari+Firefox have all accessed your credentials for google.com but only Safari has seen your iCloud credentials and only Chrome has seen your HN credentials.
I'm looking forward to iOS doing the same for contacts; there's no reason why WhatsApp/Telegram/etc need access to my entire address book if I just want to call Steve.
Why not? It works fine for Little Snitch.
And here it would be even less prompts, as it would just be every website I visit && have an login account at.
This is pretty much exactly how macOS Safari prompts, and has for several years, at least in Touch ID scenarios. It shows a suggested username/identity with a Touch ID icon next to it, presented just like a normal autofill suggestion otherwise.
The per-site prompt and the inclusion of username/identity are really good signals, and feel like they reinforce the opposite of Windows UAC. They definitely gate access in a similarly repetitive way which encourages repetitive acceptance. But they demonstrate prior authorization that would have to be manual at least once at some point before the prompt, and you won’t be promoted the same way for sites you didn’t manually authorize first.
It’s a good enough signal that I generally use it as my first line of defense against phishing/domain spoofing. If I don’t get promoted for credentials for a service I expect to have an account with, I’m immediately suspicious. That doesn’t mean I automatically trust or distrust on that alone, but it’s a pretty decent sniff test.
It just needs to tell the password "hey there's a password on wellsfargo.com" and then the password manager asks the user if they want to use the password. And maybe give access to all passwords.
IDK, what does safari do?
If you use Chrome Sync with passwords on macOS, Chrome actually stores the decryption key in the macOS keychain. Just open Keychain.app (/Applications/Utilities/Keychain Access.app) and search for "Chrome Safe Storage" to find it. That's the decryption key for the actual encrypted password/sync data stored elsewhere. (So not possible to access Chrome passwords from the Keychain directly)
Safari Passwords (Apple's password manager) also stores passwords in the Keychain as individual entries and you can access them via Keychain.app. Unfortunately, since they’re part of the iCloud Keychain not the local login Keychain, they appear to be inaccessible with the `security` CLI tool which fails in an obtuse way.
Apple has no such problem since they don’t have other OEMs.
Same deal with why Google got in trouble with the play store.
Weird. "pas" and it was top of the list for me.
Also, Spotlight is bizarrely slow finding even local apps and things like Passwords. WTF
It used to show up for me after a couple letters, in the settings app, until a few iOS versions ago, IIRC.
Which is unfortunate, because it's not very good at it.
But yes, passwords is annoying. You can use them on chrome on windows but not on MacOS, and on Windows it doesn't work on anything but chrome. Speaking of gaming, game launchers on windows can't get passwords from Apple and also seem to log me out all the time, so I have to revert to using my phone to see my password and manually type it in.
> Yeah, this is super fucking weird. You'd think this would be connected in some fashion to "keychain", but nope
No it's not. I don't want some exotic product connect to a domain I have passwords in and prompting me for access. The password should be tied to the product you used to login with.
This is a misunderstanding of keychain vs. lastpass. One is designed to remember "safari passwords" or any swift/cocoa application implementing keychain. One key feature is: once stored in Keychain this information is only available to your app, other apps can't see it.
Lastpass and other similar products are designed as a data warehouse / vault for you security items. From there, plugins in browsers etc. can take over.
I will totally agree with the fact that the GUI is frustrating at best.
It probably very much is. But Google would never add Keychain integration when they want to push you to their own password manager within Chrome
So OP disagree that it's even a good product if you are 100% Mac, but are suggesting the functionality is all there, it just needs an actually designed UI/UX.
And/But your #2 sounds pretty terrible to me too!
It does not sound like a good product at all.
#!/usr/bin/osascript
tell application "Safari"
activate
end tell
tell application "System Events"
keystroke "," using {command down}
set pass_button to (button "Passwords" of toolbar 1 of window 1 of application process "Safari")
click pass_button
end tellBut I like it overall. Even though I use multiple browsers, I don't mind treating Keychain as the master DB and occasionally copying passwords out of it. Part of this is because I use Safari exclusively for the extra important things like my bank.
This has been the Apple way since the 1980's
I just learned that this GUI exists. I have been using /System/Applications/Utilities/Keychain Access.app for years to deal with passwords.
I use 100% ma except for gaming. However, I use other browsers as well, so the coupling to Safari is a deal breaker.
https://www.icloud.com/shortcuts/22133925f3e34579b22951d6593...
That was biggest deal killer for me.
For work, I use chrome and chrome password management because my company uses gmail.
On iOS you can ask Siri "show my passwords". Doesn't seem to work on MacOS though.
I do: Cmd+space > "keychain" > Enter. Still not ideal but it's the fastest method I know. What do you mean, i.e. how do you access the GUI from the system settings? I tried finding keychain there but couldn't figure out where it is.
the short of it: It's inelegant, there's bugs, the UI is half-assed and some aspects are straight hostile (default widgets etc.). But it's an actual generic computer. Most task you assume you could do with a computer, there will be a way to do it.
It might take some efforts to get to a decent setup, but the walled garden was also a PITA, so all in all, I felt my time is better invested in making windows a nice place than the endless fighting of Apple on iOS.
As a halo effect, I'm kinda thinking about moving to Windows on my main computer as well on the next refresh cycle...not fully decided, but that feels like a viable option.
Ditto. Why do I have to replace my Windows login password with a "PIN" code that's the same as the iCloud Keychain PIN !? That's super weird!
1Password is a life-saver in this regards. All my kids have their own vaults but for the little ones I have them use a shared vault between my wife and me so we have access to their passwords. I can also easily share passwords for services like Netflix so the kids don’t have to bug me.
It has been great for teaching kids about password hygiene (what makes for a good password) and management (don’t reuse passwords!).
And it being cross-platform is great for my older kids with gaming PCs.
Also, I very much doubt if I later change the password I shared via Airdrop that it will update on the other person’s device… which is half the point.
[1]: https://support.apple.com/guide/iphone/share-passkeys-passwo...
Shared vault FTW!
I needed to share my Netflix password back in the day. My random alphanumerical 32-character password with special characters drove my family up the wall though. But in general, passwords are for personal use only.
Self-hosting is great, for as long as you're around to provide support.
No, and it's equally bizarre to me that I can't share selected Contacts with my Family account. It would make keeping track of, say, the details of my kids' friends' parents.
I don’t like shared passwords although if I really had to, I would just enter it once and let iCloud save it to their account. Stinks if I have to change the password, but I almost never change passwords.
1Password with a 'parents vault' that my wife and I share has been a life changer for coordinating family access to important accounts AND ensuring solid passwords are being used.
Apple’s implementation, for example, starts a timer that will eventually nuke the account, and it doesn’t provide access to end-to-end encrypted data. That data specifically includes iCloud Keychain, which many people use to store their credentials.
I understand the privacy reasons for that, but when we die we are leaving behind increasingly large or complicated estates of accounts, services, apps, and devices with various and sometimes unpredictable safeguards. Having a loved ones actual credentials has been invaluable every time I’ve managed an estate.
I absolutely understand what you’re saying and I don’t necessarily disagree with it. But break glass access to credentials has proven important in my experience. Especially where continuity of that access is relied upon by others.
This is much more reliable and durable than having 1Password still be around when I need it.
No, and the article specifically discusses that use case and the fact that iCloud keychain doesn't support it.
Really? My Linux devices? Android? Windows? I don't think so.
I recommend considering one of the most important features of a password manager is that it doesn't force you to use a single manufacturer's products forever. Even if you swear undying fealty to Apple (or anyone else) today, you might change your mind in the future. 1Password, Bitwarden, and others allow me to switch PC manufacturer, phone manufacturer, browser, and so on.
I can't tell you how many people used to think "Internet Explorer is popular, it'll always be the one and only browser". That did not end well.
Changing my mind is easy enough: I can export my iCloud passwords to a csv file, and I've done this to transfer a bunch of passwords to Firefox Linux desktop.
I'll tell you something though: If Bitwarden leaked passwords nothing would happen because America has very weak consumer protections, but if Google or Apple leaked passwords, they'd be hit in every EU member state for GDPR.
Some of these things are outside of my control, and using a password manager is too useful that I think it's worth a little risk, but I can't justify trusting any company unless they've got some skin in the game, and Bitwarden specifically wants to disclaim all liabilities? AgileBits thankfully is in Canada and you can at least sue them for what you've paid them in six months, but I personally have passwords more important than that. Surely there's someone else you could recommend?
And I disagree: I think everyone who has been harmed by another wants the ability to have their story heard by a judge and jury and be cured by the law. Maybe they would prefer to not be hurt in the first place, but as you point out with LastPass, they may not have that option.
What we can choose is the jurisdiction in which we trade, and I would recommend people spend less time navel-gazing and more time thinking about what they can be doing to make things better for themselves.
I use Chrome's built-in password manager. I always set up website security questions with gibberish answers. I wish Chrome would give me a field to store those answers. Or, better yet, treat them like password fields and autofill them.
Apple is, to this day, largely unable to recognize that there is a world outside their beautiful dystopian garden. I’m sure they’re drooling about making the MacBooks run iOS so you can’t use any software that hasn’t been scanned and approved. When that day comes, I’m out for good.
Hot take , but … I like the lack of integration in other operating systems/ browsers.
I see my phone as a Secure Enclave, and my passwords should be disconnected from potentially insecure systems. I see the phone as those keychain one time passwords where you have to press a physical button to get a key.
Is it inconvenient to get a password, yes. But it offers the piece of mind that I only have to worry about iPhone/Apple exploits, instead of chrome+firefox+windows+Linux+Apple+iphone.
I don’t think in this case Apple is not doing the integration because of this security feature, but I think it is a feature non the less. Of course you can always choose not to install the extensions even if they existed, but the point is that if they existed it would lower security.
Not saying Apple is doing that now, but I imagine it's not outside the realm of possibility.
Also I have recovery keys for the more important accounts printed and stored in a safe box.
But anyway, somebody could cut off your access to Dropbox, but it’s less of an issues since you have a backup.
Which I'm glad to know you can at least do with Keychain [1], although I use Bitwarden myself.
[1] https://support.apple.com/guide/keychain-access/import-and-e...
It’s useful even in non-multi-device scenarios.
What is the other one doing in the gym, unprotected?
Oh, they're stored online? There goes your entire "secure enclave" argument ;-)
I've been using KeePass apps (MacPass on macOS, KeePassium no iOS), with a different, unique master password, unlogged by default on iPhone, plus DB locks automatically after 10 minutes of inactivity.
Maybe I'm way off, but it seems safer to me.
[1] https://www.wsj.com/articles/apple-iphone-security-theft-pas...
I recently saw it with my own eyes as a family member was able to reset their iCloud password and gain full access to their account on a new device, including iCloud Keychain, using nothing but their iPad and the corresponding unlocking code. No iCloud password, no SMS-2FA (not that it would help much in the case of a stolen iPhone), nothing else.
Would someone need to steal two of your devices ?
I was under the assumption that you need to be logged in with touchid/faceid/pin code to get the unlock code
They then have everything they need to take over your iCloud account (kicking you out of it in the process by resetting all other devices capable of resetting it) and can see all your passwords stored in it, as well as use all of your WebAuthN passkeys.
I'm not sure if having a recovery code would improve that situation, but I'd guess that many people don't.
Hard to mitigate somebody looking over your shoulder, this is the case with most password managers, but I understand why this is a more likely scenario.
If somebody watches me enter my passcode and then rips the device out of my hands and runs off with it (assuming the password manager is not open), they now have access to most of the content on my phone, but importantly not the parts protected by Face ID, which includes the password manager.
If I had used Apple's password manager instead, they'd be able to recover all passwords (using the tactics described above or simply enrolling their own face in Face ID, which is possible using only the passcode).
Some apps don't, and some even react really poorly to a change of the biometric set (i.e. crashing at every Face ID use with no way to reset other than reinstalling), so I'm also not too keen on testing this on my main device.
One thing that surprised me during my limited testing was that Apple apparently doesn't make use of this capability for storing the "encrypted notes" passphrase, which effectively also reduces the security of that to that of the device passcode.
[1] https://developer.apple.com/documentation/security/secaccess...
If you have two accounts (let's say a personal one and work/family/org one), getting passwords for the second account will just be a PITA.
Same issue of course if you need someone else's password (e.g. your spouse's hotel reservation account's password)
Trying to work this around means you'll either be asking people's passwords other the phone or other means, or you'll often switch between accounts and will want lower security on the account themselves as the identification process get old very quick. Basically, these limitations are not without impact on security and how people will deal with them.
And 1Password is part of that too: https://blog.1password.com/1password-is-joining-the-fido-all...
I think that ultimately a password tool needs to be available on multiple platforms, like 1Password. Having it just be on Apple stuff just isn't gonna work for the many Windows and Linux machines I begrudgingly have to interact with.
You want to clear your Resident Key for a website on Windows? Command-line.
While I'm not sure how they've integrated it so far, I imagine browsers will either implement a plugin API for extensions to handle passkeys, or 1p can override the webauthn api and fallback to the browser when a website is authenticating.
She uses it to generate her passwords and fill-in within Safari which is great!
But there's no "Passwords" app, and she didn't know to go into Settings to reference a password when Safari doesn't recognize a password field (probably the website's fault).
2FA is also a confusing experience, but 2FA is also just confusing enough for her where Apple isn't really the problem here.
It's called Keychain Access.
Secure notes, your own signing certificates, keys, root CAs, and specific self signed certs you've accepted for SSL.
This will then show up in the launchpad. https://i.imgur.com/IRPOMC5.png
Searching for 'pass' in Spotlight does bring up Keychain access - as that's in the apps list of Keywords... however the list of apps is way down on the scrolling https://i.imgur.com/KFUC0G0.png - it found 'password' as a string in 100 python files that I had to scroll through first.
Sorry, but that also doesn't mean anything to the average user. If anything it's made it more complicated for them—they will remember to type in "key" before they learn how to make an alias
That I don't have an issue with the word "keychain" doesn't mean it's not bad UX for the average Mac OS user
If you do control-space (to bring up spotlight) and type in password, what do you want it to do and what is missing?
My wife asks me weekly "honey, what's that word I gotta type to see my passwords again?"
The thing is, its the 3rd one down.
MacOS has both Keychain Access as a standalone app, and Passwords as a section in your settings. The latter is dedicated to purely passwords that you, as the user, make. Keychain Access also contains passwords for Wi-Fi and other systems.
https://rmondello.com/passwords-shortcut/
You should be add this to home-screen like an app. Should make it a bit easier open passwords.
Every time it asked me to either "confirm on your iPad" (I have 3 of those around the house) or "confirm on your iPhone" (I have 0 of those) I was ready to hurl shit. SMS option buried in some dark pattern, of course.
If these companies want to encroach in the secrets management space they really need to hire more qa and test more than a single happy path. The number of failure modes in these systems is astonishing for the billions of dollars these companies can throw at the problem.
As with all things apple when you buy in you get the best experience. That feature on AppleTV works really well with an Apple Watch.
Personally, I was a fan of Apple laptops between something like 2010 - 2015, but after that I just couldn't deal with it anymore, as I had a Android phone and nothing else Apple.
Fast forward to 2019, Apple finally releases a phone that fits in my tiny hands, so I get a iPhone 12 Mini, thinking that the CarPlay experience will be loads better than Android Auto on a measly Moto G.
But holy smokes if I wasn't wrong, CarPlay is a UX disaster and I can't wait for the iPhone to break somehow or get too slow because of OS upgrades, so I can justify buying a new phone again.
Just the simple fact that a phone calls covers the entire screen (which I use for GPS) seems like such a simple use case that they somehow missed, that I just wanna bin the entire system and I'll never buy Apple hardware for daily use again.
I still have to use Apple laptops for software I release, but every time, I'm reminded how great the UX used to be, but how far they have fallen. Really sad to see. Windows is no better either, each version gets worse and worse...
I'm pretty happy with 1Password - it does all of the things mentioned in this article with more platform support
All you need to do is connect the AirPods to an iCloud-enrolled Apple device, and it will automatically connect to that iCloud account.
Oh, but it's not any iCloud-enrolled device, it must be an iOS device. Connecting them to my MacBook didn't do anything.
I went into the Apple Store to ask for a solution to that problem. They legitimately asked me why I'm buying AirPods if I don't have an iPhone -- they're called Air Pods after all... Anyway, their proposed solution was for me to buy a refurbished iPad for $450 to connect the AirPods to my iCloud.
Currently test-driving a smaller alternative with a one-time payment.
I've been paying for 1Password for a while, but boy that electron app they rolled out with v8 is a clunker… will probably keep paying so long as 1Password 7 works but after that I'm gonna have to figure something else out.
[1]: https://steptwo.app
It shouldn't be something people manage, hassle, or worry over. They likely want people to just be able to open their phones and have it uniquely identify them seamlessly across a variety of sites.
Unfortunately, they're not quite there yet.
I think you're right. Ventura's Passwords Settings shows that they're in transition away from the archaic Keychain app to something. My guess is that they're skating to where the puck will be in 2025 when Passkeys are universally supported, and for most use cases auth will be automatic.
Maybe they don’t want to promote their own too heavily, to allow 1Password to take on the organizational risk of running a password manager? (For context, think about your current view of lastpass vs how you felt about it a year before their leak). Maybe the internal password management functionality is better suited to orgs which restrict third party apps?
I haven't noticed even minimal credential sharing facilities in keychain.
But multiple vaults and vault sharing - no such luck. I don't think they want to deal with the UX confusion of it, especially since that confusion could lead to someone getting locked out of things.
Apple is the only one of those three that restricts their software to hardware that only they sell. So in that case I do understand your position.
Yep, they’re allowed to run on Chrome, that’s Google’s platform.
Good luck using your Chrome/Google passwords outside Chrome/Google apps.
Firefox at least does (or used to) offer a Lockbox app to use the password on your phone.
It matters to me because I use Firefox and Chrome on my work desktop, Safari and Firefox on my personal desktop, and Safari on my phone. And I want the ability to switch browser easily.
Same goes for Apple passwords, I still use Windows for some games, and I want to access my passwords easily.
So here I am using Safari on my computer and phone.
Before, I could ask on an unlocked phone to “show me my password for GitHub” and Siri would open the settings app with the password list and show the GH credentials. Now (since iOS 16?) Siri just refuses to do any request that contains ‘password’.
prefs:root=PASSWORDS
You'll want to set up Siri separately as part of it, but you can definitely do that with Shortcuts.
What I described didn’t need a shortcut before. It was a vanilla iOS feature. I assume it went away for privacy reasons with one of the OS updates. And hoped there’d be a setting to get it back.
Would like to see them in the process of transitioning it away from settings, also include the ability to change the name of the entries. Multiple URLs per login would be great too (or even a linking of separate entries). Think these are the biggest things keeping many general users still relying on the likes of 1Password/Bitwarden, which is where I disagree with the writer here, I think third party password tools should be replaced by sane defaults as soon as possible outside of niche cases.
Because without that everything on the software side by Apple will just remain glorified things that the fans keep bleating about - “just works”, “is perfect”, “just what I need”.
For heaven’s sake Apple does a shoddy job of syncing et cetera and obscures it from the user in the guise of usability and that “Apple knows what users need to do”, not what they want.
Works with touchID on my MacBook, uses KeePass so it's easy to migrate if needed, and the killer feature for me was being able to sync it to iCloud so you can use it across devices. Even better if you enable E2E encryption on your iCloud https://support.apple.com/en-au/HT212520
Still if you need a multi-platform password manager that performs well on Apple devices there's nothing I can recommend since you can just use .kdbx tools on other platforms and strongbox itself has highly reliable multi-cloud sync, extremely fast input of secrets, a better security model than keychain itself has, and even has MacOS Chrome support (abliet hacky support) if you feel like trusting the plugin. It makes Bitwarden and other Keepass clients feel clunky in comparison.
1)they don’t do cross platform software well so they would never make a windows app, chrome extension, android integration etc. It’s either all or nothing which I would never buy into (even as an iPhone and mbp user)
2) there are actually a ton of use cases here that make the software actually very complex and high stakes. I’d wager the pros don’t outweigh the cons. Also apple isn’t known for complex software with niche use cases. Honestly their current safari/iphone password manager is trash
They do a few things well and rely on lock-in and ecosystem
So if someone sees your PIN code, they can not only unlock your phone, they can get all of your passwords and change those passwords very quickly.
I enjoy 1Password being separate in that regard, and I would really like it if the iOS keychain would let you set a separate password in that respect.
The discrepancy between the "Passwords" and "Keychain Access" app. Passwords manages 2FA codes whereas Keychain doesn't. Keychain allows you to add another URL for a password whereas Passwords doesn't. The latter issue often leads to headaches dealing with passwords when the URL of the login page is not the same as the URL for the second part of the 2FA.
An example that became unnecessarily frustrating. Heroku makes you login to dashboard.heroku.com but the 2FA code needs to be filled in at a salesforce URL. Since I can't add this salesforce URL to the existing password (+ 2FA code) I have to manually copy the code. The shortest routine I found for that is:
1. CMD+Space. 2. Enter "passw". 3. Click on the search bar. 4. Enter "Heroku". 5. Click on the password. 6. Go back to the web page to enter the displayed code.
Simply having the option to add another URL (which was possible in Keychain Access) would solve this entire issue...
IMO the worst part about apple keychain is they can't be used with Chrome (the most common browser for mac!)
Chrome could access those natively on Mac, or use the keychain as the native backing store, from what I can tell.
The US government web analytics (https://analytics.usa.gov/data/), which seems like a reasonable source for general usage in the US, show Safari substantially ahead of Chrome on Mac.
Have you seen any sources that show Chrome ahead of Safari on Mac for a general audience?
https://chrome.google.com/webstore/detail/icloud-passwords/p...
It's a feature, not a product, doesn't do everything that Keychain Access does in macOS, and doesn't need (or deserve) to be in your face all the time.
Do keyboards/wallpaper/voip apps/whatever really need to have their own app icon on your homescreen? Probably not, but Apple's conditioned us over the course of 15 years that all apps have icons you can see - a view at odds with things like Fantastical and SwitchGlass, which are really "apps that run in your menubar" and can be used without a Dock icon at all.
iOS doesn't have the concept of "Utilities" within "/Applications" like macOS does, but maybe it needs to in order to address this class of app which has such a specific focus.
After 15 years, are we at a point where some of the early affordances aren't neccessary anymore?
Passwords are my ID, sometimes I have to enter them onto another computer or app or just share them with someone; I shouldn’t need to hunt my ID in the trunk of my car.
Keychain Access did this right decades ago, so there’s some logic behind it. The issue is that the app is not built for this decade and its UI is lacking.
I get nervous at how easy it is to compromise all passwords:
1. Give someone your phone passcode, they can change apple account password. P0wned
2. Have iCloud Keychain on laptop… other user account resets password on account. (Or use it on work computer without realizing)
3.
Might also limit password changes but unsure.
To get my Credit Card details, I need to go Settings > Safari > AutoFill > Saved Credit Cards.
To get 2FA / Password details, I need to go Settings > Passwords.
In a lot of cases, they auto-fill without issue. But to manage these is a bit of a flimsy process.
Like I'm in serious need of a highly secure cross browser/cross platform password solution.
On my phone, everything is fine. But I use Chrome on MacOS and my Windows desktop. Chrome used to use Keychain on MacOS, but some years back Google changed the product to tie into their own user accounts. I refuse to sign into a browser itself just to use the web.
The iCloud password extension for Windows (chrome/edge) absolutely DOES NOT WORK. I have tried getting it to work for the better part of a year. Finally gave up and removed the useless thing.
I probably dumbly still trust Apple's security policies and would prefer to use Keychain as my fits-all-sizes security tool, but the combo of product incompatibilities and non-working Apple authored software makes it impossible.
Might not affect that many people. But it would surely limit choice for those who don't even know about the lock-in later in their lives.
This is what Apple probably wants to avoid. They won't be allowed to play a "Safari" this time (i.e. all password managers are allowed, as long as they are a frontend to our own password manager).
Also, having the password manager as a separate app, it is likely they will be asked to provide a standalone password migration API for third party password managers. This would make switching to another ecosystem trivial for moms & pops, who currently need to deal with CSV import & export* if they want to move their passwords out of iCloud.
* Not sure what the situation is ATM, but a few years back exporting passwords from iCloud was not directly supported. I had to run a third-party AppleScript script to generate a CSV to import in another password manager.
https://support.apple.com/en-ca/guide/iphone/ipha6173c19f/io...
1. It really hates storing anything but website passwords. I have servers with ssh login/passwords. I have bank cards with cvv and pins. I have phones with pins. WiFi passwords. And other things not fitting to website/username/password.
2. Not enough fields. I'm ascetic when it comes to storing passwords, but it doesn't even have "notes" field.
So experience is subpar. It's possible to emulate some things, but in the end I decided to go with StrongBox. It's not ideal, I don't like UI, but it has all the functions I need. I also like KeePassium, but it's missing sync and mac app.
I know that Apple KeyChain has secure notes, but those are not accessible on iPhone, AFAIK.
Unfortunately I'm not an ios dev and wonder if it might even be possible to do the same on ios? I believe there is an API so you can write a password manager (1password et al use that) but can you get to the secure system services?
Edit: I now see who wrote this blog post. Were it straightforward on ios he probably would have said so.
You can’t access passwords stored by another app (app identifiers appeared to be globally unique, e.g. com.apple.Safari). There was an additional hurdle to access/store items in the iCloud keychain, though I forget what exactly.
This restriction makes sense.
> PPS: I dream of a future where Passkeys could make the password manager extinct. But it’ll take time…
Passkeys even more so need more of a "curated app experience" to work right, cross platform. Ironically, it is my impression that preparing for Passkeys is why Apple finally added that password explorer to Windows' weird iCloud "control panel". (For a long time, the only way to use iCloud passwords on Windows was the awful Edge/Chrome integration.)
It would be great to have a nice UI for managing passwords, 2FA codes, etc. Add password sharing over iCloud and it could be a game changer!
[1]: https://www.macrumors.com/2023/03/26/ios-17-to-provide-sever...
Dashboard/status
- I have a smart lock, and they have their own app, where all it really does is show the current status of the lock and let me toggle it. There are quite a few apps like this. It'd be nice if they could all be condensed into a dashboard/status app that could just tweak values and show current status. Apple Home attempts to do some of this.
Notifications
- It'd be nice if there was a notifications app, and I could set most of my apps to deliver their notifications to that app, instead of me directly. This would reduce notification overload and distraction.
In the notifications settings you create at least one Scheduled Notification Summary. I've currently got ones setup roughly every four hours during "core daylight hours" for me, plus I enable the "preview option" to read the next summary early if I need to. Then you add as many apps as you want to the Notification Summaries. All of the notifications for those apps during each time period get rolled up into a single Summary object in your notifications, only give a notification alert once for the entire group of them (at the scheduled time), and don't cause Watch notifications (if that's a distraction/overload you especially juggle as I do).
At this point I've even got all my email notifications going into Summaries (which is why I turned on the preview for the next summary if I feel like I need a quick glance at recent email subject lines without opening my email app up).
It is such a useful tool and not a lot of iOS users discover it in the settings. May also be an indicator that it could use its own app because discovery in the Settings app itself is hard. Maybe the Settings app is just doing too many things now and needs some sort of reorg or something.
I'm not sure if the reference here is to Keychain's "Secure Notes" or the "comments" field associated with password items. If the latter, I've found (at least on older versions of OS X/macOS) that when Safari updates the value of a changed password, it deletes the comments! I used the comment field to add the (random) answers to security questions, and got burned on a couple of sites when I've needed to do an account reset and lost those answers.
It doesn't change a password, it creates a new one.
This means if you somehow mangle saving the password (you thought you updated it, but didn't) the older password is still in your keychain with the older note and it can still be retrieved.
I think you're overestimating how much the average person thinks or cares about their computing platforms. They want something that works and gets out of the way, and to that end having everything come from one company is a feature, not a bug.
I mean I consider myself a power user and I still use iCloud Keychain purely because I was already using Safari when it launched, so it already had all my passwords. I recognise the advantages of third-party offerings, but to me they're not enough to bother moving all my stuff over.
Similarly I still use a third-party 2FA app because I was using it before Apple added it into iCloud Keychain (and also because the third-party app has an Apple Watch app and I've grown accustomed to reading the codes off my wrist).
There doesn’t currently seem to be a way to set up only the 2FA code for a site.
Of course, nothing is stopping you from saving a bogus password either.
Many password breaches are caused by technical lapses on the part of a platform, where password complexity often becomes irrelevant. Your password gets hovered up along with everyone else’s and eventually gets decrypted, and tried en masse against other platforms. In this scenario, even a simple pattern for passwords is probably enough to prevent the problem from spreading, as long as it’s not too obvious.
The other way passwords often get compromised is from someone looking over your shoulder or key logging, infrared on PIN pads, etc. In this scenario, your system is WAY, WAY worse, since one password unlocks the kingdom, and that password is frequently being used.
As it stands, if someone peeks over my shoulder and discovers my phone password, then steals my phone, it’s damaging but not game over. They can’t access any websites.
If I allow my phone password to be the only gatekeeper to access everything, IMO that’s lousy security.
- BitWarden - for personal use, stores 2FAs and acts as an iOS password source. (The claimed attacks were mitigated)
- Keeper - for enterprise use, stores 2FAs and acts as an iOS password source
- Duo - for 2FA for enterprise use with backup text mechanisms. Edit: Duo's primary app mechanism is similar to Google Gmail app's mechanism of a yes/no popup to approve a 2FA request
^ The above are cross-platform and extend beyond Apple.
https://arstechnica.com/information-technology/2022/10/passk...
Overall I'm happy with my decision. I'm now even using Safari over Chrome full-time because it has the benefits 2FA autofill.
Only thing missing is a dedicated app, but I have Apple Shortcut that works well enough in the meantime.
https://developer.apple.com/documentation/authenticationserv...
For a company that markets itself as secure these are retrograde steps.
Why wont Keychain allow Firefox sync? This seems like an extremely common use case.
Apple has a long and storied history of doing almost exactly the opposite - any sufficiently popular third-party utility either gets bought and integrated (eg Workflow, Dark Sky) or Sherlocked (eg f.lux, Watson).
Apple takes a very long-term view of revenue generation, and the App Store commissions from $random_app are way less valuable to Apple than the LTV of a customer who’s locked into buying Macs and iPads because of Apple’s proprietary version of $random_app.
But I'm not ready to move my passwords and tie them to the Apple ecosystem.
1password for the win.
Chrome, Firefox, Apple, I'm sure Windows too, have all their own password managers and all of them are hard to use and expect you to only have devices in their ecosystem.
1Password is worth every penny for how well they've kept up with updating their apps and their prevalence on all platforms. And the 2FA integration is great too!
So when she logs into the device it always falls back to device passcode.
I am frustrated they won't allow you to do both bio+code, because that would prevent my kids from flashing my pilfered phone in my face to get it to unlock then running away.
Don't put all your passwords into one single software provider.
Surely passwords are security?
Keychain its current configuration is risky, given its coupled to your iPhone password which many people frequently enter in a public setting. One shoulder surf followed by a phone theft and they've unlocked everything - including your iCloud account (which you can change the password on using iPhone password only).
No you can not. On my iPhone I have to authenticate with my finger print or pin code again for the passwords.