Official Chrome extension to use iCloud Keychain Passwords
chrome.google.com
chrome.google.com
[0]: https://github.com/dedoussis/icloud-hide-my-email-browser-ex...
Bonus is that I use a separate subdomain of my custom domain for disposable email addresses which means it never fails email checks (some don't like disposable/temporary email domains).
The advantage of iCloud is that it's a domain laymen use - those same laymen the "growth & engagement" scum wants to track and spam. They can't just ban it wholesale without alienating a large chunk of their target market (and a pretty lucrative one at that, since Apple hardware is expensive).
There’s only been a handful of times I’ve used it, maybe 12? At least a few of those times it wouldn’t even let me submit it saying it was an “invalid email”. Couldn’t even get past the validation.
> humanity will go extinct March 11th, 2401
Please explain! Citation required :) /s
Microsoft, Google, Apple
I do believe Google requires Workspace to have a custom domain, though.
I suspect they validate by looking up the MX record and block it based on the entry containing simplelogin.co
A custom domain that only I use specifically for disposable emails would look indistinguishable from any other custom domain out there, and nobody else would have used it for them to even be aware of its existence.
To block it pre-emptively, they’d have to either be omniscient or block every single custom domain in existence. The former I highly doubt is the case, the latter would generally do more harm than good to them.
The alternative I currently use is letting Gmail handle the spam. I used to be big into jon-foo@jrock.us for "foo" and that sort of thing, but every address ended up on every spam list anyway, and the filtering didn't increase the signal to noise ratio.
For true throwaways I just use mailinator. If I want to receive email from someone someday, I can just create another account. If they spam me, Google will filter it out. So it goes.
Not via a chrome extension, but it’s pretty easy to generate one on any Mac (maybe even iOS?) in system settings. You can name the forwarding address to have different ones for different uses
Edit: re-read your comment and sounds like you’re already doing this manually, like me. I agree it’s a hassle and would love to see a more native UX that doesn’t involve opening system settings
There’s also this nifty shortcut that works for both iOS and macOS: https://www.icloud.com/shortcuts/6b0c16ff0dfb4814bd881112354...
I’ll never use Apple’s Hide-my-email service until they let us use it with our own domain-names. It’s my email mailbox and my dodgy account registration, not Apple’s.
Also FWIW you can use it with custom domains - I use it with fastmail and have since day one (their version of it isn’t as tightly integrated as Apple but they offer this service as well). Hope this helps!
To confirm, you're saying that Apple will generate something like "randomString@yourDomainName.com"? If so, how can I set that up? I don't see any relevant settings on my phone's iCloud settings page.
[0] https://github.com/dedoussis/icloud-hide-my-email-browser-ex...
[1] https://addons.mozilla.org/en-US/firefox/addon/icloud-hide-m...
[2] https://chrome.google.com/webstore/detail/icloud-hide-my-ema...
This is an old extension and I can tell you from personal experience, It doesn't work.
I do productivity and work stuff on my Macbook and have a Windows desktop machine for games and movies. I have tried for several years to figure out a solution that would let me use the iCloud keychain to store all u/p and let me use them across browsers and desktops.
I have tried every combination of uninstall/reinstall/change permissions etc with the extension on Windows 10 and it doesn't do anything.
Pro-tip: Don't use software by companies who explicitly hate cross-platform software when you need said software to work cross-platform.
For credentials/secrets, there are other tools that actually does a really decent job at being cross-platform (including iOS/Android). Two of these are 1Password and BitWarden (FOSS as well). I'm a happy user of the former, but lots of people (including many here on HN) sing praise about the latter.
1. https://support.apple.com/en-gb/guide/icloud-windows/icw7603...
I also prefer the native OS browser without extra reskinned chrome (not Chrome) wrapped around it.
Firefox can’t do that.
Don’t get me wrong, I like Firefox, but I trust Apple more. Also: Firefox can’t afford to say no to the FBI.
The argument though is that it's not true E2E without the secure enclave. App data can be compromised in many ways. Apple goes to incredible lengths (including burning the root key which cannot be retrieved or reset from outside the enclave into the silicon during manufacturing with no way of them being able to tell what it is) to ensure a chain of trust from the point that anything physically enters the device.
In other words, with Firefox you trust the security of your device, whereas with Apple you trust the security of their entire ecosystem. In most cases, that's probably even a good thing, but I wouldn't exactly label one as strictly better than the other in all scenarios.
https://support.apple.com/en-us/HT212520
Although, I don't think that was accurate for iCloud Keychain anyway.
It's impossible to tell, though – Apple's platform security guide has been last updated in April 2022, which predates Advanced Data Protection. (Weirdly they do mention it in the document [1], though, so the date might also be incorrect and they might have added that information since I last looked a year ago.)
At least according to [2], it seems possible to gain access to the encrypted data using the iCloud account password and the passcode/login password of one other device on the iCloud account in any case.
[1] https://help.apple.com/pdf/security/en_US/apple-platform-sec...
But iCloud access is forced to 2FA with one of your signed in devices, which requires the local password (pin, touch id, or face id, all of which never leave the enclave) to approve. There's really no way to get something covered by ADP short of physical device access + a stolen/coerced pin number.
In 50 years they really need to do a case study on what on earth Apple poured into the drinking water to provoke these kind of comparisons.
We’ve used 1Password for ages, and I still like it a lot at work, but can probably get by with the built-in tools now.
This risk is unsuitable for an application that needs to handle sensitive credentials like an encryption key for all of a person’s passwords — or the vault itself.
Also, this is why I do not trust LastPass — they don’t run a native module, so how do I know that my vault isn’t just being stored on disk?
And OpenBSD support too, while at it. (Maybe just release the source code for the native blob.)
I wonder if that's due to a technical limitation (maybe it uses an OS-native hardware secret storage mechanism that Linux does not offer), or just because Apple refuses to acknowledge the existence of Linux on the desktop.
So for now, I stick with my pass setup.
Perhaps Apple developers don't know how to write a Windows program but the macOS version will be usable.
The only issue I can find is that you can't select two or more third-party password/passkey filling apps, unless one is "iCloud Passwords & Keychain". So if your setup is 1Password for passwords and iOS for most of your Passkeys, you can do that, but hopefully you use the same third-party passkey and password implementation.
Which is to say, I doubt I'll be using it in Chrome.
So if your credentials are stored for foo.bar.com they'll be proposed on any subdomains and the naked domain of bar.com.
You can switch it to Host. That way the credentials are only proposed on on foo.bar.com but not on cuz.bar.com.
Safari doesn't do that.
--
Yes and: The Apple Passkey future can't get here soon enough.
Meanwhile, I wish Keychain allowed memo fields. Some place to record all those stupid personal security questions.
(1Password has memo fields. I switched to iCloud once I started using Apple Pay, because of integration, ubiquity.)
Also: I (officially) asked my credit union about using U2F with my account(s). No plans. This crap needs to be legislated, or some other forcing function.
iOS 17 and macOS Sonoma should have better 3rd party browser integration, certainly Chrome for now… hopefully Firefox in the near future.
https://lifehacker.com/you-can-finally-use-icloud-keychain-i...