Apple Wants to End Passwords for Everything. Here’s How It Would Work.

OfTheCross

Veteran
Bushed
Joined
Mar 17, 2013
Messages
43,350
Reputation
4,874
Daps
98,671
Reppin
Keeping my overhead low, and my understand high
Your passwords keep your money, your job and your identity safe. But you hate them, and they’re flawed. Apple Inc. AAPL -2.79%▼ is trying to get rid of them entirely.

When Apple’s latest software updates for iPhones, iPads and Macs arrive this fall, they will include a way for users to log into various online accounts without entering passwords or relying on password managers to save and fill in credentials. The technology generates unique passkeys for each app or browser-based service in the place of characters. Those passkeys, a new type of identity authentication, prompt a scan of your face or fingerprints to log you in.

Passwords have been the longtime standard for securing online accounts, but they pose security risks. Despite expert advice to create complex, unique passwords for every account, people often use the same password, get tricked into signing into fake websites that log their information, or have their account details leaked in data breaches. Password managers beef up security, but if someone gets your master password, they can access all your logins.
Apple’s passkeys—and similar efforts from other technology giants—want to address those problems and replace passwords entirely. They aim to be easier and more secure than passwords of old, Darin Adler, Apple’s vice president of internet technologies, said last week at the company’s Worldwide Developers Conference.

Each passkey is unique, so there’s no re-use of passwords. Passkeys can be used on non-Apple devices, and for both new and old accounts. Your private keys are stored on your devices—not on the servers of Apple or the app or website developers—so hackers gaining access to those servers wouldn’t find any passkeys to steal. They are also resistant to phishing since there’s no password to share.


“Passkeys are heavily obfuscated by the operating system,” said Ondrej Krehel, head of digital forensics and incident response at cybersecurity monitoring platform SecurityScorecard. “This will deter most cybercriminals, because attackers wouldn’t get anything usable.”

 

The Bilingual Gringo

Tucked in to the socks
Supporter
Joined
May 11, 2012
Messages
4,817
Reputation
935
Daps
9,458
Password managers >

I don't mind passwords at all, but Apple, Google, etc. are trying to get away from passwords as a whole.
 

null

...
Joined
Nov 12, 2014
Messages
29,628
Reputation
5,109
Daps
46,860
Reppin
UK, DE, GY, DMV
so Apple will be able to access all of your accounts :youngsabo: ? great :blessed:


no face or fingerprint ID for me thanks :camby:


and why should you trust a "password" that you cannot change easily (your face) to Apple anyway .. :hhh:
 

Vandelay

Life is absurd. Lean into it.
Joined
Apr 14, 2013
Messages
23,874
Reputation
6,100
Daps
83,886
Reppin
Phi Chi Connection
Even biometrics can be exploited, and what's worse with biometrics much like social security numbers once they have your likeness, it's not like it changes. You will look the same for decades, barring some significant facial hair changes.

Some combination of 2 factor authentication is best. It's annoying, but having to authenticate on the spot from a secondary level is best. It's hard to fake both simultaneously unless they have a personal relationship with the hacked.
 

Pressure

#PanthersPosse
Supporter
Joined
Nov 19, 2016
Messages
46,154
Reputation
6,981
Daps
146,843
Reppin
CookoutGang
Microsoft hasn't required passwords for nearly 3 years after fully implementing mfa and windows hello.

Apple doing what's already the norm, but with a lot of fanfare. :russell:
 
Top