Apple Wants to End Passwords for Everything. Here’s How It Would Work.

OfTheCross

Veteran
Joined
Mar 17, 2013
Messages
43,513
Reputation
4,969
Daps
98,960
Reppin
Keeping my overhead low, and my understand high
Your passwords keep your money, your job and your identity safe. But you hate them, and they’re flawed. Apple Inc. AAPL -2.79%▼ is trying to get rid of them entirely.

When Apple’s latest software updates for iPhones, iPads and Macs arrive this fall, they will include a way for users to log into various online accounts without entering passwords or relying on password managers to save and fill in credentials. The technology generates unique passkeys for each app or browser-based service in the place of characters. Those passkeys, a new type of identity authentication, prompt a scan of your face or fingerprints to log you in.

Passwords have been the longtime standard for securing online accounts, but they pose security risks. Despite expert advice to create complex, unique passwords for every account, people often use the same password, get tricked into signing into fake websites that log their information, or have their account details leaked in data breaches. Password managers beef up security, but if someone gets your master password, they can access all your logins.
Apple’s passkeys—and similar efforts from other technology giants—want to address those problems and replace passwords entirely. They aim to be easier and more secure than passwords of old, Darin Adler, Apple’s vice president of internet technologies, said last week at the company’s Worldwide Developers Conference.

Each passkey is unique, so there’s no re-use of passwords. Passkeys can be used on non-Apple devices, and for both new and old accounts. Your private keys are stored on your devices—not on the servers of Apple or the app or website developers—so hackers gaining access to those servers wouldn’t find any passkeys to steal. They are also resistant to phishing since there’s no password to share.


“Passkeys are heavily obfuscated by the operating system,” said Ondrej Krehel, head of digital forensics and incident response at cybersecurity monitoring platform SecurityScorecard. “This will deter most cybercriminals, because attackers wouldn’t get anything usable.”

 

The Bilingual Gringo

Tucked in to the socks
Supporter
Joined
May 11, 2012
Messages
4,855
Reputation
945
Daps
9,629
Password managers >

I don't mind passwords at all, but Apple, Google, etc. are trying to get away from passwords as a whole.
 

null

...
Joined
Nov 12, 2014
Messages
31,260
Reputation
5,478
Daps
49,098
Reppin
UK, DE, GY, DMV
so Apple will be able to access all of your accounts :youngsabo: ? great :blessed:


no face or fingerprint ID for me thanks :camby:


and why should you trust a "password" that you cannot change easily (your face) to Apple anyway .. :hhh:
 

Vandelay

Life is absurd. Lean into it.
Joined
Apr 14, 2013
Messages
25,173
Reputation
6,808
Daps
90,646
Reppin
Phi Chi Connection
Even biometrics can be exploited, and what's worse with biometrics much like social security numbers once they have your likeness, it's not like it changes. You will look the same for decades, barring some significant facial hair changes.

Some combination of 2 factor authentication is best. It's annoying, but having to authenticate on the spot from a secondary level is best. It's hard to fake both simultaneously unless they have a personal relationship with the hacked.
 

Pressure

#PanthersPosse
Supporter
Joined
Nov 19, 2016
Messages
47,069
Reputation
7,174
Daps
149,727
Reppin
CookoutGang
Microsoft hasn't required passwords for nearly 3 years after fully implementing mfa and windows hello.

Apple doing what's already the norm, but with a lot of fanfare. :russell:
 
Top