TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

About Passkey – the password-free tech Apple is betting on

30 点作者 gautamsomani11 个月前

7 条评论

hgyjnbdet11 个月前
These articles never seem to mention the issues with passkeys asthey relate to Apple and other companies like them being in control of you account accessibility. What happens if you&#x27;re device is list or stolen? What happens if that company decides you can no longer access your account with them?<p>I&#x27;ll be using keepassxc and passwords until I&#x27;m forced to use passkeys and then I&#x27;ll use passkeys in keepassxc. No way am I tying my accounts to one of more devices controlled by multinational advertising companies.
评论 #40887697 未加载
评论 #40887669 未加载
评论 #40887632 未加载
评论 #40888082 未加载
kats10 个月前
I was having trouble understanding what they are.<p>Summary: It&#x27;s a password manager on your phone. You sign into your password manager with something easy like biometrics or a PIN. Then all the &#x27;real&#x27; passwords for sites are autogenerated and those are what&#x27;s sent to sites when you log in.
评论 #40887625 未加载
评论 #40887778 未加载
评论 #40888126 未加载
heavyset_go10 个月前
Passkeys are a nice solution, and it&#x27;s entirely possible to adopt them without locking yourself into Apple or Google&#x27;s walled garden. That seems to require you to forgo using your Apple&#x2F;Google devices as passkeys themselves, unless you use an unrelated app as your passkey manager.<p>It&#x27;s interesting seeing how they&#x27;re being used for lock-in, though. As mentioned in this thread, attestation in the standard will be abused towards that end.
评论 #40887750 未加载
AnonHP10 个月前
&gt; And if a passkey were somehow stolen and added to a bad actor’s device, it would become useless because the thief wouldn’t have access to the true owner’s biometrics.<p>I’m not sure if the author really understands passkeys well, because this statement seems either illogical or false (depending on which platform, device and passkey app one is using).
Yaina10 个月前
The biggest hurdle to passkey adoption is going to be, how complicated they are to implement for developers (relative to their advantages). I think that&#x27;s the much more pressing matter than user adoption.
评论 #40887664 未加载
评论 #40887787 未加载
评论 #40887858 未加载
评论 #40887665 未加载
unethical_ban10 个月前
I&#x27;m inebriated and curious, allow me to ask the laymans&#x27; question:<p>Is this just public&#x2F;private keys with apple managing the keys and the security of the keys via their auth stack?
评论 #40888010 未加载
评论 #40887886 未加载
cyberax10 个月前
Yeah, Apple&#x27;s gonna Apple.<p>In other words, they&#x27;ll use Passkeys as a way to deepen the vendor lock-in. It has already started. For example, try to log into your Apple ID account using Safari, and it works via passkeys. No password needed. That&#x27;s because Apple created a Passkey for apple.com automatically behind your back.<p>Now try the same from Firefox with BitWarden, and it doesn&#x27;t work. And of course, there is no way for you to set up the passkey manually.<p>There&#x27;s also no API to export it. Wouldn&#x27;t it be nice if you could install BitWarden desktop client, and then use it migrate your passkeys? Nope. Not an option. The entitlement to interact with the Keychain for passkeys is only given out to browser vendors.
评论 #40888921 未加载