Elektrine lite

← Feed

@rmondello@hachyderm.io

Post #2359376

2026-05-10 19:16 UTC

RE: https://mastodon.social/@brandonbutler/116544219969179883 Today, you cannot save an Apple Account passkey to an arbitrary passkey manager. If that were to change, I will yell it from the rooftops, because it will eliminate a lot of confusion for folks, especially in the Apple Developer community and better model how passkeys should ideally work.

Replies (3)

  • @luana@wetdry.world 2026-05-10 19:18

    @rmondello@hachyderm.io wait, you can’t? Wtf lmao

    Open ##2595467

  • @ErikvanStraten@todon.nl 2026-05-10 19:52

    @rmondello@hachyderm.io : what makes passkeys strong: 1. Software checks the domain name, which makes phishing hard; 2. Https is enforced, which helps prevent AitM attacks (unless Cloudflare et al. come into play); 3. A unique, long, unguessible, randomly generated "password" (public key) per account: dumb password rules and broken human RNG's no longer apply. The rest is marketing (including the -hyped- asymmetric cryptography). The "advantage" of denying the owner access to their own private keys hardly makes sense as long as session cookies are not device-bound. The disadvantage of not being able to back up ones own private keys is the risk of vendor lock-in and the underestimated huge risk of account lockout [1]. And the latter leads to the necessity of being able to log in using weak authentication after the user loses access to their private keys. @brandonbutler@mastodon.social [1] https://seclists.org/fulldisclosure/2024/Feb/15 #Passkeys #Phishing #PhishingResistant #AsymmetricCryptography #AndroidPasskeys #androidPasskeysGone #iOSpasskeys #iPadOSpasskeys #ApplePasskeys #BackUp #Export #BackUpPasskeys #ExportPassKeys #PasskeyBackUps #PasskeyExports

    Open ##2595469

  • @kylebshr@mastodon.social 2026-05-10 20:23

    @rmondello@hachyderm.io @brandonbutler@mastodon.social the only thing on my wwdc wishlist

    Open ##2595480