<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Apple Announces Decision to Ditch Passwords]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/phenomlab" aria-label="Profile: phenomlab">@<bdi>phenomlab</bdi></a> I guess this should be another thread, but after you post this meme, I wonder about your opinion on the new techniques to omit passwords…</p>
<p dir="auto"><a href="https://tech.co/news/apple-ditches-passwords" target="_blank" rel="noopener noreferrer nofollow ugc">https://tech.co/news/apple-ditches-passwords</a></p>
<p dir="auto">Apple, Google, and Microsoft are going in this direction I guess.</p>
]]></description><link>https://sudonix.org/topic/354/apple-announces-decision-to-ditch-passwords</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Jul 2026 21:40:19 GMT</lastBuildDate><atom:link href="https://sudonix.org/topic/354.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 21 Oct 2022 04:24:14 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Thu, 11 May 2023 16:07:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/crazycells" aria-label="Profile: crazycells">@<bdi>crazycells</bdi></a> Who knows given today’s modern technology.</p>
]]></description><link>https://sudonix.org/post/5967</link><guid isPermaLink="true">https://sudonix.org/post/5967</guid><dc:creator><![CDATA[phenomlab]]></dc:creator><pubDate>Thu, 11 May 2023 16:07:30 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Thu, 11 May 2023 14:32:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/phenomlab" aria-label="Profile: phenomlab">@<bdi>phenomlab</bdi></a> said in <a href="/post/5953">Apple Announces Decision to Ditch Passwords</a>:</p>
<blockquote>
<p dir="auto">However, I think your average criminal may not have the array of resources that the FBI has… <img src="https://sudonix.org/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=2ee9f75f7cb" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title="🙂" alt="🙂" /></p>
</blockquote>
<p dir="auto">lol I hope they do not <img src="https://sudonix.org/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=2ee9f75f7cb" class="not-responsive emoji emoji-android emoji--smile" style="height:23px;width:auto;vertical-align:middle" title=":D" alt="😄" /></p>
]]></description><link>https://sudonix.org/post/5962</link><guid isPermaLink="true">https://sudonix.org/post/5962</guid><dc:creator><![CDATA[crazycells]]></dc:creator><pubDate>Thu, 11 May 2023 14:32:05 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Thu, 11 May 2023 08:25:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/crazycells" aria-label="Profile: crazycells">@<bdi>crazycells</bdi></a> said in <a href="/post/5947">Apple Announces Decision to Ditch Passwords</a>:</p>
<blockquote>
<p dir="auto">And you cannot try indefinitely to find out the passcode.</p>
</blockquote>
<p dir="auto">That’s very true. However, as we saw with the San Bernadino shooting, the FBI did in fact manage to hack that device<br />
<a href="https://www.theverge.com/2021/4/14/22383957/fbi-san-bernadino-iphone-hack-shooting-investigation" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theverge.com/2021/4/14/22383957/fbi-san-bernadino-iphone-hack-shooting-investigation</a></p>
<p dir="auto">However, I think your average criminal may not have the array of resources that the FBI has… <img src="https://sudonix.org/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=2ee9f75f7cb" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
]]></description><link>https://sudonix.org/post/5953</link><guid isPermaLink="true">https://sudonix.org/post/5953</guid><dc:creator><![CDATA[phenomlab]]></dc:creator><pubDate>Thu, 11 May 2023 08:25:54 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Thu, 11 May 2023 03:15:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/phenomlab" aria-label="Profile: phenomlab">@<bdi>phenomlab</bdi></a> yes, let’s see how it will be implemented. I am curious about it.</p>
<p dir="auto">For most people, I believe this device will be their phone. And I believe phones are quite secure since they will need a passcode to be opened anyway. And you cannot try indefinitely to find out the passcode.</p>
]]></description><link>https://sudonix.org/post/5947</link><guid isPermaLink="true">https://sudonix.org/post/5947</guid><dc:creator><![CDATA[crazycells]]></dc:creator><pubDate>Thu, 11 May 2023 03:15:53 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Mon, 08 May 2023 18:07:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/crazycells" aria-label="Profile: crazycells">@<bdi>crazycells</bdi></a> this is an interesting concept, and I’ve been looking at this same technology for a while now. However, I do think it has flaws in the sense that you can use multiple devices, and if one of those were stolen, that could then easily act as a gateway to gain access to your accounts via an unauthorized source.</p>
<p dir="auto">Admittedly, you could easily prevent access by disabling that specific device, but the window of opportunity would still exist for a short period of time, and that may be long enough for any nefarious actor to compromise your accounts.</p>
<p dir="auto">No technology is going to be absolutely perfect, and we have to accept that. However, I do think it’s going to be a while before this new method of authentication becomes mainstream.</p>
]]></description><link>https://sudonix.org/post/5909</link><guid isPermaLink="true">https://sudonix.org/post/5909</guid><dc:creator><![CDATA[phenomlab]]></dc:creator><pubDate>Mon, 08 May 2023 18:07:27 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Mon, 08 May 2023 01:05:43 GMT]]></title><description><![CDATA[<p dir="auto">Google has started to implement this several days ago , and I asked about this to <a class="plugin-mentions-user plugin-mentions-a" href="/user/julian" aria-label="Profile: julian">@<bdi>julian</bdi></a> on NodeBB… I guess this passwordless access will be the new norm for many websites/apps…</p>
<p dir="auto"><a href="https://www.theverge.com/2023/5/3/23709318/google-accounts-passkey-support-password-2fa-fido-security-phishing" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theverge.com/2023/5/3/23709318/google-accounts-passkey-support-password-2fa-fido-security-phishing</a></p>
<p dir="auto"><a href="https://community.nodebb.org/post/92962" target="_blank" rel="noopener noreferrer nofollow ugc">https://community.nodebb.org/post/92962</a></p>
]]></description><link>https://sudonix.org/post/5908</link><guid isPermaLink="true">https://sudonix.org/post/5908</guid><dc:creator><![CDATA[crazycells]]></dc:creator><pubDate>Mon, 08 May 2023 01:05:43 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Thu, 27 Oct 2022 07:36:11 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/crazycells" aria-label="Profile: crazycells">@<bdi>crazycells</bdi></a> That sounds like a solid solution.</p>
]]></description><link>https://sudonix.org/post/4479</link><guid isPermaLink="true">https://sudonix.org/post/4479</guid><dc:creator><![CDATA[phenomlab]]></dc:creator><pubDate>Thu, 27 Oct 2022 07:36:11 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Thu, 27 Oct 2022 02:46:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/phenomlab" aria-label="Profile: phenomlab">@<bdi>phenomlab</bdi></a> said in <a href="/post/4467">Apple Announces Decision to Ditch Passwords</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/crazycells" aria-label="Profile: crazycells">@<bdi>crazycells</bdi></a> I suppose the only issue which immediately springs to mind here is that if the password manager becomes compromised - for example, if your master password is inadvertently leaked, then an attacker has both the password, and the TOTP code.</p>
<p dir="auto">This might not sit well with the more paranoid users, but be perfectly acceptable and convenient for the less discerning ones.</p>
<p dir="auto">Food for thought.</p>
</blockquote>
<p dir="auto">yeah, but thanks to 1password, I am ok with this.<br />
they have a secondary level of encryption. so even if you got my master password, it is useless without a device that I have registered. It is not enough to decrypt my account, even online. You have to enter a “secret code” to add your device to the account so that you can decrypt your passwords on that device, and this secret code is given during registration only.</p>
]]></description><link>https://sudonix.org/post/4470</link><guid isPermaLink="true">https://sudonix.org/post/4470</guid><dc:creator><![CDATA[crazycells]]></dc:creator><pubDate>Thu, 27 Oct 2022 02:46:18 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Wed, 26 Oct 2022 20:37:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/crazycells" aria-label="Profile: crazycells">@<bdi>crazycells</bdi></a> I suppose the only issue which immediately springs to mind here is that if the password manager becomes compromised - for example, if your master password is inadvertently leaked, then an attacker has both the password, and the TOTP code.</p>
<p dir="auto">This might not sit well with the more paranoid users, but be perfectly acceptable and convenient for the less discerning ones.</p>
<p dir="auto">Food for thought.</p>
]]></description><link>https://sudonix.org/post/4467</link><guid isPermaLink="true">https://sudonix.org/post/4467</guid><dc:creator><![CDATA[phenomlab]]></dc:creator><pubDate>Wed, 26 Oct 2022 20:37:23 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Sat, 22 Oct 2022 23:29:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/phenomlab" aria-label="Profile: phenomlab">@<bdi>phenomlab</bdi></a> said in <a href="/post/4388">Apple Announces Decision to Ditch Passwords</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/crazycells" aria-label="Profile: crazycells">@<bdi>crazycells</bdi></a> good call with the password manager. I use Bitwarden myself for personal and family usage, and Dashlane for work. I’ve been experimenting with Bitwarden and it’s 2fa capabilities and I have to admit it’s impressive - so much so that I’m considering using this as a drop in replacement for Authy which I’ve been using for years.</p>
</blockquote>
<p dir="auto">Yeah, I, too, prefer password managers filling 2FAs rather than me checking from an app on the phone. That is why I ditched Authy for this very reason <img src="https://sudonix.org/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=2ee9f75f7cb" class="not-responsive emoji emoji-android emoji--smile" style="height:23px;width:auto;vertical-align:middle" title=":D" alt="😄" /></p>
]]></description><link>https://sudonix.org/post/4389</link><guid isPermaLink="true">https://sudonix.org/post/4389</guid><dc:creator><![CDATA[crazycells]]></dc:creator><pubDate>Sat, 22 Oct 2022 23:29:19 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Sat, 22 Oct 2022 22:29:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/crazycells" aria-label="Profile: crazycells">@<bdi>crazycells</bdi></a> good call with the password manager. I use Bitwarden myself for personal and family usage, and Dashlane for work. I’ve been experimenting with Bitwarden and it’s 2fa capabilities and I have to admit it’s impressive - so much so that I’m considering using this as a drop in replacement for Authy which I’ve been using for years.</p>
]]></description><link>https://sudonix.org/post/4388</link><guid isPermaLink="true">https://sudonix.org/post/4388</guid><dc:creator><![CDATA[phenomlab]]></dc:creator><pubDate>Sat, 22 Oct 2022 22:29:48 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Sat, 22 Oct 2022 22:22:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/phenomlab" aria-label="Profile: phenomlab">@<bdi>phenomlab</bdi></a> Thanks for the comment.</p>
<p dir="auto">I agree with you on users being the weakest link in the system… Let’s see how well or how fast this system will be adapted… I hope they can come up with a secure way that is not annoying…</p>
<p dir="auto">I actually started using the “1password” password manager quite some time ago for this purpose, and I have to tell you that my life got so much easier. I also turn on <span class="glossary-wrapper" title="two-factor authentication" data-bs-toggle="tooltip" data-bs-placement="top"><span class="glossary-word">2FA</span></span> if the website offers one in the app, and I do not remember or know any of the passwords I have <img src="https://sudonix.org/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=2ee9f75f7cb" class="not-responsive emoji emoji-android emoji--smile" style="height:23px;width:auto;vertical-align:middle" title=":D" alt="😄" /> I only know 1 password that will unlock the 1password app <img src="https://sudonix.org/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=2ee9f75f7cb" class="not-responsive emoji emoji-android emoji--smile" style="height:23px;width:auto;vertical-align:middle" title=":D" alt="😄" /> and that is enough to fill the login page details… I usually pick a long alphanumeric password with some special characters in it, so it is hard to guess.</p>
<p dir="auto">Additionally, after my critical email addresses got exposed in several website hackings last year, I also started using “<a href="http://simplelogin.io" target="_blank" rel="noopener noreferrer nofollow ugc">simplelogin.io</a>” with a custom domain so that I could create unique email addresses for each website. I have been using this for the last 8 months or so, and happy so far…</p>
<p dir="auto">With this method, each website has a unique email address and also unique password. At least if I am hacked on website X, my info on website Y is still safe…</p>
]]></description><link>https://sudonix.org/post/4387</link><guid isPermaLink="true">https://sudonix.org/post/4387</guid><dc:creator><![CDATA[crazycells]]></dc:creator><pubDate>Sat, 22 Oct 2022 22:22:49 GMT</pubDate></item><item><title><![CDATA[Reply to Apple Announces Decision to Ditch Passwords on Sat, 22 Oct 2022 21:26:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/crazycells" aria-label="Profile: crazycells">@<bdi>crazycells</bdi></a> interesting topic, and one that’s been banded around the security community for years. Whilst it’s a good concept, even biometric security and passkeys have one major  flaw - the end user responsible for the security itself.</p>
<p dir="auto">Ever heard of users being the weakest link ? In most cases, this is absolutely true. For example, you could have the highest grade security on offer, but once you put that electronic fortress into inexperienced hands, it may as well not be there at all. It’s long been considered that the “human firewall” is relatively simple to bypass, and it’s sadly a fact. Humans are susceptible to coercion - easily convinced that even something that looks too good to be true (and often is) is genuine - a “one time” opportunity too good to miss.</p>
<p dir="auto">Then there’s the social engineering side of things. It really doesn’t matter how strong your security is, the user in control of it can easily open the door to all sorts of unwanted activity, and allow sensitive information to simply walk out of the door at the same time.</p>
<p dir="auto">Will biometric security replacing passwords resolve this issue ? No - it’ll be exactly the same, just with a modern approach. What’s needed here is awareness - a constant reminder of what can easily happen if you lower your guard. We make the same mistake constantly by requiring users to change their passwords every x days - all that has achieved is to lower entropy and in fact weaken security in the process.  This is something I’ve written about before</p>
<p dir="auto"><a href="https://sudonix.com/topic/135/changing-passwords-regularly-actually-weakens-security" target="_blank" rel="noopener noreferrer nofollow ugc">https://sudonix.com/topic/135/changing-passwords-regularly-actually-weakens-security</a></p>
<p dir="auto">Users have a nasty habit of choosing weak passwords that they as humans can remember, and by definition, make that same password vulnerable to a dictionary attack or other simple mechanism - even brute force or sieve attacks - by adding a sequential number to satisfy the change, but to keep the password memorable.</p>
<p dir="auto">Admittedly, biometric security can stop that in it’s tracks and increasingly enhance the user experience, but it’s not a silver bullet - and should never be regarded as one.</p>
<p dir="auto">For all the time users remain unaware of the risk (or are ignorant to it), then no amount of security enhancements - even biometric - are not enough to increase security.</p>
]]></description><link>https://sudonix.org/post/4386</link><guid isPermaLink="true">https://sudonix.org/post/4386</guid><dc:creator><![CDATA[phenomlab]]></dc:creator><pubDate>Sat, 22 Oct 2022 21:26:52 GMT</pubDate></item></channel></rss>