Hacker News new | ask | show | jobs
by threeseed 1378 days ago
If you are using passwords that you can remember without your phone then I assume it's pretty basic and insecure.
3 comments

You can use password manager that is cross platform. You can even use something like KeePassXC and sync the database between devices. All encrypted and secure without even having a phone if you want. You don't need to remember passwords without or with your phone.
Presenting this as a choice between using Apple's closed solution or using easy-to-remember passwords is disingenuous. Please don't participate in the discussion if you're going to be this bad faith.
> Please don't participate in the discussion if you're going to be this bad faith.

That works both ways. You've asked a question, to which the information is easily accessible online[https://support.apple.com/en-gb/HT213305]. It very clear from both the article and other online sources that this is based on WebAuthN[https://webauthn.guide]. You have been equally as disingenuous and based on your responses, acted in bad faith from the beginning in a bid to start a flamewar. How what you are doing is anything but basic bullying is beyond me.

Wow, why so angry?

My question was genuine. I have been trying to look into this before and not found anything on how keys are supposed to be synced across ecosystems. And your links don't explain that either; the Apple link explains how it syncs _within_ the iCloud ecosystem, not how it syncs between the different ecosystems. I didn't find your WebAuthN link before, but quickly skimming through it, I don't see anything about how keys are supposed to be synced between ecosystems. And when I have looked into this before, all I've been able to find is solutions to migrate between ecosystems, not syncing between them, which are wildly different use-cases.

If you have nothing productive to contribute, please don't.

It's especially ironic given that what Apple has implemented is literally an existing web standard. Luckily web apps supporting WebAuthn should also be able to support alternative means of authentication so they don't break when you don't have your device with you.
You literally said you would keep using passwords. The dichotomy was established by you.
> I'll keep using passwords, thanks.

> If you are using passwords THAT YOU CAN REMEMBER WITHOUT YOUR PHONE then I assume it's pretty basic and insecure.

> Presenting this as a choice between using Apple's closed solution or using EASY-TO-REMEMBER passwords is disingenuous.

All caps to indicate how sbuk changed the meaning of what mort96 said.

The dichotomy was between using using Apple's solution and using passwords. Deciding the latter must mean using easy to remember passwords and not acknowledging the existence of password managers and complex password generators is at best ignorance or forgetfulness and at worst dishonesty.

Unlike mort96, I didn't automatically assume dishonesty, but sbuk posted this in response to mort96's accusation:

> You have been equally as disingenuous and based on your responses, acted in bad faith from the beginning in a bid to start a flamewar. How what you are doing is anything but basic bullying is beyond me.

This implies that they were aware of what they were doing and, rather than call mort96 out on what they believed to be an attempt at a flamewar, decided to contribute to it by deliberately altering the meaning of mort96's message.

I believe mort96 and sbuk were both accusatory and rude, but what sbuk appears to have done would be worse in my view. Rather than just assume the worst of who I'm communicating with, I'd rather give them the benefit of the doubt by inquiring for more information, attempting to inform, or possibly explaining how I interpreted a passage.

Obligatory XKCD: https://xkcd.com/936/