{"id":16413,"date":"2019-09-25T06:30:18","date_gmt":"2019-09-25T14:30:18","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/09\/25\/news-10154\/"},"modified":"2019-09-25T06:30:18","modified_gmt":"2019-09-25T14:30:18","slug":"news-10154","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/09\/25\/news-10154\/","title":{"rendered":"Apple just made Safari a better fit for the enterprise"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.techhive.com\/images\/article\/2017\/05\/170509-securitykeys-1-100722022-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Wed, 25 Sep 2019 07:15:00 -0700<\/strong><\/p>\n<p>Enterprise users can now wrap a new layer of security around their web services, thanks to Apple\u2019s introduction of support for USB security keys in <a href=\"https:\/\/developer.apple.com\/documentation\/safari_release_notes\/safari_13_release_notes\" rel=\"noopener nofollow\" target=\"_blank\">Safari 13.0.1<\/a>.<\/p>\n<p>Dongles aren\u2019t a terribly convenient security protection for most people, but government, military and regulated industries are always searching out new ways to secure themselves, and their data.<\/p>\n<p>FIDO2-compliant USB security keys \u2013 such as those made by Yubico \u2013 add a layer of security to the verification process:<\/p>\n<p>Not only must users enter passwords and potentially use biometric authentication, such as Touch\/Face ID, but they must also insert and authorize a USB security key.<\/p>\n<p>(Many enterprises may add geolocation to this mix).<\/p>\n<p>The idea is that not only must a user confirm who they are using traditional protections, but must also prove themselves with possession of the hardware key and may also be required to be accessing a site or service from a specific location, or even on specific network(s).<\/p>\n<p>Yubico introduced the YubiKey 5Ci for iOS devices <a href=\"https:\/\/www.applemust.com\/security-conscious-apple-users-should-take-a-look-at-yubikey-5ci\/\" rel=\"noopener nofollow\" target=\"_blank\">earlier this year<\/a>, working in partnership with password management providers including 1Password, Bitwarden, Dashlane, Idaptive, LastPass, and Okta.<\/p>\n<p>There are also high-profile services that support these authentication technologies, such as GitHub and alternative hardware key providers, including Titan.<\/p>\n<p>This isn\u2019t the only security key enhancement Apple has applied in recent weeks.<\/p>\n<p>Earlier this month, Apple introduced new functionality that allows the full range of YubiKey authentication on iOS <a href=\"https:\/\/www.yubico.com\/2019\/09\/yubico-ios-authentication-expands-to-include-nfc\/\" rel=\"noopener nofollow\" target=\"_blank\">via near field communication<\/a> (NFC).<\/p>\n<p>In case it\u2019s not clear, provision of NFC support means users can utilize a hardware-based authentication key on their iPhone using contactless tech, so you don\u2019t need to plug the key in.<\/p>\n<p>(One big advantage of NFC for this is that it minimizes any existing risk that a USB-based key can be infected with malware it can then install into the host machine.)<\/p>\n<p>This conceivably also mean enterprise IT can create layers of hardware-based protection that make use of devices (such as iPhones) employees already have with them.<\/p>\n<p>This may also have implications on Apple\u2019s overall push toward turning Apple Watch into a platform for keyless entry systems, as used around U.S. colleges at the present time.<\/p>\n<p>Apple began testing such enterprise-class authentication technologies in 2018, when it began working with <a href=\"https:\/\/www.computerworld.com\/article\/3326069\/will-apple-s-iphone-replace-your-password.html\">WebAuthn in Safari Technology Preview Release 71<\/a>.<\/p>\n<p>WebAuthn is the credential management API enterprise developers can weave inside their enterprise apps. It\u00a0became an official web standard in 2019.<\/p>\n<p>When they do, users can authenticate to access enterprise services without the need to save passwords on any server, as this is handled by the hardware key.\u00a0<\/p>\n<p>We know hundreds of thousands of people use incredibly weak passwords such as 1234, 1111, and other inadequate protections.<\/p>\n<p>The industry response has engaged in multiple responses to this.<\/p>\n<p>Apple,for example, has created its own password manager, password recommendation systems and systems that warn users when weak passwords are deployed. It also provides biometric protections such as Face and Touch ID.<\/p>\n<p>The problem with weak passwords is that they leave people vulnerable to attack.<\/p>\n<p>This is bad in isolation but such is the nature of connected infrastructure that overall security is frequently only as strong as the weakest link in the chain, which is usually the password.<\/p>\n<p>\u201cPasswords are bad for the planet. They\u2019re bad for people. They\u2019re the easiest way for attackers to get in, and in the case of account takeovers, they\u2019re even a way to force people out,\u201d Rob Lefferts, vice president of security at Microsoft told <em><a href=\"https:\/\/www.cnbc.com\/2018\/11\/20\/microsoft-adds-support-for-usb-security-keys.html\" rel=\"nofollow\">CNBC<\/a><\/em> last year.<\/p>\n<p>Fundamentally, most systems \u2013 including Apple\u2019s \u2013 do eventually require at least one password in the chain. In Apple\u2019s case, these are the passcodes for your Apple ID and your device-specific passcodes. You need these to authenticate biometric access.<\/p>\n<p>Given the need for human interaction at some point in the password chain, it makes sense that every user should be educated and empowered to use a complex alphanumeric passcode to protect their primary account data.<\/p>\n<p>At the same time, support for hardware-based encryption in Safari may be a good step in the journey to a password-free future &#8211; at least for enterprise users.\u00a0<\/p>\n<p>Safari 13.0.1 also introduces otherl privacy and security improvements, an updated start page and weak password warnings. It introduces the ability to enable Picture in Picture from the audio button in a tab.<\/p>\n<p>The update is recommended for all users and is available in the Software Update section of the About this Mac menu item.<\/p>\n<p>Please follow me on<em>\u00a0<a href=\"https:\/\/twitter.com\/jonnyevans_cw\" rel=\"nofollow\">Twitter<\/a>, or join me in the\u00a0<a href=\"https:\/\/mewe.com\/join\/appleholics_bar_and_grill\" rel=\"nofollow\">AppleHolic\u2019s bar &amp; grill<\/a>\u00a0and\u00a0<a href=\"https:\/\/mewe.com\/join\/apple_discussions\" rel=\"nofollow\">Apple Discussions<\/a>\u00a0groups on MeWe.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3440564\/apple-just-made-safari-a-better-fit-for-the-enterprise.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.techhive.com\/images\/article\/2017\/05\/170509-securitykeys-1-100722022-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Wed, 25 Sep 2019 07:15:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>Enterprise users can now wrap a new layer of security around their web services, thanks to Apple\u2019s introduction of support for USB security keys in <a href=\"https:\/\/developer.apple.com\/documentation\/safari_release_notes\/safari_13_release_notes\" rel=\"noopener nofollow\" target=\"_blank\">Safari 13.0.1<\/a>.<\/p>\n<h2><strong>Enterprise class security<\/strong><\/h2>\n<p>Dongles aren\u2019t a terribly convenient security protection for most people, but government, military and regulated industries are always searching out new ways to secure themselves, and their data.<\/p>\n<p>FIDO2-compliant USB security keys \u2013 such as those made by Yubico \u2013 add a layer of security to the verification process:<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3440564\/apple-just-made-safari-a-better-fit-for-the-enterprise.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[10480,21640,714,20233],"class_list":["post-16413","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-ios","tag-macs","tag-security","tag-web-applications"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16413","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16413"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16413\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16413"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16413"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}