{"id":14011,"date":"2018-12-06T08:30:02","date_gmt":"2018-12-06T16:30:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/12\/06\/news-7778\/"},"modified":"2018-12-06T08:30:02","modified_gmt":"2018-12-06T16:30:02","slug":"news-7778","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2018\/12\/06\/news-7778\/","title":{"rendered":"Will Apple\u2019s iPhone replace your password?"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2017\/11\/iphonex-faceid-apple-100740908-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Thu, 06 Dec 2018 07:00:00 -0800<\/strong><\/p>\n<p>Imagine using Face ID on your iPhone alongside a password and Touch ID on your computer in order to access highly secure websites, such as online banks, enterprise intranets and confidential online data services.<\/p>\n<p>That\u2019s a possibility as Apple begins testing a new security standard called WebAuthn.<\/p>\n<p>Apple has begun <a href=\"https:\/\/webkit.org\/blog\/8517\/release-notes-for-safari-technology-preview-71\/\" rel=\"noopener nofollow\" target=\"_blank\">beta-testing support<\/a> for the standard in <a href=\"https:\/\/webkit.org\/blog\/6017\/introducing-safari-technology-preview\/\" rel=\"noopener nofollow\" target=\"_blank\">Safari Technology Preview<\/a>\u00a0Release 71, thought it does warn this support is an \u201cexperimental feature\u201d, so it may go no further than that.<\/p>\n<p><a href=\"https:\/\/www.w3.org\/TR\/webauthn\/\" rel=\"noopener nofollow\" target=\"_blank\">WebAuthn<\/a> (Web Authentication) technology lets websites\/online services use hardware keys (typically USB devices) to authenticate your identity when you try to access them.<\/p>\n<p>These keys are usually used alongside passcodes and other security protections (including <a href=\"https:\/\/support.apple.com\/en-gb\/HT204915\" rel=\"noopener nofollow\" target=\"_blank\">2FA<\/a>) to provide even stronger protection when you access these services.<\/p>\n<p>While not based on the same technology, many online banking consumers may have been offered authentication devices by their banks, but such hardware\/software keys are also used elsewhere, in government and the military for example.<\/p>\n<p>WebAuthn also supports a companion standard called FIDO2, which lets hardware keys use Bluetooth and NFC for authentication of WebAuthn sessions. In theory, this means you can use existing security devices, including fingerprint readers, cameras and USB keys as website authentication systems.<\/p>\n<p>It isn\u2019t known if Apple will support FIDO2, but if it did it may potentially be able to create a system in which iPhones (or even an Apple Watch) became a hardware \u201ckey\u201d used to access secure services, leveraging its advantages in biometric security and the industry-leading security of its operating systems.<\/p>\n<p>This would tie an individual user\u2019s mobile device up to a PC, Mac or iPad used to access the system, and would replace or at least supplement password protection.<\/p>\n<p>It is important to add that WebAuthn is not yet fully endorsed by the W3C, particularly in light of recent warnings from the <a href=\"https:\/\/paragonie.com\/blog\/2018\/08\/security-concerns-surrounding-webauthn-don-t-implement-ecdaa-yet\" rel=\"noopener nofollow\" target=\"_blank\">Paragon Initiative<\/a> that some of the algorithms used in the standard may be outdated and vulnerable to attack.<\/p>\n<p>WebAuthn is also supported in Mozilla, Microsoft Edge and Google.<\/p>\n<p>Its existence confirms that security protection will become increasingly dependent on multifactor hardware\/software\/biometric security models.<\/p>\n<p>It must.<\/p>\n<p>A quick scan of the news headlines confirms that the velocity of major attacks is increasing, with huge companies (such as the Marriot hotel chain) impacted.<\/p>\n<p>This means millions of customer details &#8212; including names and passwords used across multiple services &#8212; that have been stolen through this and many other attacks are almost certainly now trading on the dark web.<\/p>\n<p>The industry must recognise that the security challenges around phishing and data theft extend way beyond financial transactions and personal data security, but also threatens the political process.<\/p>\n<p style=\"padding-left: 30px;\" width=\"100%\" height=\"420\"><iframe loading=\"lazy\"  src=\"https:\/\/www.youtube.com\/embed\/mymEMKxhYPI\" width=\"100%\" height=\"420\" frameborder=\"0\" ><\/iframe> \u00a0<em>A\u00a02017 explanation of some of this<\/em><\/p>\n<p><iframe loading=\"lazy\"  src=\"https:\/\/www.youtube.com\/embed\/mymEMKxhYPI\" width=\"100%\" height=\"420\" frameborder=\"0\" ><\/iframe> <\/p>\n<p>With this in mind, it seems likely we\u2019ll see it come together more tightly to develop robust security technologies for a digitally-connected IoT age.<\/p>\n<p>Apple\u2019s decision to support (or at least, test) the security standard confirms the growing awareness among all stakeholders of the need to challenge the security challenge.<\/p>\n<p>To enable support you need to download and install the latest Safari Preview, then open <em>Develop&gt;Experimental Features&gt;Web Authenticatio<\/em>n.<\/p>\n<p>You will also need an external hardware device, such as the Yubikey 5 or $20 Yubi Security Key. It is interesting to note that the company that makes both of those products is also developing authentication devices with USB-C support.<\/p>\n<p><em>Please follow me on\u00a0<u><a href=\"https:\/\/twitter.com\/jonnyevans_cw\" rel=\"nofollow\">Twitter<\/a><\/u>, and join me in the\u00a0<a href=\"https:\/\/mewe.com\/join\/appleholics_bar_and_grill\" rel=\"nofollow\">AppleHolic\u2019s bar &amp; grill<\/a>\u00a0and\u00a0<u><a href=\"https:\/\/mewe.com\/join\/apple_discussions\" rel=\"nofollow\">Apple Discussions<\/a><\/u>\u00a0groups on MeWe<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3326069\/security\/will-apple-s-iphone-replace-your-password.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2017\/11\/iphonex-faceid-apple-100740908-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Thu, 06 Dec 2018 07:00:00 -0800<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>Imagine using Face ID on your iPhone alongside a password and Touch ID on your computer in order to access highly secure websites, such as online banks, enterprise intranets and confidential online data services.<\/p>\n<p>That\u2019s a possibility as Apple begins testing a new security standard called WebAuthn.<\/p>\n<h2><strong>What is WebAuthn?<\/strong><\/h2>\n<p>Apple has begun <a href=\"https:\/\/webkit.org\/blog\/8517\/release-notes-for-safari-technology-preview-71\/\" rel=\"noopener nofollow\" target=\"_blank\">beta-testing support<\/a> for the standard in <a href=\"https:\/\/webkit.org\/blog\/6017\/introducing-safari-technology-preview\/\" rel=\"noopener nofollow\" target=\"_blank\">Safari Technology Preview<\/a>\u00a0Release 71, thought it does warn this support is an \u201cexperimental feature\u201d, so it may go no further than that.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3326069\/security\/will-apple-s-iphone-replace-your-password.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[10480,10554,714],"class_list":["post-14011","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-ios","tag-mobile","tag-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14011"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14011\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14011"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}