Hacker News new | past | comments | ask | show | jobs | submit login

They are upgrading Keychain to be a first class password manager in iOS14. Along with WebAuthN improvements, this might negate the need for many third party password managers.



That's not an actual retort to the critique.

Apple cripples third party password managers on purpose. Pointing at Apple's worse product, a product that only works within their confined ecosystem, while claiming it is better than it was isn't a retort, it is a polite middle finger.

On that note, I recently set up a new iPhone & Watch. I had to enter my Apple Password six separate times, and 2F twice. And not once was my password manager allowed to populate it, even though it is saved in there.

Sure, I could use Keychain, but it lacks common & basic features and doesn't work on PCs, non-Apple mobile devices, or on the web. Maybe if Apple competed fairly on quality rather than abusing their anti-competitive silo(s), they'd have a better password manager.


Why do you think Apple is crippling third party password managers? If you want to use 1Password instead of iCloud Keychain then there’s support in iOS to do exactly that, and if you enable it then it will auto fill in the same way it did before. I personally find the 1password experience better on iOS than any other platform I’ve tried.


You also have to use a cellphone number for your apple id and it is always one of the fallbacks for 2fa which is just horrible considering how insecure cellphone numbers are.

Dear Apple, just let me use authy or a hardware token instead of your proprietary bullshit.


Your average Apple consumer doesn’t want a painful time when they lose or damage their hardware token and don’t have a spare, while also not backing up their recovery codes. This happens. It sucks.

Apple is a trillion dollar company because they make their users happy enough. Perfect security is not necessarily the best security posture; usability is still a concern.


So, 2fa is worthless. Hardware tokens are just a token gesture.I have 4 apple devices, which one provides me with a token is somewhat of a gamble...

If this is fine with Apple, ok. Why are they pushing apple school manager on me though? Why do I have to provide a cell number for an apple id to sync backups? Why are ASM accounts unable to install apps from the app store unless you assign them from a central app store profile? Why do ASM accounts not work for iMessage? Why do ASM accounts not work for iCloud backups?

It's not about usability, it is about locking people in.


How do I use Keychain with Firefox?


At some point you however have to wonder : Is it up to a browser to support the OS native password manager, or is it the burden of the OS maker to provide a plugin for each browser?

Beside Firefox now provide it's own password manager. But it is awkwardly limited within the browser.

Same with the recently touted picture in picture mode of Firefox. While I understand it might be enjoyable on OS that don't support that natively it's particularly laughable on OS that does it. Now You potentially have 3 layers of picture in picture implementation. The website, the browser and the OS... (And as you might guess the OS offer the best experience because it have control over all graphical layers).


Can’t yet. Valid use case, point taken. I use Safari.


I keep meaning to try different browsers and then realizing I'd have to manually migrate all of my passwords from safari. Not going to happen.


For the longest time, Firefox and Chrome could move passwords from another browser that was on the machine. Maybe give it a shot?


You can import passwords at least from chrome to safari and then they will sync through keychain. I assume importing from Firefox would work as well.

The issue is it does not stay in sync, if I use my windows machine and update a password there I would have to re-import where as a password manager (and/or its extension) would just stay synced.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: