<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	 xmlns:media="http://search.yahoo.com/mrss/" 
	>
<channel>
	<title>
	Kommentarer på: #174 &#8211; Brister med tvåfaktorsautentisering med Nikka	</title>
	<atom:link href="https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/</link>
	<description>IT-säkerhet med Erik och Mattias som varvar kändisintervjuer med säkerhetssnack i tiden</description>
	<lastBuildDate>Tue, 21 Jun 2022 22:01:46 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>
	<item>
		<title>
		Av: Karl Emil Nikka		</title>
		<link>https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-431</link>

		<dc:creator><![CDATA[Karl Emil Nikka]]></dc:creator>
		<pubDate>Tue, 21 Jun 2022 22:01:46 +0000</pubDate>
		<guid isPermaLink="false">https://www.itsakerhetspodden.se/?p=5418#comment-431</guid>

					<description><![CDATA[Som svar på &lt;a href=&quot;https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-430&quot;&gt;Theo&lt;/a&gt;.

Det var intressant att Apple-representanten sade det. Det går ju rakt emot det som Apple själva skriver i sin utvecklardokumentation:

“There are two forms of public-private key authentication: passkeys and security keys. With passkeys, the device stores its public-private key pair in the user’s iCloud Keychain and syncs the keys across the user’s devices.”
https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication

Ifall inte de privata nycklarna synkroniseras (end-to-end-krypterat) till Icloud Keychain vore det inte heller möjligt för en användare att återfå åtkomsten till sina konton ifall användaren förlorat alla sina Apple-enheter. Detta sade Apple att var möjligt på WWDC 2021. 

“Passkeys are WebAuthn credentials with the amazing security that the standard provides combined with the usability of being backed up, synced, and working on all of your devices. We’re storing them in iCloud Keychain. Just like everything else in your iCloud Keychain, they’re end-to-end encrypted, so not even Apple can read them. /…/ And since it’s backed by iCloud Keychain, you can still get your credentials back, even if you lose all of your Apple devices.”
https://developer.apple.com/videos/play/wwdc2021/10106/

Google skriver samma sak.

“What happens if a user loses their device? Passkeys created on Android are backed up and synced with Android devices that are signed in to the same Google Account, in the same way as passwords are backed up to the password manager. That means a users&#039; passkeys go with them when they replace their devices. To sign into apps on a new phone, all users need to do is unlock their phone.”
https://developers.google.com/identity/fido

Som Apple lyfte upp på årets WWDC går det också att dela passkeys med andra användare via Airdrop.

“I can tap on our shared account to pull up more details. Here, I can get some information about my saved passkey or add a note to this account. I can also share my passkey. There&#039;s my partner&#039;s phone. I&#039;ll go ahead and select that. Now my partner has the passkey too. And that&#039;s how easy it is to use passkeys everywhere.”
https://developer.apple.com/videos/play/wwdc2022/10092/

Jag söker gärna med Apple-ingenjören som du talade med på WWDC. Det vore mycket intressant. Ifall du har möjlighet att delge mig vem det var du talade med så får du gärna göra det. Du når mig på ke.nikka@nikkasystems.com (PGP via WKD) eller 0735181000 (Signal).]]></description>
			<content:encoded><![CDATA[<p>Som svar på <a href="https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-430">Theo</a>.</p>
<p>Det var intressant att Apple-representanten sade det. Det går ju rakt emot det som Apple själva skriver i sin utvecklardokumentation:</p>
<p>“There are two forms of public-private key authentication: passkeys and security keys. With passkeys, the device stores its public-private key pair in the user’s iCloud Keychain and syncs the keys across the user’s devices.”<br />
<a href="https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication" rel="nofollow ugc">https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication</a></p>
<p>Ifall inte de privata nycklarna synkroniseras (end-to-end-krypterat) till Icloud Keychain vore det inte heller möjligt för en användare att återfå åtkomsten till sina konton ifall användaren förlorat alla sina Apple-enheter. Detta sade Apple att var möjligt på WWDC 2021. </p>
<p>“Passkeys are WebAuthn credentials with the amazing security that the standard provides combined with the usability of being backed up, synced, and working on all of your devices. We’re storing them in iCloud Keychain. Just like everything else in your iCloud Keychain, they’re end-to-end encrypted, so not even Apple can read them. /…/ And since it’s backed by iCloud Keychain, you can still get your credentials back, even if you lose all of your Apple devices.”<br />
<a href="https://developer.apple.com/videos/play/wwdc2021/10106/" rel="nofollow ugc">https://developer.apple.com/videos/play/wwdc2021/10106/</a></p>
<p>Google skriver samma sak.</p>
<p>“What happens if a user loses their device? Passkeys created on Android are backed up and synced with Android devices that are signed in to the same Google Account, in the same way as passwords are backed up to the password manager. That means a users&#8217; passkeys go with them when they replace their devices. To sign into apps on a new phone, all users need to do is unlock their phone.”<br />
<a href="https://developers.google.com/identity/fido" rel="nofollow ugc">https://developers.google.com/identity/fido</a></p>
<p>Som Apple lyfte upp på årets WWDC går det också att dela passkeys med andra användare via Airdrop.</p>
<p>“I can tap on our shared account to pull up more details. Here, I can get some information about my saved passkey or add a note to this account. I can also share my passkey. There&#8217;s my partner&#8217;s phone. I&#8217;ll go ahead and select that. Now my partner has the passkey too. And that&#8217;s how easy it is to use passkeys everywhere.”<br />
<a href="https://developer.apple.com/videos/play/wwdc2022/10092/" rel="nofollow ugc">https://developer.apple.com/videos/play/wwdc2022/10092/</a></p>
<p>Jag söker gärna med Apple-ingenjören som du talade med på WWDC. Det vore mycket intressant. Ifall du har möjlighet att delge mig vem det var du talade med så får du gärna göra det. Du når mig på <a href="mailto:ke.nikka@nikkasystems.com">ke.nikka@nikkasystems.com</a> (PGP via WKD) eller 0735181000 (Signal).</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		Av: Theo		</title>
		<link>https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-430</link>

		<dc:creator><![CDATA[Theo]]></dc:creator>
		<pubDate>Tue, 21 Jun 2022 20:57:47 +0000</pubDate>
		<guid isPermaLink="false">https://www.itsakerhetspodden.se/?p=5418#comment-430</guid>

					<description><![CDATA[Hej igen Karl-Emil. Jag är iOS utvecklare och pratade under WWDC med en Apple ingenjör angående detta. Nej, privata nycklarna skapas i Secure Enclave och som alltid sparar man en ”data representation” i Keychain som en länk till den privata nyckeln. Den ”data representation” är som en tagg som du har på din nyckelknippa där det står till exempel ”hem”. Det går inte att återskapa den privata nyckel från den ”data representation” den fungerar liksom en SHA256 hash. Därför är det säker att använda Passkey. Om Apple hade sparat privata nyckeln i Keychain direkt hade ingen använt det eftersom man kan lätt läsa hela keychain på en iPhone (Grayshift t.ex).
Jag föreslår att du kontaktar Apple för att de bekräftar detta till dig. Alltid bäst att höra sanningen ”from the horse’s mouth” <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f604.png" alt="😄" class="wp-smiley" style="height: 1em; max-height: 1em;" />
Annars trevlig podcast var det! Använder Yubikey varje dag <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f1f8-1f1ea.png" alt="🇸🇪" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f973.png" alt="🥳" class="wp-smiley" style="height: 1em; max-height: 1em;" />]]></description>
			<content:encoded><![CDATA[<p>Hej igen Karl-Emil. Jag är iOS utvecklare och pratade under WWDC med en Apple ingenjör angående detta. Nej, privata nycklarna skapas i Secure Enclave och som alltid sparar man en ”data representation” i Keychain som en länk till den privata nyckeln. Den ”data representation” är som en tagg som du har på din nyckelknippa där det står till exempel ”hem”. Det går inte att återskapa den privata nyckel från den ”data representation” den fungerar liksom en SHA256 hash. Därför är det säker att använda Passkey. Om Apple hade sparat privata nyckeln i Keychain direkt hade ingen använt det eftersom man kan lätt läsa hela keychain på en iPhone (Grayshift t.ex).<br />
Jag föreslår att du kontaktar Apple för att de bekräftar detta till dig. Alltid bäst att höra sanningen ”from the horse’s mouth” 😄<br />
Annars trevlig podcast var det! Använder Yubikey varje dag 🇸🇪🥳</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		Av: Karl Emil Nikka		</title>
		<link>https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-429</link>

		<dc:creator><![CDATA[Karl Emil Nikka]]></dc:creator>
		<pubDate>Tue, 21 Jun 2022 20:11:19 +0000</pubDate>
		<guid isPermaLink="false">https://www.itsakerhetspodden.se/?p=5418#comment-429</guid>

					<description><![CDATA[Som svar på &lt;a href=&quot;https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-426&quot;&gt;Theo&lt;/a&gt;.

Hej Theo. Nej, de privata nycklarna stannar inte i T2-enklaven. De synkroniseras mellan enheter via Icloud Keychain. Jag lägger med länkarna till Apples och Googles utvecklardokumentation ifall du eller andra förbipasserande läsare vill veta mer.

Apple: https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication
”With passkeys, the device stores its public-private key pair in the user’s iCloud Keychain and syncs the keys across the user’s devices.”

Google: https://developers.google.com/identity/fido]]></description>
			<content:encoded><![CDATA[<p>Som svar på <a href="https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-426">Theo</a>.</p>
<p>Hej Theo. Nej, de privata nycklarna stannar inte i T2-enklaven. De synkroniseras mellan enheter via Icloud Keychain. Jag lägger med länkarna till Apples och Googles utvecklardokumentation ifall du eller andra förbipasserande läsare vill veta mer.</p>
<p>Apple: <a href="https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication" rel="nofollow ugc">https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication</a><br />
”With passkeys, the device stores its public-private key pair in the user’s iCloud Keychain and syncs the keys across the user’s devices.”</p>
<p>Google: <a href="https://developers.google.com/identity/fido" rel="nofollow ugc">https://developers.google.com/identity/fido</a></p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		Av: Karl Emil Nikka		</title>
		<link>https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-428</link>

		<dc:creator><![CDATA[Karl Emil Nikka]]></dc:creator>
		<pubDate>Tue, 21 Jun 2022 20:08:32 +0000</pubDate>
		<guid isPermaLink="false">https://www.itsakerhetspodden.se/?p=5418#comment-428</guid>

					<description><![CDATA[Hej Theo. Nej, de privata nycklarna stannar inte i T2-enklaven. De synkroniseras mellan enheter via Icloud Keychain. Jag lägger med länkarna till Apples och Googles utvecklardokumentation ifall du eller andra förbipasserande läsare vill veta mer. 

Apple: https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication
”With passkeys, the device stores its public-private key pair in the user’s iCloud Keychain and syncs the keys across the user’s devices.&quot;

Google: https://developers.google.com/identity/fido]]></description>
			<content:encoded><![CDATA[<p>Hej Theo. Nej, de privata nycklarna stannar inte i T2-enklaven. De synkroniseras mellan enheter via Icloud Keychain. Jag lägger med länkarna till Apples och Googles utvecklardokumentation ifall du eller andra förbipasserande läsare vill veta mer. </p>
<p>Apple: <a href="https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication" rel="nofollow ugc">https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication</a><br />
”With passkeys, the device stores its public-private key pair in the user’s iCloud Keychain and syncs the keys across the user’s devices.&#8221;</p>
<p>Google: <a href="https://developers.google.com/identity/fido" rel="nofollow ugc">https://developers.google.com/identity/fido</a></p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		Av: Erik Zalitis		</title>
		<link>https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-427</link>

		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Tue, 21 Jun 2022 19:49:19 +0000</pubDate>
		<guid isPermaLink="false">https://www.itsakerhetspodden.se/?p=5418#comment-427</guid>

					<description><![CDATA[Som svar på &lt;a href=&quot;https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-426&quot;&gt;Theo&lt;/a&gt;.

Hej

Tackar för kommentaren, jag ska skicka detta vidare till Karl-Emil, så får han svarar.

Mvh
Erik Zalitis]]></description>
			<content:encoded><![CDATA[<p>Som svar på <a href="https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-426">Theo</a>.</p>
<p>Hej</p>
<p>Tackar för kommentaren, jag ska skicka detta vidare till Karl-Emil, så får han svarar.</p>
<p>Mvh<br />
Erik Zalitis</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		Av: Theo		</title>
		<link>https://www.itsakerhetspodden.se/174-brister-med-tvafaktorsautentisering-med-nikka/#comment-426</link>

		<dc:creator><![CDATA[Theo]]></dc:creator>
		<pubDate>Tue, 21 Jun 2022 19:21:30 +0000</pubDate>
		<guid isPermaLink="false">https://www.itsakerhetspodden.se/?p=5418#comment-426</guid>

					<description><![CDATA[Hej. Karl-Emil Nikka har fel angående Apples Passkey: privata nycklarna är lika säkra som Yubikey eftersom de skapas och stannar i Secure Enclave (T2 Secure chip). Viktigt att korrigera!]]></description>
			<content:encoded><![CDATA[<p>Hej. Karl-Emil Nikka har fel angående Apples Passkey: privata nycklarna är lika säkra som Yubikey eftersom de skapas och stannar i Secure Enclave (T2 Secure chip). Viktigt att korrigera!</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
