{"id":133724,"date":"2023-05-15T14:02:00","date_gmt":"2023-05-15T14:02:00","guid":{"rendered":"https:\/\/developer.apple.com\/news\/?id=21mnmxow"},"modified":"2023-05-15T14:02:00","modified_gmt":"2023-05-15T14:02:00","slug":"qa-with-the-passkeys-team","status":"publish","type":"post","link":"https:\/\/sickgaming.net\/blog\/2023\/05\/15\/qa-with-the-passkeys-team\/","title":{"rendered":"Q&amp;A with the passkeys team"},"content":{"rendered":"<div class=\"inline-article-image\"><img decoding=\"async\" src=\"https:\/\/www.sickgaming.net\/blog\/wp-content\/uploads\/2023\/05\/qa-with-the-passkeys-team.jpg\" data-hires=\"false\" alt><\/div>\n<p>Get ready for a world without passwords. <\/p>\n<p>Passkeys are a replacement for passwords, offering a faster, easier, and more secure sign-in experience for your apps and websites. They\u2019re strong, resistant to phishing, and designed to work across Apple devices and nearby non-Apple devices. Best of all, there\u2019s nothing for people to create, guard, or remember.<\/p>\n<p>To help explain how to implement passkeys, the Apple privacy and security team hosted a Q&amp;A to answer common questions about device support, use cases, account recovery, and more. Here are some highlights from that conversation.<\/p>\n<h3>How do passkeys work?<\/h3>\n<p>Passkeys are based on public key cryptography, which matches a private key saved on a device with a public key sent to a web server. When someone signs in to an account, their private key is verified by your app or website\u2019s public key. That private key never leaves their device, so apps and websites never have access to it \u2014 and can\u2019t lose it or reveal it in a hacking or phishing attempt. There\u2019s nothing secret about the public key; it offers no access to anything until paired with the private key. <\/p>\n<h3>Which devices support passkeys?<\/h3>\n<p>Passkeys work on devices running a minimum of iOS 16 on iPhone 8; iPadOS 16 on iPad 5th generation, iPad mini 5th generation, iPad Air 3rd generation, all iPad Pro models that offer Touch ID or Face ID; macOS Ventura; and tvOS 16. Passkeys are also supported in Safari 16 on macOS Monterey and Big Sur. <\/p>\n<p>When Touch ID or Face ID can\u2019t be used, people can enter their device passcode or system password to authenticate passkey credentials. <\/p>\n<h3>How do I adopt passkeys?<\/h3>\n<p>The first step is to adopt WebAuthn on your back-end server and add our platform-specific API to your app. Take a deeper dive into next steps by watching the video below:<\/p>\n<section class=\"grid activity\">\n<section class=\"row\">\n<section class=\"column large-4 small-4 no-padding-top no-padding-bottom\"> <a href=\"https:\/\/developer.apple.com\/wwdc22\/10092\" class=\"activity-image-link\"> <img decoding=\"async\" class=\"actiity-image medium-scale\" width=\"250\" src=\"https:\/\/www.sickgaming.net\/blog\/wp-content\/uploads\/2023\/05\/qa-with-the-passkeys-team-1.jpg\" data-hires=\"false\" alt> <\/a> <\/section>\n<section class=\"column large-8 small-8 padding-left-small padding-top-small padding-bottom-small no-padding-top no-padding-bottom\"> <a href=\"https:\/\/developer.apple.com\/wwdc22\/10092\"> <\/p>\n<h4 class=\"no-margin-bottom activity-title\">Meet passkeys<\/h4>\n<p class=\"activity-description\">It\u2019s time for a security upgrade: Learn how to add support for passkeys to create a quick and easy sign in experience for people, all while offering a radical increase to account security. Passkeys are simple and strong credentials built to eliminate phishing attacks. We\u2019ll share how passkeys&#8230;<\/p>\n<p> <\/a> <\/section>\n<\/section>\n<\/section>\n<h3>What happens if a device is lost or stolen?<\/h3>\n<p>Data remains safe. Passkeys are end-to-end encrypted through iCloud Keychain and require biometrics, such as Face ID or Touch ID, or the device passcode to decrypt them. Without these, passkeys remain securely stored on the lost device. For extra peace of mind, you can always remotely wipe your device with Find My. <\/p>\n<h3>What does account recovery look like for someone who\u2019s only ever signed in with a passkey?<\/h3>\n<p>The recovery method is independent of the authentication mechanism. Apps and websites are welcome to maintain the same recovery methods they use today (such as sending a link in an email to create a new passkey). Recovery will likely be a much less common scenario with passkeys, which are saved by the device. There\u2019s nothing for a human to forget.<\/p>\n<h3>Can someone have multiple passkeys for my app; for instance, passkeys generated from multiple devices? <\/h3>\n<p>Yes, someone can have one passkey per account per platform. In the special case that someone has more than one account for an app, they\u2019ll have discrete passkeys for each account too.<\/p>\n<h3>What\u2019s the difference between passkeys and multifactor authentication?<\/h3>\n<p>Multifactor authentication adds additional layers of security on top of an existing password, but generally still leaves the possibility of phishing. Since passkeys eliminate the most pressing problems with passwords and are resistant to phishing, additional user-visible steps aren\u2019t needed.<\/p>\n<h3>Is it possible to use an email address as the visible account identifier instead of a username?<\/h3>\n<p>Yes, it\u2019s definitely possible. Our videos and documentation use usernames and email addresses as examples. Nothing about account identifiers has to change.<\/p>\n<h3>Resources<\/h3>\n<section class=\"grid activity\">\n<section class=\"row\">\n<section class=\"column large-4 small-4 no-padding-top no-padding-bottom\"> <a href=\"https:\/\/developer.apple.com\/wwdc22\/10092\" class=\"activity-image-link\"> <img decoding=\"async\" class=\"actiity-image medium-scale\" width=\"250\" src=\"https:\/\/www.sickgaming.net\/blog\/wp-content\/uploads\/2023\/05\/qa-with-the-passkeys-team-1.jpg\" data-hires=\"false\" alt> <\/a> <\/section>\n<section class=\"column large-8 small-8 padding-left-small padding-top-small padding-bottom-small no-padding-top no-padding-bottom\"> <a href=\"https:\/\/developer.apple.com\/wwdc22\/10092\"> <\/p>\n<h4 class=\"no-margin-bottom activity-title\">Meet passkeys<\/h4>\n<p class=\"activity-description\">It\u2019s time for a security upgrade: Learn how to add support for passkeys to create a quick and easy sign in experience for people, all while offering a radical increase to account security. Passkeys are simple and strong credentials built to eliminate phishing attacks. We\u2019ll share how passkeys&#8230;<\/p>\n<p> <\/a> <\/section>\n<\/section>\n<\/section>\n<section class=\"grid activity\">\n<section class=\"row\">\n<section class=\"column large-4 small-4 no-padding-top no-padding-bottom\"> <a href=\"https:\/\/developer.apple.com\/news\/?id=mgdnfp8w\" class=\"activity-image-link\"> <img decoding=\"async\" class=\"actiity-image medium-scale\" width=\"250\" src=\"https:\/\/www.sickgaming.net\/blog\/wp-content\/uploads\/2023\/05\/qa-with-the-passkeys-team-2.jpg\" data-hires=\"false\" alt> <\/a> <\/section>\n<section class=\"column large-8 small-8 padding-left-small padding-top-small padding-bottom-small no-padding-top no-padding-bottom\"> <a href=\"https:\/\/developer.apple.com\/news\/?id=mgdnfp8w\"> <\/p>\n<h4 class=\"no-margin-bottom activity-title\">Spotlight on: Passkeys<\/h4>\n<p class=\"activity-description\">Find out how Instacart, Kayak, and Robinhood are helping unlock a password-free future.<\/p>\n<p> <\/a> <\/section>\n<\/section>\n<\/section>\n<p><a href=\"https:\/\/developer.apple.com\/passkeys\/\" class=\"icon icon-after icon-chevronright\">Passkeys overview<\/a><\/p>\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT213305\" class=\"icon icon-after icon-chevronright\">About the security of passkeys<\/a><\/p>\n<p><a href=\"https:\/\/developer.apple.com\/documentation\/authenticationservices\/public-private_key_authentication\/supporting_passkeys\" class=\"icon icon-after icon-chevronright\">Supporting passkeys<\/a><\/p>\n<p><a href=\"https:\/\/developer.apple.com\/documentation\/authenticationservices\/connecting_to_a_service_with_passkeys\" class=\"icon icon-after icon-chevronright\">Connecting to a service with passkeys<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Get ready for a world without passwords. Passkeys are a replacement for passwords, offering a faster, easier, and more secure sign-in experience for your apps and websites. They\u2019re strong, resistant to phishing, and designed to work across Apple devices and nearby non-Apple devices. Best of all, there\u2019s nothing for people to create, guard, or remember. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":133725,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55],"tags":[],"class_list":["post-133724","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apple-developer-news"],"_links":{"self":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts\/133724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/comments?post=133724"}],"version-history":[{"count":0,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts\/133724\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/media\/133725"}],"wp:attachment":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/media?parent=133724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/categories?post=133724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/tags?post=133724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}