Face ID and Touch ID Logins Coming to Websites With Safari Web Authentication API

Apple allows Touch ID and Face ID to be used in lieu of a password to access sensitive apps like those for banking or password management, and in the future, ‌Face ID‌ and ‌Touch ID‌ will also be able to be used for authentication purposes when logging into a website.

faceidwebsites
Apple outlines the feature in a WWDC20 engineering session called "Meet ‌Face ID‌ and ‌Touch ID‌ for the web," which covers how web developers can use ‌Face ID‌ and ‌Touch ID‌ on their websites with the Web Authentication API.

An initial login on a website that supports the feature will require a username, passcode, and two-factor authentication code to be entered, but after that, ‌Face ID‌ or ‌Touch ID‌ can handle the login process. Signing in this way will require users to click on the sign in button, after which Safari will ask for confirmation. With the confirmation, a ‌Face ID‌ (or ‌Touch ID‌) scan is done, and the user is able to log in.

Apple says ‌Face ID‌ and ‌Touch ID‌ authentication is beneficial because it's frictionless, simple, and secure. The online session described it as "phishing resistant."

But more importantly, it is Phishing-resistant. Safari will only allow public credentials created by this API to be used within the Web site they were created, and the credential can never be exported out from the authenticater they were created in as well. This means that once a public credential has been provisioned, there is no way for a user to accidentally divulge it to another party. Cool right?! This is the overview of the Web Authentication standard.

Additional detail about the feature, including instructions on how web developers can enable it, can be found in the full video along with the accompanying resources.

Top Rated Comments

swm Avatar
27 months ago
i see the future, where the password manager app developers protest for a senate hearing about apple's monopolistic business practices
Score: 12 Votes (Like | Disagree)
konqerror Avatar
27 months ago

What if you have a non Apple device in your family of Apple devices?
You can’t very easily login there. I hope Apple will work with IEEE to set a standard for this so everyone can participate.
This is already a standard, called FIDO2. If you have non-Apple devices, sites allow multiple keys, or simply forget this and use an external USB/NFC/Bluetooth key.


I don’t really see how this is much more convienient that just using FaceID to grant access to the keychain?
One: it is phising-resistant, two: if the data was intercepted or the other side has a database leak, the information is worthless since it cannot be used for future logins.
Score: 5 Votes (Like | Disagree)
ArtOfWarfare Avatar
27 months ago

so I believe Sign In with Apple creates/connects an account with your Apple ID

This is basically a faster FaceID/TouchArcade reauthentication for your existing accounts.

The video demos it.

arn
TouchArcade ???
I assume autocorrect strikes again.
Score: 4 Votes (Like | Disagree)
konqerror Avatar
27 months ago

I know FIDO2, that’s different. It’s basically a hardware token system. It’s not compatible with Sign In with Apple, which is SSO via Apple.
Did you read the article? It's saying that Apple platforms will act as a built-in FIDO2 authenticator; something that Windows and Android already do today.

Exactly like Microsoft did, they implemented FIDO2 locked to their own site first, and are now expanding it to other sites.
Score: 4 Votes (Like | Disagree)
kiensoy Avatar
27 months ago
Another “finally” of the many in iOS14.
Score: 3 Votes (Like | Disagree)
dwaltwhit Avatar
27 months ago
I can’t wait til we don’t even use passwords anymore
Score: 3 Votes (Like | Disagree)

Popular Stories

top stories 2jul2022

Top Stories: M2 MacBook Air Release Date, New HomePod Rumor, and More

Saturday July 2, 2022 6:00 am PDT by
The M2 MacBook Pro has started making its way into customers' hands and we're learning more about how it performs in a variety of situations, but all eyes are really on the upcoming M2 MacBook Air which has seen a complete redesign and should be arriving in a couple of weeks. Other top stories this week included a host of product rumors including additional M2 and even M3 Macs, an updated...
Mac Studio IO

Apple Begins Selling Refurbished Mac Studio Models

Thursday June 30, 2022 7:42 pm PDT by
Apple today began selling refurbished Mac Studio models for the first time in the United States, Canada, and select European countries, such as Belgium, Germany, Ireland, Spain, Switzerland, the Netherlands, and the United Kingdom. In the United States, two refurbished Mac Studio configurations are currently available, including one with the M1 Max chip (10-core CPU and 24-core GPU) for...
macbook air m2

Exclusive: Apple Plans to Launch MacBook Air With M2 Chip on July 15

Wednesday June 29, 2022 5:23 pm PDT by
The redesigned MacBook Air with the all-new M2 Apple silicon chip will be available for customers starting Friday, July 15, MacRumors has learned from a retail source. The new MacBook Air was announced and previewed during WWDC earlier this month, with Apple stating availability will begin in July. The MacBook Air features a redesigned body that is thinner and lighter than the previous...
13 inch macbook pro m2 mock feature 2

M2 MacBook Pro Much Slower Than Previous Model

Friday July 1, 2022 2:24 am PDT by
Apple's new 13-inch MacBook Pro with the M2 chip features a significantly slower SSD compared to the previous model, resulting in poorer performance in some workflows, it has been discovered. Specifically, it has been found that the $1,299 base model with 256GB of storage has significantly slower SSD read and write speeds compared to the equivalent previous-generation 13-inch MacBook Pro....