They did, but it's no Apple watch unfortunately, and the company was first bought by Fitbit, then Google, and they don't make them anymore.Didn't Pebble use e-Ink? I loved Pebble.
It's really disappointing that the Apple Watch is actually losing functionality over time...
If you were able to install it yourself, then I have a hard time believing this was the US federal government, and yes that's what I'm referring to (14 million employees). I guess it's me calling bull**** now.I'm was able to install it myself.
I think you are confusing policies with installing outside software with outlawing of password managers. Again, it's not reasonable to expect 10s of thousands of people to remember multiple random 15 character passwords without writing them down.
The idea that you've worked with enough companies represent 80% of government employees is not reasonable. Maybe you are only referring to the US federal government.
I never said it was federal government. And you never specified federal government.If you were able to install it yourself, then I have a hard time believing this was the US federal government, and yes that's what I'm referring to (14 million employees). I guess it's me calling bull**** now.
A quick web search reveals GSA approved password managers.I'm not confusing anything with anything. The policy is that you cannot use password managers, AND that you cannot install anything yourself even if you did get special approval for a password manager - and this applies everywhere I have ever been. I've also never worked anywhere, commercial or otherwise, where you weren't expected to remember your passwords.
Well you clearly don't have much experience then; as I said before GSA, NIST, NCSC, ENISA, all recommend it. OWASP, Cyber Essentials compliance at all impact levels is as good as impossible to implement without it without excluding controls. Sure I believe wholy that there are some government department who don't provide this for whatever reason, but that is not how this started. You very clearly and unambigously stated that this is not allowed. Well on the contrary, it is recommended to implement.If you were able to install it yourself, then I have a hard time believing this was the US federal government, and yes that's what I'm referring to (14 million employees). I guess it's me calling bull**** now.
I'm not confusing anything with anything. The policy is that you cannot use password managers, AND that you cannot install anything yourself even if you did get special approval for a password manager - and this applies everywhere I have ever been. I've also never worked anywhere, commercial or otherwise, where you weren't expected to remember your passwords.
Typical Google.They did, but it's no Apple watch unfortunately, and the company was first bought by Fitbit, then Google, and they don't make them anymore.
I never said it was federal government. And you never specified federal government.
A quick web search reveals GSA approved password managers.
So to be clear, your original claim that "No government organization allows the use of a password manager, period." is obviously wrong based on my experience is a state government organization, common sense, and a quick web search.
And your revised claim that US federal government policy "is that you cannot use password managers" is also easily refuted by a quick web search.
Well you clearly don't have much experience then; as I said before GSA, NIST, NCSC, ENISA, all recommend it. OWASP, Cyber Essentials compliance at all impact levels is as good as impossible to implement without it without excluding controls. Sure I believe wholy that there are some government department who don't provide this for whatever reason, but that is not how this started. You very clearly and unambigously stated that this is not allowed. Well on the contrary, it is recommended to implement.
What we agree on is that the build should be controlled for most and I find it very odd as well that anyone is allowed (beyond controlled environments) to install their own software. Again, that would go against the same recommendations for a secure build.
But not being able to installed your own version, a particular department or agency not having any, and the statement that password management software is not allowed in government is not the same thing.
I don't think you have described the notifications correctly. In my experience, notifications always show up on the my phone. If you are actively using the phone, they only show up on the phone. If you are not using the phone, they also show up on the watch. Makes sense to me.
99% of the wearers use it for tracking steps and various health and safety activities.
I was in that bandwagon, a quick watch notification to approve and bam, done, it was great.Same. I probably use this more than any other tool throughout my entire day - signing in over and over again into different powershell modules. All this is going to do is force me to find another method of authentication with the watch.
Same for me.Good. Never even worked for me. Absolutely pointless having it on the watch.
No government organization allows the use of a password manager, period. Shell support is not going to work in this scenario.
Not sure where in the world you are but in the USA the GSA, CISA and NIST begs to differ, in the UK the NCSC begs to differ, in the EU ENISA/CSIRT begs to differ. You couldn't possibly create secure, unique passwords if you don't. I'm sorry but I'm calling bull ****.
And then you go again, and that is the reason I respond as I do. For your benefit I've quoted the previous posts as it seems there is some short-term memory loss. Yes, I didn't quote DISA, guess what I already include CISA and NIST in the original responses. My sincere apologies, I didn't quote the full list of every agency. But seriously dude, CISA, NIST, NCSC, ENISA are not non-security organizations. They are some examples of organizations totally related to cybersecurity, investigations, and standards.Can I ask why virtually every comment you make starts off by trying to insult the experience or credibility of the person you're speaking to? You have claimed a bunch of non-security organizations recommend it... Even civilian federal agencies follow the guidance of DISA when it comes to security. I was trying to glean information from the both of you to help my own crusade to push this into use - which I have done before with other product types.
And you continue digging that hole, for your benefit I've included what you actually said. Limiting to the US Federal government makes no difference, that is just a red herring. The guidance from GSA, CISA, NIST, NCSC, ENISA is no different and does not exclude that.This all started by me claiming that there are millions of us that cannot use password managers, let alone jumping from machine to machine, in our daily jobs. You were quickly hung up on the government part of it and you're both right that I should have specified US federal government - nothing else can even be spoken to with any sort of authority as every state government I've seen has its own rules, and beyond that even worse.
And yes, some of has have been doing this even before there were consumer grade password managers. Even the good old IBM VM Mainframe had it build in.We haven't agreed or disagreed on any of this, I'm not arguing against password managers. I told you that they cannot replace this functionality in the role of millions of engineers, to which you said that I must not know that I actually could. I've told you that I've never worked anywhere where you weren't expected to remember passwords, to which you replied that I must not have much experience. Do you not see the very narrow line you're trying to walk with this discussion? I've worked for the big tech companies, I've worked in the .com industry, I've worked for government, I've consulted to the military, worked in banking, worked in the legal community, all in the role of an enterprise infrastructure engineer or architect. Not once, anywhere, did someone say, "Hey, create a password then store it in our password manager". You might be seeing that somewhere recently as I've been holed up in the government since before the pandemic, but let me assure you that we aren't there yet. And if I were to make a silly claim about it being unreasonable to expect me to remember these things when every document out there even describes how to remember them...I'd be laughed at.
This is likely due to Microsoft introducing number matching to ward off MFA fatigue attacks:
![]()
Microsoft Authenticator Gets Number Matching and Other Security Features
Microsoft has announced the general availability of several new security capabilities in its Microsoft Authenticator app. The first new feature that the company highlighted today is number matching support, which prompts users to enter a number displayed on the sign-in screen to verify their ide ...petri.com
Probably not worth the dev time or finding a suitable way for this to work on the watch app - not not enough take up to be worth it I guess.
If you're not actively using either, than it is delivered to both. I don't see the problem.Sure, if you're actively using one or the other the notifications work great. For the rest of the day, it doesn't.
It also goes to your phone.Phone's on the table next to you while you're wearing a coat that covers your watch? Notification goes to your watch where you can't see it.
Yep, but I see that as a fringe case. Why would you consistently leave your phone unlocked while not using it?Put your phone down and look away without locking it? Notification goes to your phone.
Again, it's only additive. All notifications are still delivered to your phone.The Apple Watch was supposed to reduce how much I missed such notifications. Certainly it helps me catch some. But it also makes me miss some, for absolutely no reason at all other than Apple's arbitrary rules that cannot be changed.
I've always said copyright infringement is the number one reason that people want sideloading.Sideloading with iOS 17 can't come soon enough - I'm hoping we get a TinkerTool equivalent on day one, to go and change all the preferences that Apple engineers created but never exposed through the UI.
What? I want sideloading so I can develop and distribute free apps.I've always said copyright infringement is the number one reason that people want sideloading.![]()