[ad_1]
Zoom In / Google says the login flow will go like this, left to right: Type your username, choose a passkey, scan a finger. I hope your device has biometric data.
Google is taking a big step towards our supposedly passwordless future by enabling passkey-only Google accounts. In the blog post, titled “The beginning of the end of the password”, Google says: “We have started rolling out support for passkeys across all Google Accounts on all major platforms. They will be an additional option for people to use to log in, set password, two-step verification (2SV), etc.” Previously, a passkey could be used with a Google Account as part of two-factor authentication, but it was always in addition to a password. It is now possible to use a Google Account with a passkey instead of a password.
A passkey, if you haven’t heard of the new authentication method, is a new way to log into apps and websites, and it could one day replace a password. Password entry started out as a simple text box for humans, and those text boxes were slowly given automation and complications as the desire for more security came along. Whereas before you typed a remembered word into a password field, today the proper way to use a password is to have a password manager paste a random string of characters into the password box. Since few of us physically type our passwords, passkeys clear the password box.
Passkeys allow your operating system to directly exchange public-private key pairs the “WebAuthn” standard with a website, and that’s how you get authenticated. Google’s demo of how this will work on a phone looks great: The usual box asks for your Google username, then instead of a password, it asks for a fingerprint, which unlocks the passkey system and you’re logged in.
Google’s passwordless support is direct for consumer devices right now, while enterprise Google Workspace accounts will “soon” have the ability to enable passkeys for end users.
The passkeys aren’t ready for prime time yet
Even with Google going all-in on passkeys, that doesn’t mean they’re ready for widespread adoption. First, some platforms (Windows/Linux/Chrome OS) are no match for others (macOS/iOS/Android). The official passkeys.dev site has a helpful page that tracks platform-by-platform readiness, and there’s still a long way to go. It would be terrible not being able to log into your Google account passkey on Chrome OS, which would presumably lock you out until you revert to a password.
Announcement
The second problem doesn’t look like it’s going to be fixed any time soon, and that is that passkeys sync through the OS ecosystem, not through a browser, which is a major regression from how passwords work. Today, if I add a password to Chrome on Windows, that password will be instantly available anywhere I have Chrome installed, such as an Android phone, MacBook, iPhone, Chromebook, etc., but passkeys don’t work like that.
To quote the FIDO Alliance page, the passkeys are “synced with all other user devices running the same OS platform” [emphasis ours]. This means that if I add a passkey to Chrome on Windows, that passkey goes into the Microsoft OS vendor’s passkey store and will only sync with other Microsoft OSes. If you’re using Apple devices exclusively, everything will sync up and you won’t notice a difference. The rest of us will have to go through a QR code and Bluetooth-based transfer process to get our credentials to work on Windows and Android or Android and Linux or any combination of different operating system vendors. The Big Tech companies in charge of passkeys don’t seem interested in making them as simple and convenient as passwords, and that will be a major obstacle to their ubiquity.
1Password confirms this whole sync mess: “Currently, passkeys on other platforms require using a device from the same ecosystem to authenticate. Syncing with other operating systems or sharing passkeys requires tedious workarounds, like QR codes , resulting in a more complicated process and a less secure experience.” It’s unclear whether apps like 1Password were invited to Big Tech’s passkey party. 1Password says it joined the FIDO Alliance, but 1Password’s passkey page also has a video saying the passkeys weren’t open enough. The video says, “Today’s solutions don’t deliver on that promise of openness and interoperability. If you create a password on your iPhone or Android device today, it’s pretty much trapped. It’s not easy to share, move it to another platform, or sync it with your carrier.” of preferred password. We can do better. And that’s why we’re excited to show you what the future could look like, if passwordless technology was more open.”
1Password’s passkey page contains a lot of “may” and “should” terms, but the company is working on some sort of fix that will be out “this summer.” Even if the company manages to fix the passkey syncing issue for their app, having such a major cross-platform regression in the default configuration, which is what most people will use, will seriously limit the attractiveness of passkeys.
Google ad image
|
Sources 2/ https://arstechnica.com/gadgets/2023/05/passwordless-google-accounts-are-here-you-can-now-switch-to-passkey-only/ The mention sources can contact us to remove/changing this article |
[ad_2]