Android Rolling Out Passkey Transfers Between Password Managers (9to5google.com) 22
Android is rolling out a system-level way to securely transfer passwords and passkeys between credential managers, eliminating the need to export passwords as unencrypted text files or manually recreate passkeys. The feature initially supports Google Password Manager, 1Password, Bitwarden, and Dashlane, with other providers able to integrate through Android's Credentials Transfer API. 9to5Google reports on how to initiate the system-backed transfer method: 1. Start the move: Open your new password manager app and choose the option to import or copy your passwords and passkeys from another provider. The password manager will then hand the task over to Android.
2. Let Android securely coordinate the data transfer: Android will automatically detect existing password managers on your device and show you which you can import from.
3. Review and authorize: Once you tap "Continue," Android will bring you to your existing password manager to select, review, and authorize the transfer. Then your data will be quickly and securely transferred between the apps in just a few seconds.
2. Let Android securely coordinate the data transfer: Android will automatically detect existing password managers on your device and show you which you can import from.
3. Review and authorize: Once you tap "Continue," Android will bring you to your existing password manager to select, review, and authorize the transfer. Then your data will be quickly and securely transferred between the apps in just a few seconds.
How long until the scams begin? (Score:2)
"Dear user, please click the link below to transfer your passkeys securely to B1tward3n."
Re:How long until the scams begin? (Score:4, Insightful)
If passkeys are movable, then they can be duplicated and reused by nefarious actors as easy as this seems to indicate here.
I have not, and do not, and never will trust passkeys as primary security for anything.
Passkeys can be compelled legally, with and sometimes without a warrant. Passwords cannot be compelled at all. SCOTUS has already set the rules.
Re: (Score:3)
Re: (Score:2)
You are forgetting that the alternative to a passkey is a password.
Passwords can be stored in a password manager, where they have the same protections as a passkey. Or they can be stored in your brain, which will result in you either re-using them or forgetting them.
Therefore passkeys are the better choice, because they avoid things like stupid per-site limits on password complexity, have more bits of entropy than most websites allow in a password, and are overall a better experience for the user, while bei
Re: (Score:3)
There's nothing magical with the passkeys, they're just like ssh keys. Their main advantage is that by doing asymmetrical cryptography you don't just hand over your secret (password) to someone, so you don't care if somehow you're talking to the wrong site, you don't even need to rotate your credentials if they get genuinely hacked.
Protecting them locally is of secondary importance, but if you wish to be locked behind a password only you know in your password manager (most good ones nowadays do passkeys too
Re: (Score:2)
With Passkeys, they have access to your stuff without any oversight by courts and discovery. There are ZERO 4 and 5th Amendment rights to stuff protected by passkeys. They can compel you to unlock your phone, and put your finger on the print reader, and facial scan you .... all without your permission or CONSENT. As much stuff behind that initial Passkey on your phone (ApplePay/GoogleWallet, Banks, everything).
Legally it is untenable how much access they have with Passkeys.
Passcodes cannot be compelled (XKC
Re: (Score:2)
The "With Passkeys" qualifier is unnecessary, ANYTHING you store in the cloud, or on your phone behind a fingerprint is up for grabs for any entity that has access to the cloud or can force you to u
Re: (Score:2)
Re: (Score:1)
barn door (Score:2)
Hey, where did all of the animals go?
And send them to Google (Score:2)
In addition to transferring your credentials to the new password manager of your choice, Android will also securely send a copy of them to the Google Cloud for extra security and peace of mind.
enshitification of passkeys (Score:3)
Everytime, there's a catch-22. (Score:2)
The parallel is obvious;
Re: (Score:2)
With Android, iOS and MacOS they aren't on disk exactly. The database is encrypted with a hardware bound key and only opened inside a secure enclave. Windows Hello probably too.
Re: (Score:2)
PS. as long as you stay inside the Apple ecosystem I think you always need one device left registered to the account (directly or through recovery contact) to restore the backup. I don't think the customer service based account recovery (last ditch, prove identity through passport/etc) recovers the passkeys from icloud backup. Every ecosystem will differ.
Re: (Score:2)
By that logic there's no point to have ssh keys, they're just files that can be copied. But of course there is, you're doing a complicated dance to prove you have the secret - WITHOUT TELLING YOUR SECRET PASSWORD TO SOMEONE EACH TIME YOU LOGIN
Colour me surprised (Score:2)
I never expected Google and Apple to export to third party vaults, or the user hostile FIDO to create a standard to export to non manufacturer attested endpoints.
Different Password Managers (Score:2)
My password manager and the NSA's password manager?
Keepass does this better (Score:2)
As long as you can remember the password to your hosting site, of course.
Re: (Score:2)