Forgot your password?
typodupeerror
Privacy Android Operating Systems Security

Android Rolling Out Passkey Transfers Between Password Managers (9to5google.com) 22

Android is rolling out a system-level way to securely transfer passwords and passkeys between credential managers, eliminating the need to export passwords as unencrypted text files or manually recreate passkeys. The feature initially supports Google Password Manager, 1Password, Bitwarden, and Dashlane, with other providers able to integrate through Android's Credentials Transfer API. 9to5Google reports on how to initiate the system-backed transfer method: 1. Start the move: Open your new password manager app and choose the option to import or copy your passwords and passkeys from another provider. The password manager will then hand the task over to Android.
2. Let Android securely coordinate the data transfer: Android will automatically detect existing password managers on your device and show you which you can import from.
3. Review and authorize: Once you tap "Continue," Android will bring you to your existing password manager to select, review, and authorize the transfer. Then your data will be quickly and securely transferred between the apps in just a few seconds.

Android Rolling Out Passkey Transfers Between Password Managers

Comments Filter:
  • "Dear user, please click the link below to transfer your passkeys securely to B1tward3n."

    • by Archangel Michael ( 180766 ) on Thursday September 10, 2026 @05:54PM (#66333052) Journal

      If passkeys are movable, then they can be duplicated and reused by nefarious actors as easy as this seems to indicate here.

      I have not, and do not, and never will trust passkeys as primary security for anything.

      Passkeys can be compelled legally, with and sometimes without a warrant. Passwords cannot be compelled at all. SCOTUS has already set the rules.

      • by Cyberax ( 705495 )
        Passkeys are by _definition_ moveable, so they can't be rooted in hardware. You can use WebAuthn to create device-rooted keys that never live the hardened secure enclave.
      • by AmiMoJo ( 196126 )

        You are forgetting that the alternative to a passkey is a password.

        Passwords can be stored in a password manager, where they have the same protections as a passkey. Or they can be stored in your brain, which will result in you either re-using them or forgetting them.

        Therefore passkeys are the better choice, because they avoid things like stupid per-site limits on password complexity, have more bits of entropy than most websites allow in a password, and are overall a better experience for the user, while bei

      • There's nothing magical with the passkeys, they're just like ssh keys. Their main advantage is that by doing asymmetrical cryptography you don't just hand over your secret (password) to someone, so you don't care if somehow you're talking to the wrong site, you don't even need to rotate your credentials if they get genuinely hacked.

        Protecting them locally is of secondary importance, but if you wish to be locked behind a password only you know in your password manager (most good ones nowadays do passkeys too

        • With Passkeys, they have access to your stuff without any oversight by courts and discovery. There are ZERO 4 and 5th Amendment rights to stuff protected by passkeys. They can compel you to unlock your phone, and put your finger on the print reader, and facial scan you .... all without your permission or CONSENT. As much stuff behind that initial Passkey on your phone (ApplePay/GoogleWallet, Banks, everything).

          Legally it is untenable how much access they have with Passkeys.

          Passcodes cannot be compelled (XKC

          • With Passkeys, they have access to your stuff without any oversight by courts and discovery. There are ZERO 4 and 5th Amendment rights to stuff protected by passkeys. They can compel you to unlock your phone, and put your finger on the print reader, and facial scan you .... all without your permission or CONSENT.

            The "With Passkeys" qualifier is unnecessary, ANYTHING you store in the cloud, or on your phone behind a fingerprint is up for grabs for any entity that has access to the cloud or can force you to u

          • So put a passcode in front of your passkeys, it isn't rocketscience.
    • by Anonymous Coward
      Yeah, it's the exact opposite of how it should be implemented: you should go to a password manager and initiate a system-backed EXPORT of passkeys to another password manager.
  • Hey, where did all of the animals go?

  • In addition to transferring your credentials to the new password manager of your choice, Android will also securely send a copy of them to the Google Cloud for extra security and peace of mind.

  • by bloodhawk ( 813939 ) on Friday September 11, 2026 @02:08AM (#66333572)
    passkeys started off as a wonderful tech that you could ensure were bound to a device even if a little difficult for some newbies to use. Now through Apple et al they have now become as shitty as the tech they were designed to replace where they can be transferred and stolen by scammers through social engineering scams.
  • You all, are correct: There's no point having Passkeys if they can be copied from disk to disk, that's repeating the problems with passwords but as a digital file. Which is why the term "credential" appears. Passkeys can move only from one approved application to another. At the moment, that means 'via the cloud'. So it all depends on online security. An average user probably hasn't enabled TOTP/"Yubi-key" verification, which makes the system, slightly vulnerable: See below.

    The parallel is obvious;

    • With Android, iOS and MacOS they aren't on disk exactly. The database is encrypted with a hardware bound key and only opened inside a secure enclave. Windows Hello probably too.

      • PS. as long as you stay inside the Apple ecosystem I think you always need one device left registered to the account (directly or through recovery contact) to restore the backup. I don't think the customer service based account recovery (last ditch, prove identity through passport/etc) recovers the passkeys from icloud backup. Every ecosystem will differ.

    • There's no point having Passkeys if they can be copied from disk to disk, that's repeating the problems with passwords but as a digital file.

      By that logic there's no point to have ssh keys, they're just files that can be copied. But of course there is, you're doing a complicated dance to prove you have the secret - WITHOUT TELLING YOUR SECRET PASSWORD TO SOMEONE EACH TIME YOU LOGIN

  • I never expected Google and Apple to export to third party vaults, or the user hostile FIDO to create a standard to export to non manufacturer attested endpoints.

  • My password manager and the NSA's password manager?

  • They allow you to store your database on a third party hosting site (Dropbox, etc.) so it isn't even actually on your phone unless you are using it. Nothing to transfer but the app itself. Great if your phone is lost or non-functional.

    As long as you can remember the password to your hosting site, of course.

You must realize that the computer has it in for you. The irrefutable proof of this is that the computer always does what you tell it to do.

Working...