Forum Moderators: phranque

Message Too Old, No Replies

Google Passkeys Ready To Use: Passwordless Solution

         

engine

3:09 pm on May 3, 2023 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Google has moved to release Passkeys, which is a way of creating a passwordless solution, and works on the local computer or device.This concept was announced last year when the FIDO Alliance won additional support for passwordless Sign-Ins [webmasterworld.com]
Moving away from passwords has long been the goal of many sectors of the industry, slowly tacking on additional security with, for example, SMS or 2FA. It still required a valid password. Because this relies on user security of their device or computer, it's felt that this is a more secure way of protecting an account. Passkey works across all platforms and browsers adopting these standards.

For those of us using multiple devices, there is a solution, but it does seem a little cumbersome.
When you do need to use a passkey from your phone to sign in on another device, the first step is usually to scan a QR code displayed by that device. The device then verifies that your phone is in proximity using a small anonymous Bluetooth message and sets up an end-to-end encrypted connection to the phone through the internet. The phone uses this connection to deliver your one-time passkey signature, which requires your approval and the biometric or screen lock step on the phone. Neither the passkey itself nor the screen lock information is sent to the new device. The Bluetooth proximity check ensures remote attackers can’t trick you into releasing a passkey signature, for example by sending you a screenshot of a QR code from their own device.


[security.googleblog.com...]