Technology

X is bringing passkeys to Android — log in with a fingerprint, no password to steal. Here is what a passkey actually is

Two months after iPhone users got them, code found in X’s Android app shows passkey login is next: your fingerprint or face unlocks a cryptographic key on the phone, and there is no password for a phishing site to capture. What passkeys are, why they beat two-factor codes, and how to set one up on the services that already support them.

X is bringing passkeys to Android — log in with a fingerprint, no password to steal. Here is what a passkey actually is

In January X let iPhone and iPad users sign in with a passkey instead of a password. Android users are next: the reverse-engineer who posts as AssembleDebug found the code for passkey login in the latest version of X’s Android app, and although the company has announced nothing, the feature appears ready to switch on. It is a small change to one app and a useful moment to explain the thing that is quietly replacing passwords everywhere.

What a passkey is

A passkey is a pair of cryptographic keys made for one website or app. The public half lives on the service’s server; the private half lives on your phone, protected by whatever unlocks it — fingerprint, face or screen-lock PIN. When you sign in, the service sends a challenge, your phone signs it with the private key after you touch the sensor, and the service checks the signature with the public one. Nothing that could be reused ever leaves the device. Your fingerprint is not sent to X; it only unlocks the key locally. Through Google’s or Apple’s cloud, the passkey syncs to your other devices, so a new phone works without re-enrolling.

Why it is better than a password plus a code

Passwords can be guessed, leaked and reused. One-time codes by SMS can be intercepted or, more often, simply read out by the victim to a caller pretending to be the bank — the commonest fraud in Bangladesh. A passkey defeats both: there is no secret to guess or leak, and it only works on the exact domain it was created for, so a look-alike phishing site gets nothing even if you try to log in to it. That is why Google, Apple, Microsoft, PayPal, Amazon and now X are moving to them.

How to start using them

  1. Make sure your phone has a screen lock and, ideally, a fingerprint or face unlock.
  2. In a supporting service’s security settings — Google Account, Apple ID, Microsoft, PayPal, X on iOS today and Android soon — choose Create a passkey and confirm with your fingerprint.
  3. Keep the password as a fallback until every device you use supports passkeys; the two coexist.

Local services have not caught up: no Bangladeshi bank or mobile-money app offers passkeys yet, and their OTP-by-SMS logins remain the weak point that fraudsters target. When bKash or a bank does add them, this is the feature to switch on first.

Source: Gadgets 360, via Prothom Alo.

Source: Prothom Alo

Written by

Rakin M

Rakin M writes Tech BD’s security and privacy coverage — breaches, scams, surveillance and account safety. He is more interested in the step a reader can take this evening than in the name of the vulnerability, and says so in most of what he writes.