{"id":21922,"date":"2023-05-04T02:30:06","date_gmt":"2023-05-04T10:30:06","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2023\/05\/04\/news-15653\/"},"modified":"2023-05-04T02:30:06","modified_gmt":"2023-05-04T10:30:06","slug":"news-15653","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/05\/04\/news-15653\/","title":{"rendered":"How to use Google passkeys for stronger security on Android"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2021\/12\/android-security-100913715-small.jpg\"\/><\/p>\n<p>Still signing into your Google account by tapping out an actual password? That&#8217;s, like, <em>so <\/em>2022.<\/p>\n<p>Now, don&#8217;t get me wrong: The tried-and-true password is perfectly <em>fine<\/em>, especially if you&#8217;re using it <a href=\"https:\/\/www.computerworld.com\/article\/3528554\/10-steps-to-smarter-google-account-security.html#:~:text=Step%202%3A%20Give%20your%20Google%20account%20a%20second%20layer%20of%20protection\">in conjunction with two-factor authentication<\/a>. But particularly for something as important as your Google account, you want to have the most effective security imaginable to keep all your personal and\/or company info safe.<\/p>\n<p>And starting this week, you&#8217;ve got a much better way to go about that.<\/p>\n<p>So here it is: Google <a href=\"https:\/\/blog.google\/technology\/safety-security\/the-beginning-of-the-end-of-the-password\/\" rel=\"noopener nofollow\" target=\"_blank\">just announced<\/a> the first official availability of something called passkeys as a way to sign into Google services. In the simplest possible terms, using a passkey means anytime you&#8217;d traditionally be prompted to put in your Google account password, you&#8217;ll instead be able <a href=\"https:\/\/www.csoonline.com\/article\/3695173\/google-rolls-out-passkey-support-across-accounts-on-all-major-platforms.html\" rel=\"noopener\" target=\"_blank\">to securely authenticate yourself<\/a> via your phone&#8217;s face identification system or fingerprint scanner.<\/p>\n<p><strong>[Get fresh Googley advice and insight in your inbox every Friday with my <\/strong><a href=\"https:\/\/www.androidintel.net\" rel=\"noopener nofollow\" target=\"_blank\"><strong>Android Intelligence newsletter<\/strong><\/a><strong>. Three new things to try every Friday!]<\/strong><\/p>\n<p>Why&#8217;s that so much better, you might be wondering? Well, I&#8217;ll tell ya:<\/p>\n<p>That last part is important, as it basically combines the idea of two-factor authentication with a regular password into a single tough-to-circumvent system. In order for someone to hack into your account with a passkey in place, they&#8217;d have to have your physical phone in their hands, have <em>you<\/em> unlock it with your face or fingerprint (provided you&#8217;re using biometric authentication), and <em>then <\/em>have you use your greasy mug or fingie once more to sign into the account itself.<\/p>\n<p>The problem with passkeys is that up until now, they&#8217;d mostly been a theoretical thing. Until a large number of apps, sites, and services support &#8217;em, they really don&#8217;t mean much.<\/p>\n<p>But now, the biggest gorilla of &#8217;em all is on board. And that means it&#8217;s time for you to take notice.<\/p>\n<p>All right \u2014 ready to upgrade your <a href=\"https:\/\/www.computerworld.com\/article\/3528554\/10-steps-to-smarter-google-account-security.html\">Google account security<\/a> with an Android-based passkey?<\/p>\n<p>It&#8217;ll take you about 10 seconds to do:<\/p>\n<p>Aaaaand, that&#8217;s it! (Told ya it was easy, didn&#8217;t I?!) On Android, Google automatically creates a passkey for you as soon as you sign into your Google account. So all you&#8217;ve gotta do is activate it and opt in, like you just did, and boom: You&#8217;re in business.<\/p>\n<p>The one caveat is that if you&#8217;re using a company-connected Google Workspace account, your organization&#8217;s administrator will have to first enable the option for passkeys to be permitted \u2014 and Google hasn&#8217;t made that setting available quite yet (though the company says it&#8217;ll be there &#8220;soon&#8221;). So stay tuned and stand by, if you&#8217;re in that situation.<\/p>\n<p>Once you get things going, though, the bits and bytes that make your passkey work will be stored securely on your actual Android phone and never shared with anyone, including Google itself. Even when you authenticate, the passkey just gets unlocked <em>locally<\/em> and then your phone confirms to Google that you&#8217;re good to go. Because of that, there&#8217;s no possible way to share the info or inadvertently grant access to a scoundrel, miscreant, or garden-variety rapscallion \u2014 which means phishing and breaches are no longer a worry.<\/p>\n<p>Last but not least, the <em>really <\/em>cool part: This doesn&#8217;t just affect sign-ins on your phone. It also works for when you&#8217;re signing into your Google account on <em>other<\/em> devices.<\/p>\n<p>With your passkey set up and active, the next time you try to sign into your Google account on any phone, tablet, computer, or internet-connected camel, you&#8217;ll see a prompt asking you to use your passkey on your phone to prove it&#8217;s you. Clicking through will cause a notification to pop up on your phone, and when you tap it, the phone will prompt you for your biometric authentication and then connect to the <em>other <\/em>device to confirm that you&#8217;re approved.<\/p>\n<p>You won&#8217;t even be asked for two-factor authentication, as you&#8217;ve ultimately already provided it.<\/p>\n<p>Simple, secure, and safe from shady shenanigans. What more could you ask for?!<\/p>\n<p><i>Ready to complete your Android Intelligence upgrade? <a href=\"https:\/\/www.androidintel.net\" rel=\"noopener nofollow\" target=\"_blank\"><strong>Come check out my free weekly newsletter<\/strong><\/a> to get all sorts of invaluable experience-enhancing info in your inbox each week, straight from me to you.<\/i><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3695076\/google-passkeys-android-security.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2021\/12\/android-security-100913715-small.jpg\"\/><\/p>\n<article>\n<section class=\"page\">\n<p>Still signing into your Google account by tapping out an actual password? That&#8217;s, like, <em>so <\/em>2022.<\/p>\n<p>Now, don&#8217;t get me wrong: The tried-and-true password is perfectly <em>fine<\/em>, especially if you&#8217;re using it <a href=\"https:\/\/www.computerworld.com\/article\/3528554\/10-steps-to-smarter-google-account-security.html#:~:text=Step%202%3A%20Give%20your%20Google%20account%20a%20second%20layer%20of%20protection\">in conjunction with two-factor authentication<\/a>. But particularly for something as important as your Google account, you want to have the most effective security imaginable to keep all your personal and\/or company info safe.<\/p>\n<p>And starting this week, you&#8217;ve got a much better way to go about that.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3695076\/google-passkeys-android-security.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[10462,1670,714],"class_list":["post-21922","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-android","tag-google","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21922","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=21922"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21922\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=21922"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=21922"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=21922"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}