this post was submitted on 17 Oct 2023
53 points (100.0% liked)

Android

18976 readers
3 users here now

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

πŸ”—Universal Link: [email protected]


πŸ’‘Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.


Support, technical, or app related questions belong in: [email protected]

For fresh communities, lemmy apps, and instance updates: [email protected]

πŸ’¬Matrix Chat

πŸ’¬Telegram channels / chats

πŸ“°Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to [email protected].

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to [email protected].

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities

Lemmy App List

Chat and More


founded 2 years ago
MODERATORS
all 19 comments
sorted by: hot top controversial new old
[–] [email protected] 16 points 2 years ago (3 children)

I like the idea of passkeys, but one thing that I'm still not clear on is what happens to them when I get a new phone.

It says the passkeys are stored on the device, so would I need to keep my previous phone around to be able to sign in on the new phone?

[–] [email protected] 12 points 2 years ago* (last edited 2 years ago) (3 children)

Password managers like 1Password and Bitwarden support it already or are planning to in the near future, so you will be able to sync them across devices. And I'm pretty sure they will be stored in the iCloud and Google password managers as ways to lock in users even more

[–] [email protected] 3 points 2 years ago

I use Bitwarden, so that will make things easy.

Thank you!

[–] [email protected] 1 points 2 years ago

Exactly what I've been doing. I don't like them being saved on-device, and I don't want to create multiple, so 1password handles it for me. Has been really convenient, however only around 10 platforms total have let me add a passkey, out of some 1300 passwords I have registered. Quite a slow rollout

[–] [email protected] 4 points 2 years ago

I'm with ya. I need to see kind of how it pans out. How smooth it is, how device changing works, how in general sites handle lost passkeys. Then I'll decide. I want security but I'm also not looking for even more hassle then my current method of strong passwords and 2FA.

[–] [email protected] 3 points 2 years ago (1 children)

Keys, like everything in digital devices, are just strings of data. So if they are on device, it's the matter where they are stored on the device.

Google and Apple implementations are going to store them in secure TPM chip, basically once written there should be no way (people knowing darker side of TPM can disagree) to get them back. But, if I understand correctly, there is no forced way how to store them in the spec, there can just be a way Google implement it in such a way, hope they add open API to Android.

[–] [email protected] 15 points 2 years ago (3 children)

I won't begin using passkeys until keepass supports them and I don't know when that will be.

[–] [email protected] 7 points 2 years ago (1 children)

You sent me to this rabbithole and here's the relevant issue for those who are also interested github

TLDR: devs are on board, PR is being actively developed and reviewed. ETA is unclear but is sooner rather then ~~never~~ later

[–] [email protected] 1 points 2 years ago

Awesome to hear!

[–] [email protected] 5 points 2 years ago

Same here. Though this transition in general will take forever as you'll always have that one odd site that doesn't support passkeys even when it gains mass adoption.