2 ms·
That's a bit snarky. As other commenters mentioned, it can leverage TEEs using the Android Keystore for secure storage. And the way WebAuthn works means users a
by Rafert 7y ago
That's a bit snarky. As other commenters mentioned, it can leverage TEEs using the Android Keystore for secure storage. And the way WebAuthn works means users are protected in case of a database breach (it contains only public keys) and the protocol protects against phishing. Both are ways better than usernames and passwords.
It got certified (at level 1[0]) too, in case that changes your mind: https://fidoalliance.org/android-now-fido2-certified-accelerating-global-migration-beyond-passwords/ https://fidoalliance.org/android-now-fido2-certified-acceler...
[0]: https://fidoalliance.org/certification/authenticator-certification-levels/authenticator-level-1/ https://fidoalliance.org/certification/authenticator-certifi...
- oneplane 7y agoI was intended to be a bit snarky indeed. I know TEE's and remote attestation are supposed to help out here, but I also know that even a purpose-designed chip couldn't get it right the first few times (think MIFARE NFC, TPMs and YubiKeys with Infineon cores). It's a very hard problem, and making light of it by having marketing (big assumption) play it as if a phone is now a security key seems a bit of a leap here. At the same time, WebAuthn is better in itself but still not the silver bullet versus passwords and a password manager. We don't live in an ideal world of course, but if we are going to turn commodity multipurpose devices into soft tokens, we might as well name it as such. (but naming it that way definitely doesn't have the same ring to it: "Your Phone is a Soft Token").