3 ms·
On Android any way you've set up to unlock the device can be used to also authenticate locally for unlocking the key material (stored inside a TEE): swipe patte
by Rafert 6y ago
On Android any way you've set up to unlock the device can be used to also authenticate locally for unlocking the key material (stored inside a TEE): swipe pattern, finger print, PIN code, password, etc. Once that is done the key material is used with WebAuthn protocol which is fairly straightforward public key crypto operations that have been well vetted.
Based on this video we don't know exactly if Apple allows that to be done as well, but it seems within the realm of possibility based on how Apple Pay works (which AFAIK can use a passcode).
Either way discarding the entire protocol because of one implementation is silly. With Apple joining Google, Microsoft and many other companies supporting WebAuthn (a W3C standard) there's a lot of support for it to make logging in easier and more secure. SQRL never got any real traction.