Google’s passkey gamble: a cage for innovation?

Google’s quietly rolling out a feature that could effectively trap Android users within its password manager, undermining the very promise of passkeys. It’s a frustratingly familiar story – the tech giant lagging behind on a fundamental shift in online security, and now, potentially, locking users in a walled garden.

The silent shift: importing passkeys, not exporting

Initially, the rollout resembled a helpful upgrade: “Import passwords and passkeys” and “Export passwords and passkeys” now grace Google Password Manager’s settings. Users can seamlessly migrate from other compatible managers like Bitwarden, a process that sounds convenient on the surface. But the devil, as always, is in the details. The crucial point is the lack of portability. Moving passkeys out of Google’s ecosystem means deleting them entirely and starting over on the new app – a decidedly un-portable experience.

Apple’s lead: pioneering portability

Apple’s lead: pioneering portability

This isn’t a new problem. Apple, notoriously resistant to collaboration, shipped the ability to move passkeys to Bitwarden and 1Password last year on iOS and macOS. iPhone users have been leveraging this functionality for months, demonstrating that true cross-platform portability is achievable. Android users, meanwhile, have been stuck with a frustrating workaround: creating passkeys within Google’s manager, only to lose them if they dared to switch to a competitor. It’s a deliberate form of digital lock-in masked as enhanced security.

The cxp protocol: the technology behind the hand-off

The cxp protocol: the technology behind the hand-off

Underneath the surface, the technology enabling this transition is the Credential Exchange Protocol (CXP), developed by the FIDO Alliance. This protocol allows for secure and seamless transfer of passkeys between different apps and services. The good news is that the CXP is backed by industry giants – Google, Apple, Samsung, and Bitwarden – meaning most users will likely benefit from this development. But the fact remains: Google is still playing catch-up.

Why this matters now

The promise of passkeys – phishing-resistant logins, biometric authentication, and an end to password reuse – is genuinely compelling. Yet, Google’s reluctance to embrace true portability casts a shadow over this potential revolution. It’s a missed opportunity, a strategic misstep that could ultimately hinder the widespread adoption of a far more secure online experience. The fact that Apple, a company often viewed with suspicion by the tech establishment, managed to deliver this feature first is, frankly, embarrassing for Google. They built Android, the very platform designed to champion these advancements, and yet they’re struggling to provide the basic functionality that users demand.

A crucial decision

Ultimately, Google’s decision here reflects a fundamental question about trust and control. Do users truly want to be tethered to a single password manager, even if that manager offers a degree of perceived security? I personally haven’t felt the pressure of needing to migrate passkeys, relying instead on Google Authenticator for many of my accounts. However, the growing chorus of complaints from those who have invested heavily in this technology is undeniable. It’s time for Google to demonstrate that it understands the importance of user freedom and interoperability – or risk being left behind in the evolving landscape of online security. A truly secure login shouldn’t feel like a cage.