Skip to main content

Apple, Google, and Microsoft will soon implement passwordless sign-in on all major platforms

Apple, Google, and Microsoft will soon implement passwordless sign-in on all major platforms

/

The tech giants want to roll out FIDO passkey technology in the coming year

Share this story

Illustration by Alex Castro / The Verge

On May 5th — World Password Day — we might have come one step closer to passwords being a thing of the past.

In a joint effort, tech giants Apple, Google, and Microsoft announced Thursday morning that they have committed to building support for passwordless sign-in across all of the mobile, desktop, and browser platforms that they control in the coming year. Effectively, this means that passwordless authentication will come to all major device platforms in the not too distant future: Android and iOS mobile operating systems; Chrome, Edge, and Safari browsers; and the Windows and macOS desktop environments.

“Just as we design our products to be intuitive and capable, we also design them to be private and secure,” said Kurt Knight, senior director of platform product marketing at Apple. “Working with the industry to establish new, more secure sign-in methods that offer better protection and eliminate the vulnerabilities of passwords is central to our commitment to building products that offer maximum security and a transparent user experience — all with the goal of keeping users’ personal information safe.” 

A representation of passwordless sign-in
A representation of passwordless sign-in
image: FIDO Alliance

A passwordless login process will let users choose their phones as the main authentication device for apps, websites, and other digital services, as Google detailed in a blog post published Thursday. Unlocking the phone with whatever is set as the default action — entering a PIN, drawing a pattern, or using fingerprint unlock — will then be enough to sign in to web services without the need to ever enter a password, made possible through the use of a unique cryptographic token called a passkey that is shared between the phone and the website.

By making logins contingent on a physical device, the idea is that users will simultaneously benefit from simplicity and security. Without a password, there will be no obligation to remember login details across services or compromise security by reusing the same password in multiple places. Equally, a passwordless system will make it much more difficult for hackers to compromise login details remotely since signing in requires access to a physical device; and, theoretically, phishing attacks where users are directed to a fake website for password capture will be much harder to mount.

Vasu Jakkal, Microsoft’s vice president for security, compliance, identity, and privacy, emphasized the degree of compatibility across platforms. “With passkeys on your mobile device, you’re able to sign in to an app or service on nearly any device, regardless of the platform or browser the device is running,” Jakkal said in an emailed statement. “For example, users can sign-in on a Google Chrome browser that’s running on Microsoft Windows—using a passkey on an Apple device.”

Users will simultaneously benefit from simplicity and security

The cross-platform functionality is being made possible by a standard called FIDO, which uses the principles of public key cryptography to enable passwordless authentication and multi-factor authentication in a range of contexts. A user’s phone can store a unique FIDO-compliant passkey and will share it with a website for authentication only when the phone is unlocked. Per Google’s post, passkeys can also be easily synced to a new device from cloud backup in the event that a phone is lost.

Though many popular applications already included support for FIDO authentication, initial sign-on has required the use of a password before FIDO can be configured — meaning that users were still vulnerable to phishing attacks that see passwords intercepted or stolen along the way.

But the new procedures will do away with the initial requirement for a password, as Sampath Srinivas, product management director for secure authentication at Google and president of the FIDO Alliance, said in an email statement sent to The Verge.

“This extended FIDO support being announced today will make it possible for websites to implement, for the first time, an end-to-end passwordless experience with phishing-resistant security,” said Srinivas. “This includes both the first sign-in to a website and repeat logins. When passkey support becomes available across the industry in 2022 and 2023, we’ll finally have the internet platform for a truly passwordless future.”

So far, Apple, Google, and Microsoft have all said that they expect the new sign-in capabilities to become available across platforms in the next year, although a more specific roadmap has not been announced. Although the plot to kill the password has been underway for years, there are signs that, this time, it may have finally succeeded.

Today’s Storystream

Feed refreshed 21 minutes ago Alexa is better with buttons.

A
External Link
Andrew J. Hawkins21 minutes ago
Tesla is buzzing with robot fever.

Elon Musk’s company is getting ready to debut its supposedly not-fake humanoid robot, Optimus, during its “AI Day” event September 30th. What evidence do we have that it won’t just be another a person in a spandex robot costume doing an extremely awkward dance? There have been meetings! And job postings! And Elon tweeted that there may be a working prototype! Look, this will either be a major breakthrough in the field of robotics or a spectacular flop. But considering Musk has already solved the problem of self-driving cars, I’m inclined to— what’s that? [touches earpiece] I’m being told he hasn’t solved the problem of self-driving cars? And that humanoid robots could prove even more difficult? Oh well, then bring on the spandex dancers I guess.


N
Twitter
Nilay Patel36 minutes ago
I cannot stop laughing at Trombone Champ.

You have to watch this video, and PC Gamer’s writeup is also great.

Accuracy and timing determine how well you play, with little words popping up to tell you how you’re doing. Words like Perfecto! Or Nice! If you’re sucking, as I typically do, you’ll get a Meh or sometimes a Nasty, which is maybe the funniest word to use to describe someone playing a trombone poorly.


J
Twitter
Jay Peters51 minutes ago
A lot of people are playing Cyberpunk 2077 right now.

The game has had 1 million players, “both new and returning,” each day this week, according to developer CD Projekt Red. Interest is likely up due to a big new update and the well-received Netflix anime.


Welcome to the new Verge

Revolutionizing the media with blog posts

Nilay PatelSep 13
S
External Link
Sarah Jeong52 minutes ago
Is it just me or are right-wing extremists a little too into Tolkien?

The obvious example is Peter Thiel naming his surveillance company Palantir (after an unspeakably evil scrying artifact that irreversibly corrupts its users?) but once you notice one profile of an alt-right or extremist figure mentioning how much they love Lord of the Rings, you start seeing it everywhere — including the footnotes of specious lawsuits attempting to undermine the 2020 election.

Anyways, you should read this, about an ascendant hard-right politician in Italy, whose politics are intertwined with high fantasy fandom in a way that will be unsettling to nerds of good conscience. And if you want to read more about Italy’s neo-fascist Camp Hobbit youth rallies in the 1970s, Atlas Obscura has you covered.


R
External Link
Russell BrandomAn hour ago
Republicans are not wild about antitrust enforcement.

The US government’s two biggest antitrust regulators — FTC chair Lina Khan and Justice Department antitrust chief Jonathan Kanter — appeared for a Senate Oversight hearing on Tuesday, and there were two quick takeaways:

1) Republicans still are eager to notch some kind of win against Khan and the Democratic FTC majority

2) They don’t really know how to do it yet.

Expect a lot of fireworks here if Republicans take back the Senate majority in November.


J
External Link
Jacob KastrenakesTwo hours ago
The Elon attrition is real.

“Hundreds of Twitter employees have fled since June,” according to Insider’s sources. That’s just over a month after Twitter agreed to sell the company to Musk — or, about as long as it’d take a highly qualified engineer to find a new job.

The company is down about 700 employees, according to the report, with many citing Musk and the acquisition as the reason why.


J
Youtube
Jon PorterTwo hours ago
The PS VR2 has a new trailer, but no release date.

Maybe I’m just old fashioned, but it feels weird to release a slick trailer like this for a product without an official release date? Regardless, the ad offers a pretty nice summary of the headset’s key features, which you can also read about in our recent hands-on preview. The PS VR2 is currently scheduled for release in “early 2023.


N
Nilay Patel1:09 PM UTC
Here’s 3.5 hours of me and John Gruber talking about the iPhone 14.

Going on The Talk Show to dive deep on our iPhone reviews has become one of my favorite yearly traditions. A little bit of Apple Watch Ultra conversation in there too — and yes, I asked John what he thought of our redesign fonts.


D
External Link
David Pierce1:00 PM UTC
YouTube’s former business chief will be Warner Music’s next CEO,

according to The Wall Street Journal. It’s a totally fascinating match: YouTube has always seen itself as a music service, even though nobody else really sees it that way, and talks a lot about how much it pays labels and artists. Warner needs to figure out how to get more money out of YouTube — and TikTok, and Fortnite, and the other platforms. Robert Kyncl’s going to be trying to improve the deals Robert Kyncl helped broker!


A
The Verge
Andrew Webster12:22 PM UTC
Andor, the latest Star Wars show, is now streaming.

Yet another Star Wars show is out, with the first three episodes of Andor — a prequel to Rogue One — available today on Disney Plus. My colleague Charles Pulliam-Moore calls it “a sobering reflection on the human costs of Star Wars’ never-ending conflicts.” My favorite part? There’s a sad droid named B2EMO.


J
TikTok
Jess Weatherbed11:48 AM UTC
This nifty AI lighting tool can give any selfie that ‘Golden Hour’ glow.

ClipDrop Relight is a free web app that allows you to apply artificial lighting to images in seconds. The tool is intended to be used with photos, but it’s taken the art community by storm as folks use it to add depth and funky lighting to their illustrations. Sure, it may not be able to replicate the real Golden Hour, but it saves you from relying on the sun’s schedule. AI = 1, sun = 0.