{"id":92404,"date":"2023-06-06T19:29:40","date_gmt":"2023-06-06T19:29:40","guid":{"rendered":"https:\/\/www.techrepublic.com\/?p=4109056"},"modified":"2023-06-06T19:29:40","modified_gmt":"2023-06-06T19:29:40","slug":"google-launches-passkeys-for-workspace","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=92404","title":{"rendered":"Google launches passkeys for Workspace"},"content":{"rendered":"<figure id=\"attachment_4019213\" aria-describedby=\"caption-attachment-4019213\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4019213\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2023\/06\/google-launches-passkeys-for-workspace.jpg\" alt=\"Two interlocking keys representing encryption over a background of machine code.\" width=\"1400\" height=\"933\"><figcaption id=\"caption-attachment-4019213\" class=\"wp-caption-text\">Image: faithie\/Adobe Stock<\/figcaption><\/figure>\n<p>Google validated the virtues of passkey authentication technology on Monday with an open beta version of <a href=\"http:\/\/g.co\/passkeys\">passkey access<\/a> that allows people and organizations around the world to sign into their Google Workspaces using passkeys. Google reports that nine million organizations now use Workspace.<\/p>\n<p>Google is in step with many other companies in moving away from passwords and toward public\/private encrypted credentials \u2014 based on FIDO standards (called FIDO2) \u2014 that are resistant to phishing exploits.<\/p>\n<p>The company said passkeys will pair with on-device biometrics \u2014 like fingerprints and facial recognition, for example. Passkeys can be used across browsers, are browser-agnostic, and allow for authentication across devices. Google said its <a href=\"https:\/\/security.googleblog.com\/2023\/05\/making-authentication-faster-than-ever.html\" target=\"_blank\" rel=\"noopener noreferrer\">data<\/a> from last spring shows passkeys are two times faster and four times less error-prone than passwords.<\/p>\n<p>With the public\/private keys \u2014 the basis of the cryptographic system that allows password-free logins \u2014 an encrypted key lives on a user\u2019s device, meaning it cannot be activated unless the user themselves have unlocked the device. While the cryptographic key is stored on the device, a public key is uploaded to Google.<\/p>\n<p>Jump to:<\/p>\n<h2 id=\"passkeys\">Passkeys enabled by industry push in 2022<\/h2>\n<p>Google \u2014 along with Microsoft, Apple and others \u2014 announced last year that it would start to support passkeys and participate in their development with the Fast Identity Online Alliance, better known as the <a href=\"https:\/\/fidoalliance.org\/fido2\/\" target=\"_blank\" rel=\"noopener noreferrer\">FIDO Alliance<\/a>, and the World Wide Web Consortium standards.<\/p>\n<p>At last year\u2019s Worldwide Developers Conference, Apple announced it would be integrating passkey support into its next version of iOS this fall. This year, ahead of World Password Day, Google, Microsoft and Apple all reaffirmed their support for passkeys, with Google doing so across Google Accounts on all major platforms.<\/p>\n<p><strong>SEE:<\/strong> RIP passwords; tech giants <a href=\"https:\/\/www.techrepublic.com\/article\/world-password-day-not-for-long\/\">roll out<\/a> passkey capabilities ahead of World Password Day (TechRepublic).<\/p>\n<p>\u201cPasskeys introduce meaningful security and usability benefits to users, and we\u2019re thrilled to be the first major public cloud provider to bring this technology to our customers \u2014 from small businesses and large enterprises to schools and governments,\u201d said the company in a statement.<\/p>\n<h2 id=\"password-managers\">Password managers moving to passkeys<\/h2>\n<p>Identity access management companies are retooling to support passkeys. As TechRepublic <a href=\"https:\/\/www.techrepublic.com\/article\/1password-enables-passkeys\/\">reported<\/a> last week, 1Password began allowing passkey support using its browser tool and will soon allow passkey access to 1Password vaults. At the RSA conference this year, 1Password CEO Jeff Shiner said that he foresaw that Google\u2019s move to a passwordless system would constitute a sea-change moment for the industry.<\/p>\n<aside class=\"pinbox right\">\n<h3 class=\"heading\">Must-read security coverage<\/h3>\n<\/aside>\n<p>Cisco\u2019s Duo authentication platform is introducing a number of passkey-based features to its platform, and in August, Dashlane introduced integrated passkey support in its security-first password manager and unveiled the first in-browser passkey solution.<\/p>\n<p>At the RSA conference in April, Iva Blazina Vukelja, the vice president of product at Zero Trust at Duo, said companies are very ready to shift away from passwords.<\/p>\n<p>\u201cThere are two big reasons to go passwordless,\u201d she said. \u201cFriction for corporate end users is a big one. When we started doing private previews and rolled out passkey authentication out to a limited set of end users, we got feedback saying it was 75% less annoying than any other authentication methods. \u2018Please roll it out,\u2019 is what they said. End users love it.\u201d<\/p>\n<p>Rew Islam, the director of product engineering and innovation at Dashlane, which is part of the W3C working group for WebAuthn, pointed out that the underlying technology for public\/private keys has been around for many years. However, the key event that made the migration to passkeys possible was the industry coming together to agree on a standard, \u201cespecially the big three platforms,\u201d he said, adding that passkeys can be managed today in Dashlane using a Chromium-based extension. \u201cWe\u2019ve had that since last summer,\u201d he said. \u201cWe\u2019re waiting for Android 14, and our app is <a href=\"https:\/\/www.dashlane.com\/blog\/dashlane-passkey-support-android\" target=\"_blank\" rel=\"noopener noreferrer\">ready for it<\/a>.\u201d<\/p>\n<h2 id=\"drawbacks\">Few drawbacks to passkeys<\/h2>\n<p>When a user creates a passkey on a shared device, by default, anyone who can use that device can therefore also login to one\u2019s account using the public\/private key handshake since they would presumably have an enabled biometric sign-on to the device. Islam said this could introduce a problem with where the keys of individuals sharing that device reside.<\/p>\n<p>\u201cCan people access the keys of others on that shared device? I think there will eventually be solutions to this issue, but it\u2019s not obvious how, let\u2019s say, a family manages their passkeys if they\u2019re sharing a Mac unless they\u2019re maintaining separate user accounts on the actual operating system itself,\u201d he said.<\/p>\n<p>Google said if one loses a device with a passkey for a Google account and worries that the device can be unlocked, they can immediately revoke the passkey in account settings.<\/p>\n<p>Okta last fall announced it was rolling out a passkey management feature that allows admins to block passkeys for new enrollments at an organizational level. This feature addresses a key problem for enterprises using passkeys: authorized users who sign on with an unmanaged device.<\/p>\n<p>Mukul Hinge, the group product marketing manager of workforce identity at Okta, <a href=\"https:\/\/www.okta.com\/blog\/2022\/09\/okta-passkey-management-a-new-feature-flag\/\" target=\"_blank\" rel=\"noopener noreferrer\">explained the feature in a blog post<\/a> that offers a good overview of passkeys and the FIDO standards that enable them. He said the feature for Okta Classic and Okta Identity Engine prohibits a user from enrolling with a multi-device FIDO credential and preempts any potential risks of unmanaged and insecure devices accessing sensitive applications.<\/p>\n<p>He explained that one could access sensitive applications with, for example, an unmanaged iPad using an older, vulnerable version of iOS that does not conform to the security posture requirements of the organization. \u201cThis is a serious security vulnerability. From an admin standpoint, this needs to be addressed immediately,\u201d he said.<\/p>\n<p>Some platforms, like Apple, allow users to access accounts using a single passkey. For Apple, iCloud accounts allow the sharing of passkeys across various Apple devices, the point being that if one loses a device, they can access an account with passkeys on one of their other Apple devices.<\/p>\n<p> <!-- default newsletter at the end --> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Image: faithie\/Adobe Stock Google validated the virtues of passkey authentication technology on Monday with an open beta version of passkey access that allows people and organizations around the world to sign into their Google Workspaces using passkeys. Google reports that nine million organizations now use Workspace. Google is in step with many other companies in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":92405,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[40,783,154,287],"tags":[],"class_list":["post-92404","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud","category-cloudsync","category-google","category-security"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/92404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=92404"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/92404\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/92405"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=92404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=92404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=92404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}