Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Secure Credential Transfer. Show all posts

Android Simplifies Secure Migration of Saved Logins


With the advent of Android's new credential transfer feature, passwords and passkeys can be transferred directly between supported password managers without the creation of an unencrypted file. This feature resolves a problem longstanding with migration. 

In the past, it was often necessary to export stored credentials into a text or CSV file that was unencrypted, so that a temporary copy could remain visible on the device while the password was transferred. Previously, users were not able to transfer passwords between password managers, requiring them to recreate them if they changed providers. 

The new transfer process is handled by Android itself. Migrations begin with the password manager receiving the credentials, and an import or transfer option is offered to initiate the migration. Upon identifying supported password managers installed on the device, Android passes control to the existing manager, allowing them to review and authorize credentials that have been selected for transfer. 

The new system facilitates the transfer of passwords and passkeys, eliminating the need to create plaintext credentials as part of the migration process. This approach aims to reduce the exposure of sensitive authentication data during the switch of password managers. 

With Android's new credential transfer feature, users can move passwords and passkeys directly between password management applications without having to create an unencrypted file in the process. This feature addresses the long-standing issue of migration between password management applications. 

Passwords were traditionally exported into an unencrypted text or CSV file when transferring stored credentials, creating a temporary copy that could remain exposed on the device while the passwords were being transferred. Passkeys, however, cannot be transferred between password managers, so users must recreate them when switching providers. New transfer procedures are managed by Android itself. 

When a password manager receives credentials, it will offer the option of importing or transferring credentials, which will initiate the migration process. Android identifies supported password managers on the device and passes control to those managers in order for the stored credentials to be reviewed and authorized for transfer. 

Passwords and passkeys can be transferred with this new system, removing the requirement to prepare a plaintext credential file during migration. This approach is intended to minimize the potential for exposing sensitive authentication information. 

Support Remains Limited

Four password managers are currently supported by the feature: Google Password Manager, 1Password, Bitwarden, and Dashlane Google has indicated that additional providers are planned, although no specific deadline has been announced. It will still be necessary to use conventional export and import methods when using password managers outside the supported group. This system utilizes a standardized credential exchange approach so that participating password managers can communicate through Android devices. 

Additionally, migration support for passkeys is now available, removing the barrier that previously existed when changing password management services. This feature is accessible on Android 8 or later devices, allowing older supported devices to benefit from this capability, rather than being restricted to recent releases. 

The change is part of a larger effort by Google to improve the security of account information and device migration. The Android platform also includes requirements that are intended to improve the way applications restore the state of their sign-ins when users switch devices. During device migration, eligible applications will use Android's Restore Credentials API to restore authentication under the Zero-Tap Sign-In standard. 

With the introduction of this system, supported applications will be able to recognize existing sign-in states on new devices without requiring additional login steps. Google plans to begin enforcing the Zero-Tap Sign-In requirement by April 2027 while that initiative focuses on application authentication during device upgrades, the password-manager feature allows credentials to be transferred between different password management services. 

There are currently limited provider support options, however, wider adoption could facilitate easier transitions between password managers while reducing the security risks associated with manually handling exported credentials.