Android: Sicherer Wechsel zwischen Passwort-Managern inklusive Passkeys

Android: Securely Switch Password Managers Including Passkeys

Google is closing a serious security gap on Android when switching between password managers. Starting immediately, users can transfer their saved credentials and modern passkeys directly and encrypted between supported apps, rather than having to export sensitive login details in plain text.

An End to the Security Risk of Plain-Text Exports

Previously, migrating from one password manager to a competing product involved considerable security risks. Many services required exporting all credentials into an unencrypted CSV file. If this file fell into the wrong hands or was not completely wiped from storage after importing, passwords for sensitive services such as email accounts or payment providers were exposed completely unprotected. The situation was even more critical with passkeys: these cryptographic keys could not be exported this way at all, effectively locking users into a specific provider.

FIDO Standard Enables Direct App-to-App Transfer

The technical foundation for this secure transfer is provided by the FIDO Alliance’s Credential Exchange protocol. With this method, data transmission occurs encrypted and directly between the respective password apps on the same smartphone.

The process is straightforward for users:

  • The procedure is initiated in the target app where the credentials are to be transferred.
  • There, you select the import function, prompting the operating system to scan for installed vault apps on the smartphone.
  • A system prompt displays the exact number of passwords and passkeys found.
  • After user confirmation, all entries are imported securely into the new manager.
See also  Google Warns of Active Exploitation of Modem Vulnerability in Pixel Smartphones

According to Google, the process is already supported by its native Google Password Manager as well as 1Password, Bitwarden, and Dashlane. Other developers are expected to follow.

Availability and Existing Limitations

Apple had introduced a comparable feature back in the fall of 2025 with iOS 26. However, a direct transfer between Android and iOS is not yet possible via the new FIDO protocol, as the data exchange must take place locally between two apps on the very same device. Users switching platforms between Android and iPhone will therefore still need to rely on separate migration tools.

On Android devices, the feature is available starting with Android 8, which was released in August 2017. Rollout is handled as part of Google Play Services and has reportedly been underway gradually since June. While owners of Google Pixel devices generally receive the update promptly, availability on devices from other manufacturers like Samsung may be delayed. Users should check the settings of their preferred password managers to see if the import option is already active.

Sources: Netztwelt.de

Leave a Comment

Your email address will not be published. Required fields are marked *

Mastodon
Scroll to Top