A new update to Google’s Smart Lock iOS app lets users set up their iPhone or iPad as a security key for two-factor authentication when signing into native Google services via Chrome browser.
Once the feature is set up in the app, attempting to log in to a Google service via Chrome on another device such as a laptop results in a push notification being sent to their iOS device.
The user then has to unlock their iPhone or iPad using Face ID or Touch ID and confirm the log-in attempt via the Smart Lock app before it can complete on the other device.
After installing the update, users are asked to select a Google account to set up their phone’s built-in security key. According to a Google cryptographer, the feature makes use of Apple’s Secure Enclave hardware, which securely stores Touch ID, Face ID, and other cryptographic data on iOS devices.
The Smart Lock app requires that Bluetooth is enabled on both the iPhone/iPad and the other device for two-factor authentication to work, so they have to be in close proximity, but the advantage of the system is that it ensures the process is localized and can’t be leaked onto the internet.