{"id":2462,"date":"2019-08-05T07:00:44","date_gmt":"2019-08-05T14:00:44","guid":{"rendered":"https:\/\/blog.mozilla.org\/security\/?p=2462"},"modified":"2019-08-01T09:59:37","modified_gmt":"2019-08-01T16:59:37","slug":"web-authentication-in-firefox-for-android","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/","title":{"rendered":"Web Authentication in Firefox for Android"},"content":{"rendered":"<p><a href=\"https:\/\/www.mozilla.org\/en-US\/firefox\/android\/all\/\">Firefox for Android<\/a> (Fennec) now supports the<a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Web_Authentication_API\"> Web Authentication API<\/a> as of<a href=\"https:\/\/www.mozilla.org\/en-US\/firefox\/android\/68.0\/releasenotes\/\"> version 68<\/a>. WebAuthn blends public-key cryptography into web application logins, and is our best technical response to credential phishing. Applications leveraging WebAuthn gain new\u00a0 second factor and \u201cpasswordless\u201d biometric authentication capabilities. Now, Firefox for Android matches our support for<a href=\"https:\/\/blog.mozilla.org\/security\/2019\/03\/19\/passwordless-web-authentication-support-via-windows-hello\/\"> Passwordless Logins using Windows Hello<\/a>. As a result, even while mobile you can still obtain the highest level of anti-phishing account security.<\/p>\n<div style=\"width: 400px;\" class=\"wp-video\"><!--[if lt IE 9]><script>document.createElement('video');<\/script><![endif]-->\n<video class=\"wp-video-shortcode\" id=\"video-2462-1\" width=\"400\" height=\"711\" poster=\"https:\/\/blog.mozilla.org\/security\/files\/2019\/07\/webauthn-android-fennec.png\" loop=\"1\" preload=\"metadata\" controls=\"controls\"><source type=\"video\/mp4\" src=\"https:\/\/blog.mozilla.org\/security\/files\/2019\/07\/webauthn-android-fennec-1.mp4?_=1\" \/><source type=\"video\/webm\" src=\"https:\/\/blog.mozilla.org\/security\/files\/2019\/07\/webauthn-android-fennec-1.webm?_=1\" \/><a href=\"https:\/\/blog.mozilla.org\/security\/files\/2019\/07\/webauthn-android-fennec-1.mp4\">https:\/\/blog.mozilla.org\/security\/files\/2019\/07\/webauthn-android-fennec-1.mp4<\/a><\/video><\/div>\n<p>Firefox for Android uses your device\u2019s native capabilities: On certain devices, you can use built-in biometrics scanners for authentication. You can also use security keys that support Bluetooth, NFC, or can be plugged into the phone&#8217;s USB port.<\/p>\n<p>The attached video shows the usage of Web Authentication with a built-in fingerprint scanner: The <a href=\"https:\/\/webauthn.io\/\">demo website<\/a> enrolls a new security key in the account using the fingerprint, and then subsequently logs in using that fingerprint (and without requiring a password).<\/p>\n<p>Adoption of Web Authentication by major websites is underway: Google, Microsoft, and Dropbox all support WebAuthn via their respective Account Security Settings\u2019 \u201c2-Step Verification\u201d menu.<\/p>\n<h2>A few notes<\/h2>\n<ul>\n<li>For Microsoft Accounts, you\u2019ll need to be running the latest release of Windows 10. Look under the heading \u201cWindows Hello and security keys\u201d.<\/li>\n<li>For Google Accounts, due to Google limitations you must enroll your security keys via a desktop browser, and then you can use them with Firefox for Android. Look for the heading \u201cSecurity keys\u201d and choose a USB or NFC key.<\/li>\n<li>Additionally you can try Web Authentication out at a variety of demo sites:<a href=\"https:\/\/webauthn.org\/\"> https:\/\/webauthn.org\/<\/a>,<a href=\"https:\/\/webauthn.io\/\"> https:\/\/webauthn.io\/<\/a>,<a href=\"https:\/\/webauthn.me\/\"> https:\/\/webauthn.me\/<\/a>,<a href=\"https:\/\/webauthndemo.appspot.com\/\"> https:\/\/webauthndemo.appspot.com\/<\/a>, or<a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Web_Authentication_API\"> learn more about it on MDN<\/a>.<\/li>\n<\/ul>\n<p>For technical reasons, Firefox for Android does not support the older, backwards-compatible FIDO U2F Javascript API, which we<a href=\"https:\/\/blog.mozilla.org\/security\/2019\/04\/04\/shipping-fido-u2f-api-support-in-firefox\/\"> enabled on Desktop earlier in 2019<\/a>. For details as to why, see<a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1550625\"> bug 1550625<\/a>.<\/p>\n<p>Currently<a href=\"https:\/\/blog.mozilla.org\/futurereleases\/2019\/06\/27\/reinventing-firefox-for-android-a-preview\/\"> Firefox Preview<\/a> for Android does not support Web Authentication. As Preview matures, Web Authentication will be joining its feature set.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Firefox for Android (Fennec) now supports the Web Authentication API as of version 68. WebAuthn blends public-key cryptography into web application logins, and is our best technical response to credential &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/\">Read more<\/a><\/p>\n","protected":false},"author":1349,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[320796,69],"tags":[41994,320808,451,8807,320798],"coauthors":[45540],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Web Authentication in Firefox for Android - Mozilla Security Blog<\/title>\n<meta name=\"description\" content=\"Firefox for Android now supports Web Authentication anti-phishing technology. WebAuthn permits passwordless logins using mobile biometric scanners.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"J.C. Jones\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/\",\"url\":\"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/\",\"name\":\"Web Authentication in Firefox for Android - Mozilla Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\"},\"datePublished\":\"2019-08-05T14:00:44+00:00\",\"dateModified\":\"2019-08-01T16:59:37+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/f2bfcea9a0c404ce2431925922bedbde\"},\"description\":\"Firefox for Android now supports Web Authentication anti-phishing technology. WebAuthn permits passwordless logins using mobile biometric scanners.\",\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Web Authentication in Firefox for Android\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/security\/\",\"name\":\"Mozilla Security Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/f2bfcea9a0c404ce2431925922bedbde\",\"name\":\"J.C. Jones\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/d063fc46e7671301c178b2781210dff7\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/64eb1412c9354cf356df31936368cdac?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/64eb1412c9354cf356df31936368cdac?s=96&d=identicon&r=g\",\"caption\":\"J.C. Jones\"},\"description\":\"Keeping people safe on the 'net. Cryptography Engineering lead for Firefox.\",\"sameAs\":[\"https:\/\/tacticalsecret.com\/\",\"https:\/\/x.com\/JamesPugJones\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Web Authentication in Firefox for Android - Mozilla Security Blog","description":"Firefox for Android now supports Web Authentication anti-phishing technology. WebAuthn permits passwordless logins using mobile biometric scanners.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/","twitter_misc":{"Written by":"J.C. Jones","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/","url":"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/","name":"Web Authentication in Firefox for Android - Mozilla Security Blog","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/security\/#website"},"datePublished":"2019-08-05T14:00:44+00:00","dateModified":"2019-08-01T16:59:37+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/f2bfcea9a0c404ce2431925922bedbde"},"description":"Firefox for Android now supports Web Authentication anti-phishing technology. WebAuthn permits passwordless logins using mobile biometric scanners.","breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/security\/2019\/08\/05\/web-authentication-in-firefox-for-android\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/security\/"},{"@type":"ListItem","position":2,"name":"Web Authentication in Firefox for Android"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/security\/#website","url":"https:\/\/blog.mozilla.org\/security\/","name":"Mozilla Security Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/f2bfcea9a0c404ce2431925922bedbde","name":"J.C. Jones","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/d063fc46e7671301c178b2781210dff7","url":"https:\/\/secure.gravatar.com\/avatar\/64eb1412c9354cf356df31936368cdac?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/64eb1412c9354cf356df31936368cdac?s=96&d=identicon&r=g","caption":"J.C. Jones"},"description":"Keeping people safe on the 'net. Cryptography Engineering lead for Firefox.","sameAs":["https:\/\/tacticalsecret.com\/","https:\/\/x.com\/JamesPugJones"]}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/2462"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/users\/1349"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/comments?post=2462"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/2462\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media?parent=2462"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/categories?post=2462"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/tags?post=2462"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/coauthors?post=2462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}