With latest version of Google Play Services, Android 7.0 and up now supports the FIDO2 standard which lets users login to services using fingerprints or PIN
Natt Garun / The Verge :
Context & Ripple Effects
This closes a loop Google opened years ago: back in 2015 it announced fingerprint authentication for Android alongside Smart Lock for Passwords in Play Services 7.5, but biometric logins stayed fragmented across apps and OEM builds. In March 2019 Google extended its own accounts to FIDO2 hardware security keys on Firefox and Edge, establishing the standard server-side.
What changes with this Play Services release is distribution: by pushing FIDO2 through Play Services rather than an OS version bump, every Android 7.0+ device becomes a compliant authenticator overnight — no new hardware, no system update. That converts Google's earlier hardware-key story into a software feature for the installed base.
First-order effects
- Users on Android 7.0 and up can immediately log into FIDO2-enabled services with their fingerprint or PIN instead of a password, using the phone they already own.
- Service developers who had reserved FIDO2 for hardware-key owners gain access to the entire Android 7.0+ installed base as eligible clients.
Second-order effects
- Services that already accepted FIDO2 hardware keys — including Google's own logins on Firefox and Edge per the related coverage — can now onboard Android users at zero marginal hardware cost, making password fallback look increasingly expensive to maintain.
- Rival platforms face pressure to expose equivalent standards-based biometric login through their own update channels, since Google has demonstrated credentials can be upgraded via Play Services independent of OS releases.
Third-order effects
- If the pattern holds, authentication consolidates at the platform-update layer: whoever controls the services layer on a device fleet — here Google via Play Services — sets the pace of passwordless adoption faster than OS upgrade cycles allow.
- The distinction between dedicated security keys and ordinary phones blurs, reinforced weeks later when Google said any Android 7.0+ device could serve as a two-factor security key — pointing toward FIDO2 as the default web login path rather than an enterprise add-on.
The trend: Web authentication is shifting from passwords and dedicated hardware tokens to standards-based biometrics distributed through platform services layers, letting Google upgrade its entire Android installed base without waiting on OS updates.