Google says it will now let iPhone and iPad owners use its Android security key tech to verify sign-ins for Google accounts
though I'm not sure how many will once Sign In with Apple rolls out: https://www.cnet.com/...
Context & Ripple Effects
Google has been dismantling the physical security key one device at a time: it opened its hardened Advanced Protection Program to Apple's native apps back in 2018, then in April made any Android 7.0+ handset usable as a two-factor key. This announcement completes the loop by extending that same Android security-key technology to iPhone and iPad owners, so Apple's hardware can now verify Google account sign-ins directly.
It matters because Google's earlier experiments — from phone-notification logins tested in 2015 onward — all pointed at replacing passwords with devices people already carry, and this move brings iOS users into that system rather than leaving them buying dedicated USB keys.
First-order effects
- iPhone and iPad owners can now use their existing Apple device as the second factor for Google account sign-ins, removing the need to purchase a separate physical security key.
- Google's Advanced Protection-style high-security accounts become reachable for iOS-first users who previously had no native path into the program's key-based flow.
Second-order effects
- Dedicated hardware-key vendors lose the iOS-user segment as a buyer pool, since the phone they already own now performs the same role over the same protocol.
- Apple's competing Sign In with Apple push targets the same sign-in moment, raising the stakes on whose credential layer owns third-party app authentication.
Third-order effects
- If the pattern holds, platform secure hardware — Android's built-in key support and later the iPhone's Secure Enclave — becomes the industry's default authenticator, collapsing the market for standalone keys and setting up Google's eventual passkey rollout as the endpoint of this arc.
The trend: Authentication is consolidating around the smartphone's secure hardware as the universal second factor, steadily displacing both passwords and dedicated physical keys.