In the iOS 13.3 beta, Safari gains support for NFC, USB, and Lightning FIDO2-compliant security keys
Juli Clover / MacRumors :
Context & Ripple Effects
This is the payoff of a slow opening of the iPhone's hardware to the web. Apple first tested WebAuthn — the protocol that lets sites verify identity via a physical key — in Safari Technology Preview 71 back in December 2018, and iOS 13 then widened NFC access so iPhones could read NFC-enabled passports and government IDs. The iOS 13.3 beta now closes the loop by letting Safari itself talk to FIDO2-compliant security keys over NFC, USB, and Lightning.
First-order effects
- iPhone users holding FIDO2 security keys can finally use them as a second factor on websites directly from Mobile Safari, instead of falling back to SMS codes or app-based prompts.
- Security-key vendors have an incentive to ship Lightning-connector variants, since a desktop-oriented USB-A or USB-C key physically cannot plug into an iPhone's port.
Second-order effects
- Apple's own roadmap points past hardware keys entirely — it later moved to bring Face ID and Touch ID logins to the web in Safari 14, making biometrics the zero-hardware path and positioning the key support as the bridge for high-assurance users.
- Services still defaulting to SMS two-factor for iPhone users face growing pressure to adopt WebAuthn flows now that the dominant mobile browser on iOS supports them natively.
Third-order effects
- If the pattern holds — incremental NFC access, protocol-level WebAuthn support, then biometric web login — Apple is rebuilding web authentication around device-anchored identity rather than passwords, with the browser as the enforcement point rather than individual sites.
- That trajectory sits against a broader backdrop where major browsers including Safari are implementing features that block or limit web tracking, pushing the web toward stronger, less portable user identity at the same time it restricts cross-site data flows.
The trend: Mobile browsers are absorbing hardware-backed authentication, moving web identity off passwords and SMS codes onto security keys and device biometrics.