Passkeys are being hacked


For years, the digital landscape has been defined by the frustrating necessity of passwords—secret strings of characters we must remember and protect. But a new revolution in security is taking shape, one that promises to eliminate this historical headache entirely: passkeys.

Passkeys represent a significant leap forward. Unlike traditional passwords, which are vulnerable to phishing and sharing, a passkey offers a superior defense. Since a passkey is intrinsically tied to the user and cannot be given away or stolen through typical means, it establishes a higher, more personal level of authentication.

Yet, even the most secure systems are not immune to sophisticated threats. Cybersecurity experts are constantly mapping the new attack vectors, and a recent discovery highlights a specific vulnerability in this promising new system.

Arie Olshtein, a cybersecurity expert with Palo Alto Networks, detailed a collective threat nicknamed Pass-ta-key. This attack targets the most private form of digital authentication by focusing on the extraction of locally synced passkeys.

The potential impact of Pass-ta-key lies in the ability to steal these passkeys and use them to bypass security and log into various websites, potentially leading to serious security breaches.

However, the vulnerability is not universal. The threat seems to be highly specific, focusing exclusively on Windows operating systems. Furthermore, the risk appears concentrated when these passkeys are managed through Google Password Manager within Chrome for Windows.

This finding serves as a critical reminder that while technology offers powerful new security tools, the battle against malicious actors is ongoing. The evolution of digital security means that understanding the specific interaction points between modern operating systems and passwordless solutions is just as important as the features themselves.

You may also like: