The Actual News

Just the Facts, from multiple news sources.

New Pass-ta-key attack reveals all the things we didn't know about passkeys

New Pass-ta-key attack reveals all the things we didn't know about passkeys

Summary

A security researcher revealed a way to steal passkeys stored in the Google Password Manager app on Windows computers infected with malware. This attack works because, unlike other platforms, Windows does not require passkeys to be stored only in special secure hardware, making them more vulnerable to local malware.

Key Facts

  • Passkeys are a new, more secure way to log in without passwords.
  • A security researcher from Palo Alto Networks found a method called "Pass-ta-key" to steal passkeys on Windows.
  • Many people thought all passkeys are stored inside secure hardware chips called TPMs, but this is not true for most platforms.
  • Only Microsoft offers the option to store passkeys in the TPM on Windows, mainly for businesses.
  • Other platforms like macOS, iOS, and Android store passkeys locally but isolate apps better to prevent malware access.
  • Windows apps usually run with full user permissions, making it easier for malware to read data from other apps.
  • The design decision to store passkeys locally helps users sync them across devices easily.
  • So far, attacks on passkeys through the OS security model have been rare except on Windows due to its weaker app isolation.
Read the Full Article

This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.

Save articles & personalize your feed — Create a free account