Think passkeys protect you from hacking and malware? Think again
Windows malware can still exploit Google Password Manager passkeys despite strong cryptography.
Recent research from Palo Alto Networks’ Unit 42 has revealed that Google Password Manager’s synced passkeys are not as secure as they may seem, particularly in the face of malware attacks on Windows PCs. Three malware attack paths have been identified, all of which exploit weaknesses in device trust, onboarding, and recovery mechanisms rather than attempting to break the passkey cryptography.
The most severe of these techniques, dubbed Golden Pass-ta-key, enables attackers to recover the master secret and subsequently decrypt all synced passkeys linked to an account. However, it is important to note that all these attacks necessitate the presence of malware on the victim’s Windows PC, making endpoint security the most critical takeaway from this research.
While passkeys have gained attention as a more secure alternative to traditional passwords, many individuals remain unclear on how they function. Understanding what passkeys fail to protect against is just as crucial as grasping their capabilities. The Palo Alto Networks’ Unit 42 researchers emphasize that, while passkeys themselves remain secure, they are vulnerable to exploitation by malware when present on a compromised Windows system.
Written by urgent.news from Android Authority's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.