Urgent.News

the world's headlines, one feed

Editions

Tech

Report: Passkey security issues could allow account takeover

Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion. They also pointed out that the issues are not strictly caused by holes in passkeys so much as by…

Report: Passkey security issues could allow account takeover

A recent report by Palo Alto Networks Unit 42 reveals potential security issues with passkeys, which have become a popular password replacement in enterprises. While analysts note that the demonstrated attacks can only occur after a successful intrusion, they emphasize that the issues stem from weaknesses in the procedures surrounding passkeys, rather than inherent flaws in the cryptography itself.

Justin Greis, CEO of Acceligence, explains that attackers exploit onboarding flows, recovery mechanisms, and trust signals that are not being validated.

The report identified three categories of attacks, collectively called Pass-ta-key. Pass-ta-key allows an attacker to take over a Google-synced passkey-protected account using malware on the victim's device without needing privilege escalation, device unlock, or user interaction. Silver Pass-ta-key involves tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, resulting in full account takeover without using the victim's device during authentication.

Finally, Golden Pass-ta-key enables an attacker to extract all synced passkeys, which can then be shared or sold on the credential black market.

CISOs have faced challenges implementing passwordless processes in environments with legacy and virtual components. Despite the Palo Alto report's focus on post-compromise attacks, which assume the attacker has already penetrated the environment and installed malware, the primary issue lies in the lack of attention paid to the surrounding mechanisms.

Consultants stress that CISOs must now focus on implementing user verification, validating user-verified flags in authentication responses, and enforcing required verification procedures. They also recommend treating verification as mandatory, regularly checking server-side, and prioritizing hardware-bound keys for critical accounts.

The Palo Alto report suggests that poor support processes may weaken passkey capabilities, undermining the purpose of such systems. J. Wolfgang Goerlich, a cybersecurity consultant, suggests that CISOs should require device-bound authenticators, such as hardware tokens or computers, for privileged and sensitive access. While wallets might be acceptable for lower-risk access, passkeys in browsers should be considered an unacceptable risk.

Written by urgent.news from Computerworld's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at computerworld.com →

More in Tech

iPhone 18 Pro Will Reportedly Start With 256GB of Storage

iPhone 18 Pro Will Reportedly Start With 256GB of Storage

While the iPhone 17 Pro has double the base storage compared to the iPhone 16 Pro, there will apparently be no further increase this year. In a report this week estimating that the iPhone 18 Pro's bill of materials will be nearly 40% higher than the iPhone 17 Pro , Taiwanese research firm TrendForce said the iPhone 18 Pro will start with…