New Pass-ta-key attack reveals all the things we didn't know about passkeys
Why passkey apps treat Windows differently than other operating systems.
Last week, a researcher unveiled a novel attack known as Pass-ta-key, which reveals all the secrets about passkeys. However, this attack is neither groundbreaking nor exclusive to passkeys, which has caused confusion among end users and security experts evaluating the safety of this new authentication method. Pass-ta-key, a clever combination of "passkey" and "pass the key," exploits the Google Password Manager app (GPM) on Windows when the system is compromised by malware.
This revelation puzzled many, as they assumed passkeys are securely stored in the trusted platform manager (TPM). If passkeys were indeed stored in the TPM, how could Pass-ta-key extract the entire collection of passkeys held by the app, they wondered.
Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.