{
  "id": 1246477,
  "title": "Are passkeys still safe after Pass-ta-key?",
  "url": "https://urgent.news/2026/08/16/are-passkeys-still-safe-after-pass-ta-key",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-16T09:51:11.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/akashdas/are-passkeys-still-safe-after-pass-ta-key-ij1"
  },
  "original_language": "en",
  "account": "Passkeys are still safer than passwords, according to research published by Palo Alto Networks Unit 42 on August 3, 2026. The research outlines three variants of a malware attack that can take over accounts protected by Google-synced passkeys. However, the coverage that followed failed to explain who is actually affected and what steps to take to protect oneself. The scope of the attack is narrow, and the fix is cheap. The standard itself is not broken. The research describes three variants: Silver, Golden, and Golden Pass-ta-key, but several outlets reported a fourth variant, which was not named by Unit 42. The attacks require malware to be running on the victim's device during the initial stage, so they do not transfer mechanically to another vendor's design. However, nobody has published the same audit of Apple's or 1Password's passkey systems. Passkeys remove phishing as an attack path entirely and do not put it back. The risk of synced passkeys is reduced to whether the device is clean. If it is, synced passkeys are a convenient feature.",
  "summary": "Passkeys are still safer than passwords. That is the answer, and the research behind the scary headlines says so too. On 3 August 2026, Palo Alto Networks' Unit 42 published three techniques that let malware take over accounts protected by Google-synced passkeys. No fingerprint, no PIN, and no prompt on screen. The coverage that followed skipped the part readers need: exactly who is exposed, and…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}