{
  "id": 568634,
  "title": "New Pass-ta-key attack reveals all the things we didn't know about passkeys",
  "url": "https://urgent.news/2026/08/11/new-pass-ta-key-attack-reveals-all-the-things-we-didnt-know-about",
  "topic": "world",
  "section": "World",
  "published": "2026-08-11T11:30:08.000Z",
  "source": {
    "name": "Ars Technica",
    "slug": "ars-technica",
    "url": "https://arstechnica.com/security/2026/08/heres-why-the-new-pass-ta-key-attack-is-mostly-a-nothingburger/"
  },
  "original_language": "en",
  "account": "Last week, a researcher unveiled a novel attack known as Pass-ta-key, which reveals all the secrets about passkeys. However, this attack is neither groundbreaking nor exclusive to passkeys, which has caused confusion among end users and security experts evaluating the safety of this new authentication method. Pass-ta-key, a clever combination of \"passkey\" and \"pass the key,\" exploits the Google Password Manager app (GPM) on Windows when the system is compromised by malware. This revelation puzzled many, as they assumed passkeys are securely stored in the trusted platform manager (TPM). If passkeys were indeed stored in the TPM, how could Pass-ta-key extract the entire collection of passkeys held by the app, they wondered.",
  "summary": "Why passkey apps treat Windows differently than other operating systems.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}