Passkeys are a somewhat new attempt to find something to replace passwords, session cookies, MFA and all the other ways we have to use on the internet to verify both that we…
Passkeys are a somewhat new attempt to find something to replace passwords, session cookies, MFA and all the other ways we have to use on the internet to verify both that we are indeed who we say we are and that we’re authorized to access the resource being queried. If you’re not quite clear on what passkeys are, Ars Technica posted a great primer a few years back. In brief they are paired cryptographic keys, one public on the site you created an account and one private which is located on the specific device you used when creating the key. If the pairing checks out you get to log in without needing to enter a password or other verification method.
The assumption most had was that those local passkeys were stored securely on the local system, be it TPM chips, secure enclaves or whatever the OS calls it’s protected area. The problem is that storing it in such a way means that you can’t replicate your passkeys to another device. If you can only use a passkey on one device without creating it again from scratch then people are unlikely to adopt it because it would be a bit of a PITA. The FIDO Alliance decided that the OS on the local device would protect attackers from cloning passkeys on compromised machines and they were right, apart from Windows, and therefore storing passkeys in these secure locations would be optional and not required.
Windows tends to run everything with the same privileges as the logged in user, other OSes tend towards least access and that is where Pass-ta-key comes in. Pass-ta-key is the oddly named vulnerability discovered by a researcher at security firm Palo Alto Networks. They proved that if a Windows machine is compromised by malware, an attacker could steal any and all local passkeys stored in the Google Password Manager app. It is unclear if other password manager apps suffer the same vulnerability but it is not impossible that they could also be vulnerable to Pass-to-key.
The attacker has several ways to take advantage of Pass-ta-key, such as making an infected machine look like an iPhone, accessing a user’s Google Password Manager and triggering the convenient copy mechanism to migrate your passkeys to a new device to get a copy of all your passkeys. While this means Pass-ta-key is not exactly the novel attack it was billed as but it is still dangerous. You can get more details from Ars Technica if you want.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | La alternativa a las contraseñas que deberías conocer | 0 | 8.26 | 17-07-2026 |
| 2 | Why you need to take back control of your synced passwords and how to go about doing that | 0 | 10.76 | 20-06-2026 |
| 3 | Эксперты предупредили о новом способе обхода защиты аккаунтов мошенниками | -2 | 6 | 03-07-2026 |
| 4 | Эксперты считают, что злоумышленники распространяют вирус под видом ChatGPT для Windows | 0 | 0 | 22-02-2023 |
| 5 | Windows clipboard is more capable than you think, here's how to get the most out of it | 2 | 6 | 19-07-2026 |
| 6 | Microsoft разрешила пользователям входить в учетные записи без пароля | 0 | 0 | 16-09-2021 |
| 7 | Мошенники нашли новый способ взлома двухфакторной аутентификации | -2 | 7 | 02-07-2026 |
| 8 | Мошенники придумали новую уловку для кражи аккаунтов на «Госуслугах» | 0 | 10 | 24-07-2026 |
| 9 | Why Risk-Based MFA is a Game Changer for User Experience | 0 | 12.01 | 10-08-2026 |
| 10 | Минцифры рассказало о новом способе мошенничества с QR-кодами на "Госуслугах" | 0 | 0 | 15-01-2022 |