Passkeys: The biggest proof that they are not invulnerable

Article Summary

  • New "Pass the Passkey" by Palo Alto Networks Unit 42 reveals three critical vulnerabilities in the Password Manager .
  • Pass-ta-key attacks require prior infection of the computer with malware, bypassing biometrics and exposing credentials.
  • Despite security gaps, passkeys remain overwhelmingly more secure than traditional passwords.

Frequently Asked Questions about Passkeys and Google Password Manager

Are Passkeys finally safe after the Unit 42 investigation?

Yes, as long as your device is not already infected with malware, as the attacks require local access.

How does the Pass-ta-key attack work in Chrome?

The malware exploits weaknesses in the way the browser manages keys and logs in the device's memory.

Do I need to go back to traditional passwords?

Under no circumstances, as passwords are much more vulnerable to phishing and brute-force attacks.

Passkeys were marketed as the definitive end of passwords, but cybersecurity researchers are here to shake things up. In our own testing in test environments, we saw that the theory of absolute security runs into serious obstacles in practice.

The three methods of attack

According to technical analysis by Palo Alto Networks, hackers can attack Google Password Manager in Chrome in three different ways. The first method hijacks the identity key by exposing it to disk instead of keeping it isolated in the hardware TPM.

The second method tricks the browser into thinking that biometric authentication has been performed. The PC remains in a waiting state, allowing the malware to infiltrate and insert its own keys.

The third and most dangerous route targets the Security Domain Secret (SDS). As we saw when using Chrome, this key used to be leaked in plain text in the logs, but is now located in memory where a memory dump is enough for the malware to grab it.

https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js?client=ca-pub-9816651697894810

(adsbygoogle = window.adsbygoogle []).push({});

What does this mean for your device?

None of these gaps matter if your computer is clean of malware. In the TechNoid lab, we noticed that all tests require prior local infection, which means that the most important firewall remains your own caution about what you download.

It doesn't break the encryption itself, but it bypasses Chrome's credential management logic. If you use public Wi-Fi or download cracked programs, no authentication technology can save you from a compromised device.

Our opinion at TechNoid

New research debunks the myth that passkeys are magical and invulnerable in every scenario. But let's not get too crazy; passkeys are still overwhelmingly more secure than putting "123456" or your date of birth everywhere.

Google should immediately close the memory management loopholes in Chrome, but the responsibility remains hybrid. Keep your operating system up to date and don't look for an excuse to go back to vulnerable passwords.

Dimitris Marizas
Dimitris Marizashttps://technoid.gr
I write about technology from the perspective of the person who uses it every day — not from conference rooms. I deal with networks, satellite internet, smartphones and digital services, with an emphasis on what these mean practically for the Greek user. Behind each article lies hours of analysis, testing and — when necessary — criticism of what the marketing tries to hide.

Related Articles

LEAVE A REPLY

enter your comment!
please enter your name here

- Advertisement -

Stay Connected

321SupportersLike
112FollowersFollow
231FollowersFollow
- Advertisement -

Most Popular 48hrs

- Advertisement -

Latest Articles