Wird geladen…
  • August 4, 2026
  • Von aOneITForce

Pass-ta-key Research Finds New Weak Links in Synced Passkey Security

Pass-ta-key Research Finds New Weak Links in Synced Passkey Security

<p><strong>News Date: 2026-08-03</strong></p><p>Passkeys are widely promoted as the successor to passwords, but new research shows that passwordless authentication still depends heavily on the integrity of the endpoint and the surrounding implementation.</p><p>Palo Alto Networks Unit 42 researchers disclosed three attacks, collectively called Pass-ta-key, affecting Google Password Manager passkeys used through Chrome on Windows systems equipped with a Trusted Platform Module. Each technique requires malware to be running on the victim's computer, so the research does not describe a remote attack against a clean device or a failure of the underlying public-key cryptography.</p><h2>Three Routes Around Expected Protections</h2><p>The first technique allows unprivileged malware to impersonate a trusted device and obtain a valid authentication response. Its success can depend on whether the website properly checks the User Verified flag in the WebAuthn response. Researchers successfully demonstrated the issue against eBay before the company corrected its validation process.</p><p>The Silver Pass-ta-key variation targets device re-registration. Malware can force Chrome into an onboarding state and register an attacker-controlled verification key. This may let the attacker authenticate from another computer while appearing to have completed the required PIN or biometric verification.</p><p>The Golden Pass-ta-key technique is more serious because it targets the master secret used to encrypt synchronized passkeys. Google removed this secret from Chrome's diagnostic logs after disclosure, but the researchers reported that it can still appear temporarily in browser process memory during registration or recovery.</p><h2>What Security Teams Should Do</h2><ul><li>Require user verification for passkey authentication and validate the resulting flag.</li><li>Detect unexpected changes to Chrome passkey state and device-registration files.</li><li>Use endpoint controls that prevent untrusted software from reading browser memory.</li><li>Investigate unusual recovery prompts or repeated device onboarding events.</li><li>Keep Chrome, Windows and endpoint security products fully updated.</li></ul><p>I believe the central lesson is not that organizations should abandon passkeys. They remain a major improvement over reusable passwords and conventional phishing-sensitive authentication. However, passkeys must not be treated as a substitute for endpoint security.</p><p>When malware can manipulate trusted-device signals or observe secrets in memory, the authentication system may faithfully approve a request generated by a compromised machine. In my view, organizations adopting passkeys should combine them with application control, behavioral endpoint detection, hardened recovery procedures and risk-based monitoring of authentication events.</p>

Nach oben