Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google.
Google's "uncopyable" passkeys might be more susceptible to theft than expected.
Passkeys are promoted as a safer alternative to passwords, ensuring protection against phishing, credential reuse, and password leaks. Google even asserts that they cannot be copied or inadvertently shared with others. However, their security may not be as robust as the company claims.
Security researchers (as reported by BleepingComputer) have discovered three ways in which malware can compromise the promises associated with passkeys synced via Google Password Manager. These techniques, collectively referred to as Pass-ta-key, target Google Password Manager within Chrome on Windows computers that are equipped with a Trusted Platform Module. Each attack necessitates that malware is already operating on the victim's computer.
The researchers did not breach the cryptographic mechanism of the passkeys, but rather took advantage of vulnerabilities in device trust, account recovery, onboarding, and the process by which services confirm that a user has indeed unlocked their device.
With a passkey, I can access my Google account on Windows.
Malware can impersonate a trusted device.
The first Pass-ta-key method allows malware to utilize Chrome’s TPM-backed device identity to request a valid passkey response from Google's cloud authenticator. This process does not require administrative rights, a biometric scan, a PIN, device unlocking, or any action from the victim. Google’s service interprets the request as coming from a recognized computer, thus providing the necessary authentication response for access.
Websites are meant to verify a flag indicating that the user has authenticated their identity. Unit 42 found that GitHub appropriately blocked the attack, while eBay accepted it despite claiming a verification requirement. eBay addressed this vulnerability after it was reported by the researchers.
A more sophisticated attack, known as Silver Pass-ta-key, can compel Chrome to register a verification key controlled by the attacker. This key is then recognized as confirmation that the victim entered a PIN or provided biometric data, enabling access from another device once the original one is offline.
The most severe attack directly steals the keys.
The Golden Pass-ta-key technique aims at the master secret used to encrypt all passkeys synced through a Google account. Researchers initially noted that Chrome revealed this secret in plain text through its internal FIDO logs. Google eliminated this information from the logs following the disclosure. However, Unit 42 reports that the key can still temporarily appear in Chrome’s process memory during device registration or recovery. Malware can capture it and decrypt the victim’s synced passkeys.
The compromised master key could potentially expose both existing and future passkeys. Unit 42 also points out that Google’s current setup does not allow for the rotation or revocation of that secret once it has been breached. Passkeys remain considerably more secure against phishing and password leaks, and Google's documentation still accurately reflects those benefits. This research indicates that malware already present on the computer can exploit the system surrounding the passkey instead.
Vikhyaat Vivek is a tech journalist and reviewer with seven years of experience covering consumer hardware, focusing on...
Apple will finally make it easier to copy and paste between iPhone and Windows.
Your iPhone may finally enable seamless copy and paste with a Windows PC.
Copying something on an iPhone to paste on a Windows PC ought to be a straightforward feature. While this seemingly simple process works effortlessly between an iPhone and a Mac, Windows users continue to wait. Now, Microsoft is officially requesting Apple to offer interoperable clipboard access through the European Union's interoperability process. The request, made on March 25, argues that iOS limitations hinder third-party platforms from providing an experience similar to Apple’s Universal Clipboard. Apple has now entered Phase III and committed to creating a solution.
Google looks to enhance extension reviews, but good ratings won’t completely prevent malware.
Google is testing integrated extension review prompts, but positive ratings can still conceal malware.
Google is preparing to introduce links for extension reviews directly within Chrome, placing feedback closer to the menus users already utilize to manage their extensions. A change in Chromium, first observed by Windows Report, indicates review options will be included in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would be considered, and the feature is still in development.
Apple's lawsuit against OpenAI has faced an embarrassing misdirected email.
Apple took aim at OpenAI’s trade secrets, but OpenAI has provided email evidence.
The legal dispute between Apple and OpenAI has rapidly moved past carefully crafted court statements. OpenAI has revealed the email exchanges related to the case, with one conversation casting doubt on Apple’s narrative. In a bluntly titled post, “Apple is getting this wrong,” OpenAI contested Apple’s request for a preliminary injunction and accused the iPhone maker of basing parts of its case on incorrect or incomplete information. Apple is seeking a court ruling to prevent OpenAI and two former Apple employees from accessing or disclosing its purported confidential information.
Other articles
Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google.
Researchers discovered three methods by which malware on a compromised Windows PC can seize Google-synced passkeys, circumvent user verification, and retrieve all private keys stored in the vault.
