Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google.

Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google.

      Google's "uncopyable" passkeys might be more susceptible to theft than expected.

      Passkeys are promoted as a safer alternative to passwords, ensuring protection against phishing, credential reuse, and password leaks. Google even asserts that they cannot be copied or inadvertently shared with others. However, their security may not be as robust as the company claims.

      Security researchers (as reported by BleepingComputer) have discovered three ways in which malware can compromise the promises associated with passkeys synced via Google Password Manager. These techniques, collectively referred to as Pass-ta-key, target Google Password Manager within Chrome on Windows computers that are equipped with a Trusted Platform Module. Each attack necessitates that malware is already operating on the victim's computer.

      The researchers did not breach the cryptographic mechanism of the passkeys, but rather took advantage of vulnerabilities in device trust, account recovery, onboarding, and the process by which services confirm that a user has indeed unlocked their device.

      With a passkey, I can access my Google account on Windows.

      Malware can impersonate a trusted device.

      The first Pass-ta-key method allows malware to utilize Chrome’s TPM-backed device identity to request a valid passkey response from Google's cloud authenticator. This process does not require administrative rights, a biometric scan, a PIN, device unlocking, or any action from the victim. Google’s service interprets the request as coming from a recognized computer, thus providing the necessary authentication response for access.

      Websites are meant to verify a flag indicating that the user has authenticated their identity. Unit 42 found that GitHub appropriately blocked the attack, while eBay accepted it despite claiming a verification requirement. eBay addressed this vulnerability after it was reported by the researchers.

      A more sophisticated attack, known as Silver Pass-ta-key, can compel Chrome to register a verification key controlled by the attacker. This key is then recognized as confirmation that the victim entered a PIN or provided biometric data, enabling access from another device once the original one is offline.

      The most severe attack directly steals the keys.

      The Golden Pass-ta-key technique aims at the master secret used to encrypt all passkeys synced through a Google account. Researchers initially noted that Chrome revealed this secret in plain text through its internal FIDO logs. Google eliminated this information from the logs following the disclosure. However, Unit 42 reports that the key can still temporarily appear in Chrome’s process memory during device registration or recovery. Malware can capture it and decrypt the victim’s synced passkeys.

      The compromised master key could potentially expose both existing and future passkeys. Unit 42 also points out that Google’s current setup does not allow for the rotation or revocation of that secret once it has been breached. Passkeys remain considerably more secure against phishing and password leaks, and Google's documentation still accurately reflects those benefits. This research indicates that malware already present on the computer can exploit the system surrounding the passkey instead.

      Vikhyaat Vivek is a tech journalist and reviewer with seven years of experience covering consumer hardware, focusing on...

      Apple will finally make it easier to copy and paste between iPhone and Windows.

      Your iPhone may finally enable seamless copy and paste with a Windows PC.

      Copying something on an iPhone to paste on a Windows PC ought to be a straightforward feature. While this seemingly simple process works effortlessly between an iPhone and a Mac, Windows users continue to wait. Now, Microsoft is officially requesting Apple to offer interoperable clipboard access through the European Union's interoperability process. The request, made on March 25, argues that iOS limitations hinder third-party platforms from providing an experience similar to Apple’s Universal Clipboard. Apple has now entered Phase III and committed to creating a solution.

      Google looks to enhance extension reviews, but good ratings won’t completely prevent malware.

      Google is testing integrated extension review prompts, but positive ratings can still conceal malware.

      Google is preparing to introduce links for extension reviews directly within Chrome, placing feedback closer to the menus users already utilize to manage their extensions. A change in Chromium, first observed by Windows Report, indicates review options will be included in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would be considered, and the feature is still in development.

      Apple's lawsuit against OpenAI has faced an embarrassing misdirected email.

      Apple took aim at OpenAI’s trade secrets, but OpenAI has provided email evidence.

      The legal dispute between Apple and OpenAI has rapidly moved past carefully crafted court statements. OpenAI has revealed the email exchanges related to the case, with one conversation casting doubt on Apple’s narrative. In a bluntly titled post, “Apple is getting this wrong,” OpenAI contested Apple’s request for a preliminary injunction and accused the iPhone maker of basing parts of its case on incorrect or incomplete information. Apple is seeking a court ruling to prevent OpenAI and two former Apple employees from accessing or disclosing its purported confidential information.

Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google. Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google. Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google. Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google. Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google. Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google. Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google.

Other articles

Apple challenges the UK's restricted iCloud backdoor directive. Apple challenges the UK's restricted iCloud backdoor directive. After losing the battle in 2025, Britain restricted its demand for an Apple backdoor to only UK users. Apple has gone back to a covert surveillance court to contest this. Alex Karp's one-sided radicalism: Palantir's issue with Marxism is Palantir itself. Alex Karp's one-sided radicalism: Palantir's issue with Marxism is Palantir itself. Alex Karp states that Palantir has 'Marxist overtones.' If this concept is considered seriously, it focuses on Palantir itself, the company that controls the infrastructure. The demand for AI is pushing data center developers to seek financing from banks. The demand for AI is pushing data center developers to seek financing from banks. As power has become the limiting factor for AI, data center developers are pursuing billions in bank financing commitments to secure electricity and facilitate construction. TikTok reaches another settlement to avoid a jury trial regarding harm to teens. TikTok reaches another settlement to avoid a jury trial regarding harm to teens. TikTok resolved the three lawsuits it was scheduled to contest in October, continuing a streak that has spared it from any jury trials. In contrast, Meta and Google opted to contest their cases. The U.S. is working on a prohibition against Chinese devices in data centers. The U.S. is working on a prohibition against Chinese devices in data centers. The Trump administration is working on a ban for data center equipment manufactured in China, furthering its efforts to isolate US AI infrastructure from Chinese technology. SpaceX is pushing competitors out of the market for the rockets they rely on. SpaceX is pushing competitors out of the market for the rockets they rely on. As SpaceX increases the number of its Starlink satellites, it is pushing competing satellite companies out of the Falcon 9 launch schedule, with some reservations extending to 2028-2029.

Passkeys were promoted as a more secure future. However, hackers have found methods to compromise those synchronized with Google.

Researchers discovered three methods by which malware on a compromised Windows PC can seize Google-synced passkeys, circumvent user verification, and retrieve all private keys stored in the vault.