Report: Passkey security issues could allow account takeover
Summary
A Palo Alto Networks Unit 42 report details methods attackers can exploit to take over passkey-protected accounts. These attacks leverage weaknesses in surrounding procedures like onboarding and recovery, rather than breaking passkey cryptography itself. The methods can allow attackers to bypass user verification and extract synced passkey private keys.
IFF Assessment
This report details new attack vectors that could allow account takeover, posing a risk to defenders who are implementing passkey authentication.
Defender Context
This analysis highlights that while passkeys offer improved security over traditional passwords, vulnerabilities can still exist in the implementation and surrounding workflows. Defenders need to be aware of these 'seam' exploits, focusing on securing account onboarding, recovery processes, and ensuring proper validation of trust signals to prevent account takeover.