New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Summary

Three new research efforts have revealed ways to bypass passkey security measures without compromising their underlying cryptography. These attacks exploit vulnerabilities by reusing signed authentication data, abusing cloud-synced passkey systems with existing malware, or other undisclosed methods. Passkeys are intended to replace passwords and offer phishing resistance, making these findings significant for authentication security.

IFF Assessment

FOE

The article describes new methods for defeating passkey security, which are designed to enhance authentication and prevent phishing, thus representing a negative development for defenders.

Defender Context

Defenders need to be aware of these new passkey attack vectors that undermine their intended phishing resistance. Organizations and users should monitor for updates and patches addressing these vulnerabilities, and consider layered security approaches beyond just passkeys.

Read Full Story →