New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Summary
Three new research efforts have revealed ways to bypass passkey security measures without compromising their underlying cryptography. These attacks exploit vulnerabilities by reusing signed authentication data, abusing cloud-synced passkey systems with existing malware, or other undisclosed methods. Passkeys are intended to replace passwords and offer phishing resistance, making these findings significant for authentication security.
IFF Assessment
The article describes new methods for defeating passkey security, which are designed to enhance authentication and prevent phishing, thus representing a negative development for defenders.
Defender Context
Defenders need to be aware of these new passkey attack vectors that undermine their intended phishing resistance. Organizations and users should monitor for updates and patches addressing these vulnerabilities, and consider layered security approaches beyond just passkeys.