39 New Methods That Compromise Passkey Authentication
Summary
Researchers have identified 39 new methods that can compromise passkey authentication, despite the technology's ability to mitigate many password-based attacks. These methods exploit trust boundaries such as authentication prompts, synced credentials, enrollment, and recovery processes, without directly breaking the underlying FIDO2 cryptography.
IFF Assessment
The article details new attack vectors that can compromise passkey authentication, posing a direct threat to defenders.
Defender Context
While passkeys are designed to be more secure than passwords, this research highlights that attackers are finding novel ways to circumvent their protections. Defenders need to be aware of these emerging attack vectors and ensure that the implementation and management of passkey systems address these potential weaknesses beyond just the cryptographic layer.