ELSEIF
Your brief EB
320 stories from 72 feeds 58 clusters Refreshed 5 minutes ago next pull 01:05

SECURITY Signal 531

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

New research reveals malware-based attacks that bypass passkey authentication in Google’s synced ecosystem without user interaction or device unlocks.

WHY IT MATTERS

Engineers building or deploying passwordless systems must now account for endpoint compromise as a viable attack path. The shift from phishing-resistant credentials to cloud-synced keys introduces new failure modes that existing security controls may not detect. If unaddressed, these attacks could erode trust in passkeys as a replacement for passwords.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Malware on a compromised device can authenticate to passkey-protected accounts without privilege escalation or user prompts.

02

Attackers can extract and exfiltrate all synced passkey private keys, enabling credential theft at scale.

03

Hardware-backed device trust mechanisms fail when the endpoint itself is untrusted.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Hacker News Pass the Passkey: A Novel Attack Surface in Passwordless Authentication Open ↗