SECURITY Signal 531
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
New research reveals malware-based attacks that bypass passkey authentication in Google’s synced ecosystem without user interaction or device unlocks.
Engineers building or deploying passwordless systems must now account for endpoint compromise as a viable attack path. The shift from phishing-resistant credentials to cloud-synced keys introduces new failure modes that existing security controls may not detect. If unaddressed, these attacks could erode trust in passkeys as a replacement for passwords.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Malware on a compromised device can authenticate to passkey-protected accounts without privilege escalation or user prompts.
Attackers can extract and exfiltrate all synced passkey private keys, enabling credential theft at scale.
Hardware-backed device trust mechanisms fail when the endpoint itself is untrusted.
THE CLUSTER
↗