Hacker News·4 min read·hard

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

J
jchanimal
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
AI Summary

Security researchers have uncovered new attack vectors targeting passwordless authentication systems, specifically Google's synced passkey ecosystem. The research demonstrates how malware can bypass user verification and extract private keys, challenging the perceived invulnerability of passkeys.

This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycrypto

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication — Headlinne — headlinne