As cited
Copy frozen at (site build).
identity access
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Researcher Arie Olshtein from Palo Alto Networks disclosed a technique called Pass-ta-key that can extract passkeys from Google Password Manager on infected Windows machines, contradicting common assumptions that passkeys are stored exclusively in the trusted platform module (TPM). The attack demonstrates that not all passkeys are protected by TPM hardware isolation, though the underlying vulnerabilities are neither novel nor unique to the passkey authentication mechanism itself. The disclosure has prompted reassessment of passkey security among practitioners and end users.
Why it matters: Organizations and users relying on passkeys for Windows systems need to verify whether their passkey storage uses TPM protection or is vulnerable to malware-based extraction, and should ensure endpoint protection and monitoring are in place to detect compromised credentials.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
identity access
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Researcher Arie Olshtein from Palo Alto Networks disclosed a technique called Pass-ta-key that can extract passkeys from Google Password Manager on infected Windows machines, contradicting common assumptions that passkeys are stored exclusively in the trusted platform module (TPM). The attack demonstrates that not all passkeys are protected by TPM hardware isolation, though the underlying vulnerabilities are neither novel nor unique to the passkey authentication mechanism itself. The disclosure has prompted reassessment of passkey security among practitioners and end users.
Why it matters: Organizations and users relying on passkeys for Windows systems need to verify whether their passkey storage uses TPM protection or is vulnerable to malware-based extraction, and should ensure endpoint protection and monitoring are in place to detect compromised credentials.
- Source published
- First seen by Cybersecurity Tracker