Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
4 clusters · 6 sources · 47 days · First seen · Last updated
Passkey technology adoption and security research
Overview
Passkey technology has seen widespread adoption, with approximately five million users globally and high consumer awareness. For enterprises, the technology has demonstrated the ability to reduce help-desk tickets related to password issues by as much as 60%. New specifications have also been proposed to create an interoperable format for storing passkey credentials, which aims to simplify server-side integration. However, cybersecurity research has identified vulnerabilities in how passkeys are implemented and managed. These findings indicate that while the underlying cryptography remains secure, flaws in authentication chains—such as those involving Windows and Microsoft Entra ID—can allow for user impersonation. Researchers have also identified methods to recover private keys within Google Password Manager and noted that malware in active sessions can sometimes utilize hardware-bound keys without additional biometric checks. Experts have clarified that these risks often stem from storage methods; because FIDO 2 specifications do not mandate hardware-based storage, many platforms store passkeys locally to facilitate cross-device syncing, creating an attack surface for malware already present on a system. Recent studies have expanded on these risks. Research from Palo Alto Networks’ Unit 42 indicates that malware can exploit passkey workflows, device sharing, and account recovery processes, sometimes bypassing biometric or PIN requirements by leveraging trust from previously registered devices. Furthermore, a Cornell University study presented at the USENIX Security Symposium highlighted limitations within the FIDO2 architecture, demonstrating that an attacker with temporary physical or technical access to a device could potentially register their own credentials. Newer research has identified at least 39 documented methods and exploitation scenarios that can compromise passkey authentication and its surrounding infrastructure. These techniques target various layers, including web applications, browsers, operating systems, and cloud synchronization services, through methods such as assertion phishing, browser hooking, and user verification manipulation.
Entities
FIDO Alliance · Palo Alto Networks · SpecterOps · Proton Pass · Google
Timeline
-
27 days ago
[TECHNOLOGY] 2 sourcesPasskey authentication faces new security threats and market shiftsResearchers have identified 39 ways to compromise passkey authentication, while major password managers like 1Password and Bitwarden navigate new security features and pricing shifts.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesPasskey security vulnerabilities identified by researchersResearchers from Palo Alto Networks and Cornell University have identified ways attackers can bypass passkey security and take over accounts if a user's device is already infected or physically accessed.
-
about 2 months ago
[TECHNOLOGY] 3 sourcesPasskey security research reveals vulnerabilities in authentication implementationsResearchers have demonstrated new ways to bypass passkey protections by exploiting how authentication material is reused, synced, or stored on devices, rather than breaking the underlying cryptography.
-
2 months ago
[TECHNOLOGY] 2 sourcesPasskeys Adoption Cuts Helpdesk Requests by Up to 60%Passkeys are used by about five million people, known by 90% of consumers, and can slash password‑related helpdesk tickets by up to 60%; a new interoperable record format aims to simplify implementation.
Sources
arstechnica.com · b2b-cyber-security.de · cybernoz.com · it-boltwise.de · technewsdaily.com · thehackernews.com
This summary has been updated 2 times: see revision history