Pass-ta-Key Attacks: Is Passwordless Security Still Safe?

Pass-ta-Key Attacks: Is Passwordless Security Still Safe?

Apple, Google, Microsoft, and the security industry have spent years telling us that passkeys are the future of authentication.

No passwords.

Less phishing.No reusable credentials for attackers to steal.

But researchers have now demonstrated something important :Attackers may not need to break the passkey itself. They can attack everything around it. Windows. Browsers. Extensions. Password managers. Cloud synchronization. Authentication workflows.

Welcome to the world of Pass-ta-Key attacks.

In this episode of the Technically U Podcast, we break down how researchers demonstrated more than 20 techniques targeting weaknesses in the passkey ecosystem—and what that means for consumers, enterprises, and the future of passwordless authentication.

🔍 THE BIG DISTINCTIONPass-ta-Key attacks do not necessarily break FIDO2 cryptography.Instead, they target implementation weaknesses surrounding authentication, including:•

Windows event logging• Server-side WebAuthn validation• Malicious browser extensions• Synced passkey architectures• Endpoint memory• Recovery and registration workflowsThe cryptography can remain strong while the surrounding environment creates another path for attackers.🎯 ATTACK VECTOR 1: WINDOWS EVENT LOGGINGResearchers identified a Windows vulnerability, CVE-2026-34348, involving WebAuthn authentication information appearing in Windows Event Logs.In the demonstrated attack chain:An attacker first compromises the endpointMalware accesses Windows Event LogsWebAuthn authentication material is extractedThe attacker attempts to replay itWeak validation can allow unauthorized accessMicrosoft released a Windows update addressing the issue in July 2026.🌐 ATTACK VECTOR 2: MALICIOUS BROWSER EXTENSIONSResearchers also demonstrated how a malicious Chrome or Edge extension could interfere with passkey creation.Instead of stealing an existing private key, the extension attacks the registration process itself.If successful, an attacker-controlled credential may be registered while everything appears normal to the user.The lesson:If the browser is compromised, strong authentication alone may not save you.🔑 ATTACK VECTOR 3: SYNCED PASSKEYSSynced passkeys provide enormous convenience because credentials can follow users across devices.But synchronization also creates additional attack surface.Research involving Google Password Manager examined techniques targeting sensitive information available during the synchronization and decryption process.A sufficiently capable attacker with endpoint access may attempt to steal information protecting multiple synced passkeys rather than attacking accounts one at a time.⚠️ SO... ARE PASSKEYS BROKEN?No.Passkeys still provide major security improvements over traditional passwords, especially against:• Credential phishing• Password reuse• Weak passwords• Stolen password databasesBut “phishing-resistant” should not be interpreted as attack-proof.Passkeys still depend on secure operating systems, browsers, identity providers, endpoints, synchronization systems, and proper implementation.That means defense in depth still matters.🏢 WHAT ENTERPRISES SHOULD DOA passkey can be a strong authentication factor.It should not automatically become the entire security strategy.🎙️ Technically U PodcastMaking complex cybersecurity, networking, cloud, AI, and emerging technology easier to understand.Subscribe and join the conversation.#Passkeys #FIDO2 #Cybersecurity #WebAuthn #Passwordless #MFA #IdentitySecurity #ZeroTrust #BrowserSecurity #MicrosoftSecurity #CyberSecurity #TechnicallyU

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(270)

SaaS Bloodbath: Why Your Trusted Apps Are Now the Attack Surface

SaaS Bloodbath: Why Your Trusted Apps Are Now the Attack Surface

Your company may not get hacked through the firewall. It may get breached through the SaaS app everyone trusts.In this episode of Technically U, we break down the growing SaaS security crisis and why ...

5 Sep 36min

The AI Data Disaster: What ChatGPT, Claude, and Gemini Really Do With Your Secrets

The AI Data Disaster: What ChatGPT, Claude, and Gemini Really Do With Your Secrets

143,000 ChatGPT, Claude, and Copilot conversations are publicly accessible right now. Here's what was exposed—and why your AI isn't as private as you think.🚨 THE HEADLINE:143,000 user conversations w...

29 Aug 21min

The BIMI Paradox: Why 90% of Companies Are Losing Thousands.

The BIMI Paradox: Why 90% of Companies Are Losing Thousands.

The BIMI Paradox: Why 90% of Companies Are Losing Thousands—And Why Your Logo Might Be Illegal in Inboxes (2026 Reality Check).BIMI (Brand Indicators for Message Identification): 90% of companies have...

29 Aug 26min

Beyond Surveillance: How Behavioral Analytics Became a Trust Problem

Beyond Surveillance: How Behavioral Analytics Became a Trust Problem

Behavioral Analytics in 2026: How Companies Are Moving From Surveillance to Trust ArchitectureThe paradox nobody talks about: 76% of companies see efficiency gains from monitoring. But 60% of employee...

20 Aug 17min

The Confidence Gap: Why Executives Think AI Agents Are Secure (And Why They're Wrong)

The Confidence Gap: Why Executives Think AI Agents Are Secure (And Why They're Wrong)

The Confidence Gap: AI Agents and the Security Crisis Nobody Is Talking AboutEighty-two percent of executives feel confident that their existing AI agent policies are enough to keep their organization...

8 Aug 18min

Seeing Is No Longer Believing: How Deepfake Fraud Targets Businesses and Families

Seeing Is No Longer Believing: How Deepfake Fraud Targets Businesses and Families

What if the voice on the phone sounds exactly like your boss, your bank, or someone in your family — but it isn’t them?In this episode of Technically U, we break down Deepfake Fraud and why it has bec...

31 Jul 23min

The AI Criminal Playbook: How Cybercrime Changed Forever in 2026

The AI Criminal Playbook: How Cybercrime Changed Forever in 2026

The next generation of cybercrime may not come from a hacker typing code in a dark room.It may come from someone using AI to generate phishing emails, clone voices, create fake identities, manipulate ...

24 Jul 16min

Populært innen Teknologi

teknisk-sett
energi-og-klima
lydartikler-fra-aftenposten
nasjonal-sikkerhetsmyndighet-nsm
smart-forklart
tomprat-med-gunnar-tjomlid
elektropodden
rss-ai-forklart
shifter
pedagogisk-intelligens
fornybaren
kortslutning
rss-bouvet-bobler
rss-ki-praten
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
rss-alt-som-gar-pa-strom
rss-larervarelset
rss-digitaliseringspadden
hans-petter-og-co
rss-bits-and-bytes-for-advokater