Pass-ta-key attacks expose flaws in Google Password Manager passkeys
Security researchers reveal three attacks that let malware on compromised Windows devices hijack Google-synced passkeys and extract private keys.
Conversation activity · last 8 days peak 5/2h
Summary, timeline and people extracted by Claude from 23 items across 6 sources · 8h ago. Quotes are verbatim.
Security researchers have discovered three attacks called "Pass-ta-key" that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. The attacks reveal differences in how passkey apps treat Windows compared to other operating systems. While some analysts characterize the threat as limited since it requires prior device compromise, the findings highlight security gaps in passwordless authentication systems.
- Pass-ta-key attacks allow malware on compromised Windows devices to hijack Google Password Manager's synced passkeys and extract private keys.
- The attacks work because passkey apps treat Windows differently than other operating systems, creating a security gap.
- The threat requires prior device compromise, limiting its real-world impact for most users.
- The discovery highlights vulnerabilities in supposedly more-secure passwordless authentication systems.
How it unfolded
-
Dan Goodin publishes analysis explaining why passkey apps treat Windows differently than other operating systems, framing the Pass-ta-key attack as "mostly a nothingburger."
“Here's why the new Pass-ta-key attack is mostly a nothingburger”
Dan Goodin · Mastodon ↗ -
The Hacker News, Unit 42 (Paloalto Networks), CyberSecurityNews, and other outlets publish detailed coverage of the Pass-ta-key attacks and their impact on Windows 11 and Microsoft Entra ID.
-
Security researchers discover three attacks enabling malware on compromised Windows devices to abuse Google Password Manager's synced passkeys, hijack accounts, bypass verification, and extract private keys.
What people are saying verbatim
“Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys.”
Lawrence Abrams, BleepingComputer reporter · BleepingComputer ↗
“Here's why the new Pass-ta-key attack is mostly a nothingburger”
Dan Goodin, Ars Technica security journalist · Ars Technica ↗ · Aug 10
“Why passkey apps treat Windows differently than other operating systems.”
Dan Goodin, Ars Technica security journalist · Ars Technica ↗ · Aug 10
Voices from the web unedited
-
The new "pass-ta-key" attack emphases what I've been saying all along about passkeys. If you're using passkeys -- heavily promoted by Google and other firms -- and your device is infected, you can lose EVERYTHING on EVERY account that is "protected" by passkeys. This is unlike the situation where password protected accounts would typically not be…
-
Because I don't want to trust google to have my passkeys? Why? See the featured article. I use a couple of hardware keys and they're unhackable. It's easy technology to use, and no passwords have to be remembered (other than a PIN). Google/Apple/Microsoft have made passkeys less secure because they want to own them (for example for 'syncing').
-
That’s good for you, but now try to convince my mom, that dumb person at work who calls help desk every time they try to print, the sales guy who is too busy, the parent who can never find their keys, etc.