A researcher has outlined a potential vulnerability in passkeys, a new authentication method designed to be more secure than traditional password-based systems. The attack, dubbed Pass-ta-key, was described by Arie Olshtein, a researcher at security firm Palo Alto Networks, in a post last week. However, experts have pointed out that the attack is neither novel nor unique to passkeys, and has generated confusion among users and security professionals about the safety of this new mechanism.
The Pass-ta-key attack can obtain all passkeys stored in the Google Password Manager app for Windows when it’s running on a machine infected with malware. This has raised questions about how the attack is able to extract passkeys, as many people believed they were stored exclusively in the trusted platform manager (TPM), a secure enclave in a hardened silicon chip reserved for storing cryptographic keys and other sensitive information on Windows machines.
The fact that Pass-ta-key can extract passkeys from the Google Password Manager app has come as a surprise to many, as it was thought that passkeys were stored securely in the TPM. The discovery has led to concerns about the security of passkeys and whether they are truly safe to use.
According to Olshtein's post, the Pass-ta-key attack takes advantage of the fact that passkeys are not always stored in the TPM. While the TPM is a secure environment for storing sensitive information, it appears that passkeys can also be stored in other locations, making them vulnerable to attack.
The Pass-ta-key attack has highlighted the need for further research and understanding of how passkeys are stored and protected. As passkeys become more widely adopted, it is essential to ensure that they are secure and resistant to attack. The discovery of the Pass-ta-key vulnerability is an important reminder of the need for ongoing vigilance and testing to ensure the security of new authentication methods.
Security professionals and users will be watching closely to see how the Pass-ta-key vulnerability is addressed and what steps are taken to improve the security of passkeys. In the meantime, users are advised to remain cautious and to keep their systems and software up to date to minimize the risk of attack.
<small>Source: Ars Technica — read the original story there.</small>