Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
- Executive Summary This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients.
- The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts.
- We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.
Unverified
- Executive Summary This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients.
- The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts.
- We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.
Sources: Paloaltonetworks