Skip to content
Tech News
← Back to articles

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

read original more articles
Why This Matters

This article highlights emerging security challenges in passwordless authentication systems, emphasizing that even advanced passkey ecosystems are vulnerable to sophisticated malware attacks. As passkeys aim to enhance security and replace traditional passwords, understanding these new attack surfaces is crucial for developers and consumers to ensure robust protection. Addressing these vulnerabilities is vital for maintaining trust and security in the evolving digital authentication landscape.

Key Takeaways

Executive Summary

This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.

After decades of breaches and billions in losses, the attack vectors that defined the era of passwords and shared secrets are finally starting to fade. Passkeys replace passwords and traditional multi-factor authentication (MFA) with public-key cryptography, decreasing entire classes of attacks that have dominated the threat landscape for years.

With no shared secret to steal, reuse or phish, many of an attacker’s most reliable tools are becoming obsolete. This represents a significant disruption for the credential theft market.

Attackers, however, persist. They evolve, and defenders must prepare for a new generation of attacks. As passkeys become widely adopted and scale to billions of accounts, defenders must prepare for new attack surfaces, some of which we disclose in our research.

This article is part 3 in our series examining passkey adoption from a security perspective. If you haven’t read the previous parts, we recommend starting here:

Part 1: The Art of the Invisible Key – Passkey Global Breakthrough

Part 2: Google Authenticator: The Hidden Mechanisms of Passwordless Authentication

Palo Alto Networks customers are better protected from this new attack vector through the following products and services:

If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team.

... continue reading