Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Pass-ta-key Takes Advantage Of Some Assumptions When Grabbing Your Windows Passkeys

Дата публикации: 11-08-2026 22:31:02


Passkeys are a somewhat new attempt to find something to replace passwords, session cookies, MFA and all the other ways we have to use on the internet to verify both that we…

Основное содержимое страницы с новостью.

Definitely Not Blessed By His Noodly Appendage

Passkeys are a somewhat new attempt to find something to replace passwords, session cookies, MFA and all the other ways we have to use on the internet to verify both that we are indeed who we say we are and that we’re authorized to access the resource being queried.  If you’re not quite clear on what passkeys are, Ars Technica posted a great primer a few years back.   In brief they are paired cryptographic keys, one public on the site you created an account and one private which is located on the specific device you used when creating the key.  If the pairing checks out you get to log in without needing to enter a password or other verification method.

The assumption most had was that those local passkeys were stored securely on the local system, be it TPM chips, secure enclaves or whatever the OS calls it’s protected area.  The problem is that storing it in such a way means that you can’t replicate your passkeys to another device. If you can only use a passkey on one device without creating it again from scratch then people are unlikely to adopt it because it would be a bit of a PITA.  The FIDO Alliance decided that the OS on the local device would protect attackers from cloning passkeys on compromised machines and they were right, apart from Windows, and therefore storing passkeys in these secure locations would be optional and not required.

Windows tends to run everything with the same privileges as the logged in user, other OSes tend towards least access and that is where Pass-ta-key comes in.  Pass-ta-key is the oddly named vulnerability discovered by a researcher at security firm Palo Alto Networks.  They proved that if a Windows machine is compromised by malware, an attacker could steal any and all local passkeys stored in the Google Password Manager app.  It is unclear if other password manager apps suffer the same vulnerability but it is not impossible that they could also be vulnerable to Pass-to-key.  

The attacker has several ways to take advantage of Pass-ta-key, such as making an infected machine look like an iPhone, accessing a user’s Google Password Manager and triggering the convenient copy mechanism to migrate your passkeys to a new device to get a copy of all your passkeys.   While this means Pass-ta-key is not exactly the novel attack it was billed as but it is still dangerous.  You can get more details from Ars Technica if you want.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1La alternativa a las contraseñas que deberías conocer08.2617-07-2026
2Why you need to take back control of your synced passwords and how to go about doing that010.7620-06-2026
3Эксперты предупредили о новом способе обхода защиты аккаунтов мошенниками-2603-07-2026
4Эксперты считают, что злоумышленники распространяют вирус под видом ChatGPT для Windows0022-02-2023
5Windows clipboard is more capable than you think, here's how to get the most out of it2619-07-2026
6Microsoft разрешила пользователям входить в учетные записи без пароля0016-09-2021
7Мошенники нашли новый способ взлома двухфакторной аутентификации-2702-07-2026
8Мошенники придумали новую уловку для кражи аккаунтов на «Госуслугах»01024-07-2026
9Why Risk-Based MFA is a Game Changer for User Experience012.0110-08-2026
10Минцифры рассказало о новом способе мошенничества с QR-кодами на "Госуслугах"0015-01-2022

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.86. Источник: pcper.com.