
Pass-ta-key exposes Windows' passkey blind spot
A Pass-ta-key–style attack on Windows’ Google Password Manager shows passkeys aren’t universally bound to hardware; while other platforms store keys locally, Windows often uses cloud‑based encrypted blobs, allowing malware on a compromised PC to exfiltrate keys and trigger syncing to the infected device. The underlying design of FIDO2 does not require TPM storage, and the key takeaway is that passkeys reduce phishing but do not protect against a device already under attacker control.