Tag

Passkeys

All articles tagged with #passkeys

Pass-ta-key exposes Windows' passkey blind spot
technology14 days ago

Pass-ta-key exposes Windows' passkey blind spot

A Pass-ta-key–style attack on Windows’ Google Password Manager shows passkeys aren’t universally bound to hardware; while other platforms store keys locally, Windows often uses cloud‑based encrypted blobs, allowing malware on a compromised PC to exfiltrate keys and trigger syncing to the infected device. The underlying design of FIDO2 does not require TPM storage, and the key takeaway is that passkeys reduce phishing but do not protect against a device already under attacker control.

Fresh Passkey Flaws Threaten MFA Across Windows, Chrome, and Entra ID
security14 days ago

Fresh Passkey Flaws Threaten MFA Across Windows, Chrome, and Entra ID

Three independent groups revealed passkey-related attack vectors that don’t break cryptography: exploiting exposed Windows-stored signed data to impersonate privileged users via Entra ID, compromising Google Password Manager’s synced passkeys in Chrome to recover private keys, and abusing a compromised Windows session to use a Windows Hello for Business key for new WebAuthn assertions. Impacts vary, with mitigations including CVE-2026-34348 fixes, enforcing user-verification for WebAuthn, and strengthened endpoint/zero-trust protections; no single fix exists since issues lie in surrounding controls, not math.

Three Pass-ta-key Attacks Threaten Google Password Manager Passkeys on Windows
security20 days ago

Three Pass-ta-key Attacks Threaten Google Password Manager Passkeys on Windows

Security researchers from Unit 42 disclosed three TPM-based attacks—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—targeting Google Password Manager’s synced passkeys on Windows; the exploits don’t break cryptography but abuse Chrome’s device identity, onboarding, and recovery flows to hijack or recover passkeys. Pass-ta-key impersonates a trusted device to obtain an authentication assertion, though some services verify user verification flags (GitHub blocked it; eBay failed but has since been addressed). Silver Pass-ta-key enables attacker-controlled verification keys during re-registration, letting attackers authenticate from a separate system. Golden Pass-ta-key captures the master key (security domain secret) used to encrypt synced passkeys from memory during re-registration, enabling decryption of passkeys and impersonation across accounts, with no current rotation or revocation. The researchers urge stronger verification, safer recovery/re-registration, and memory-protection of the master key.

Three Attack Vectors Threaten Chrome Passkeys on Windows
security22 days ago

Three Attack Vectors Threaten Chrome Passkeys on Windows

Unit 42 details three post-compromise attack paths—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that let malware on Windows abuse Chrome's Google Password Manager to sign into passkey-protected accounts, re-enroll devices, or extract the 32-byte Security Domain Secret from memory. The flaws do not break cryptography but target how Chrome stores device keys, re-enrolls devices, and checks user verification. No CVEs are listed and there are no confirmed exploits in the wild as of Aug 3, 2026. Mitigations include requiring userVerification, attesting newly enrolled keys, strengthening re-registration/recovery checks, restricting local passkey state access, and avoiding logging sensitive data. It’s unclear if SDS rotation or revocation is possible with current fixes.

Google expands recovery options with selfie-video sign-in
technology1 month ago

Google expands recovery options with selfie-video sign-in

Google adds a selfie-video sign-in as a new backup method for account recovery, using live-face verification (real-time movements) to confirm it’s you. The initial setup video is encrypted and stored with user consent (and can be deleted later), and eligible accounts can enable the feature via g.co/signin-selfie, complementing existing passkeys and recovery contacts.

Entra ID Makes Passkeys the Default, Ditching SMS/Voice MFA by 2027
technology1 month ago

Entra ID Makes Passkeys the Default, Ditching SMS/Voice MFA by 2027

Microsoft will make passkeys the default authentication method for Entra ID starting September 2026, auto-enabling them for users currently on SMS/voice MFA; SMS/voice authentication will be retired across all tenants on February 1, 2027. Users already using passkeys, Windows Hello for Business, FIDO2 keys, or other phishing-resistant methods can continue. After rollout, organizations should ensure all users adopt phishing-resistant methods to avoid sign-in disruptions, with third-party telecom providers available via the Security Store if needed. Microsoft cites AI-enabled phishing risks and says passkeys reduce credential theft by replacing phishable factors.

Phone passkeys: safer than passwords—but what about loss or theft?
life-and-style2 months ago

Phone passkeys: safer than passwords—but what about loss or theft?

A Guardian reader questions whether passkeys (which can be a PIN or biometrics on a smartphone) are truly safer than traditional passwords, given risks of phone theft or loss. While passkeys align with phishing resistance and stay device-bound, questions remain about real-world scenarios when a phone is compromised. The piece notes that the UK National Cyber Security Centre and others promote passkeys and invites readers to share experiences to better understand their practicality.

Microsoft Pushes Passkeys, Phasing Out SMS 2FA for Accounts
technology3 months ago

Microsoft Pushes Passkeys, Phasing Out SMS 2FA for Accounts

Microsoft is phasing out SMS-based two-factor authentication for personal Microsoft accounts in favor of passwordless options like passkeys and verified email, citing SMS vulnerabilities to fraud; users can set up a passkey through Advanced Security Options (Face, Fingerprint, PIN, or Security Key) and store it on a device, though passkeys can be less convenient on new or temporary devices. No firm date for a full rollout was given, and SMS may remain as a fallback via verified email until then.

Microsoft shifts to passwordless sign-ins, phasing out SMS codes
technology3 months ago

Microsoft shifts to passwordless sign-ins, phasing out SMS codes

Microsoft will retire SMS-based authentication for personal accounts and push passwordless sign-ins using passkeys, with verified secondary emails for account recovery. The new flow offers on-device passkeys that can be stored in password managers, smartphones, or Windows Hello biometrics, aiming to curb phishing and SIM-swapping. While sign-in could be faster and more secure, users accustomed to SMS verification may face friction during the transition.

Microsoft ends SMS sign-ins, doubles down on passwordless on Windows 11
technology3 months ago

Microsoft ends SMS sign-ins, doubles down on passwordless on Windows 11

Microsoft will stop using SMS verification for personal Microsoft accounts, phasing out SMS as a method for two-factor authentication and account recovery in favor of passwordless options like passkeys, authenticator apps, and verified backup emails. Microsoft argues SMS is insecure and a frequent fraud vector (including SIM-swaps), and promotes passkeys that rely on device biometrics and hardware-backed keys. The transition is cross-device compatible but may cause friction for power users and scenarios like virtual machines where a hardware-based sign-in isn’t available.

Entra passkeys enable phishing-resistant sign-ins on Windows
technology5 months ago

Entra passkeys enable phishing-resistant sign-ins on Windows

Microsoft is rolling out Entra passkeys on Windows to enable phishing-resistant, passwordless sign-in via Windows Hello. The opt-in public preview runs mid-March to late April 2026 for worldwide tenants (government-cloud timelines differ) and extends passwordless sign-in to unmanaged Windows devices. Passkeys are device-bound and per-account (no cross-device syncing), with multiple accounts able to coexist on one machine; each Entra account must register its own passkey. Admins must enable Passkeys (FIDO2) in Entra, create a Windows Hello profile with required AAGUIDs, and assign it to groups.

Bitwarden Enables Windows 11 Sign-Ins With Vault-Stored Passkeys
technology5 months ago

Bitwarden Enables Windows 11 Sign-Ins With Vault-Stored Passkeys

Bitwarden now supports Windows 11 sign-ins using passkeys stored in its vault, enabling phishing-resistant, passwordless authentication across all plans (including free). Users enable Entra ID FIDO2 sign-in, register a Bitwarden-stored passkey, and log in by scanning a QR code with a mobile device. The passkey is stored in the Bitwarden vault and synced across devices, improving recovery options and reducing exposure by avoiding password transmission.

ISO 27001 in a Passwordless World: The Passkey Migration Playbook
technology6 months ago

ISO 27001 in a Passwordless World: The Passkey Migration Playbook

The article argues that enterprises should migrate from password-based authentication to passkeys (FIDO2/WebAuthn) to strengthen security and stay compliant with ISO/IEC 27001, detailing how passkeys work, which controls they map to, practical migration steps, risk considerations (device loss, downgrade attacks), and best practices for phased rollout and documentation, with Passwork offering migration support.

The Shift Toward Passwordless Security: Embracing Passkeys and Facial Recognition
technology7 months ago

The Shift Toward Passwordless Security: Embracing Passkeys and Facial Recognition

Passkeys are a secure and user-friendly alternative to passwords that are underutilized due to low awareness, misconceptions, and implementation challenges. Companies are encouraged to promote phased adoption and educate users on their benefits to improve security and user experience, especially as traditional methods become more vulnerable to AI-driven attacks.