Tag

Webauthn

All articles tagged with #webauthn

WebKit flaws bypass iCloud Private Relay, revealing real IPs and DNS data
technology1 month ago

WebKit flaws bypass iCloud Private Relay, revealing real IPs and DNS data

Researchers have documented three WebKit mechanisms—DNS prefetching, WebAuthn verification requests, and WebTransport—that can slip outside iCloud Private Relay, potentially exposing a user’s real IP address or DNS information even when Private Relay is enabled. These are legitimate browser features, and the leaks may affect Safari privacy users and WebKit-based proxy browsers on iOS/macOS. VPNs at the system level remain unaffected, but passkeys aren’t stolen; exposure comes from specific network requests used during verification. To mitigate, keep Private Relay on, install OS updates, consider a full-device VPN when IP privacy is paramount, and monitor browser privacy updates as developers may block these paths (as some browsers have started to do).

Fresh Passkey Flaws Threaten MFA Across Windows, Chrome, and Entra ID
security2 months ago

Fresh Passkey Flaws Threaten MFA Across Windows, Chrome, and Entra ID

Three independent groups revealed passkey-related attack vectors that don’t break cryptography: exploiting exposed Windows-stored signed data to impersonate privileged users via Entra ID, compromising Google Password Manager’s synced passkeys in Chrome to recover private keys, and abusing a compromised Windows session to use a Windows Hello for Business key for new WebAuthn assertions. Impacts vary, with mitigations including CVE-2026-34348 fixes, enforcing user-verification for WebAuthn, and strengthened endpoint/zero-trust protections; no single fix exists since issues lie in surrounding controls, not math.

iCloud Private Relay Leaks Real IPs Through Passkey WebAuthn
technology2 months ago

iCloud Private Relay Leaks Real IPs Through Passkey WebAuthn

Security researchers say iCloud Private Relay, Apple’s feature designed to mask IP addresses in Safari, can still reveal a user’s real IP when WebAuthn passkeys are used because the OS credential service issues HTTPS requests outside Private Relay; DNS prefetching and WebTransport may also disclose IPs. Apple is investigating, and a test site has been released by the researchers. Since the leak stems from WebKit behavior and affects some third‑party browsers too, users may want to consider using a VPN or disabling Private Relay for certain sites until a fix is deployed.

Three Attack Vectors Threaten Chrome Passkeys on Windows
security2 months ago

Three Attack Vectors Threaten Chrome Passkeys on Windows

Unit 42 details three post-compromise attack paths—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that let malware on Windows abuse Chrome's Google Password Manager to sign into passkey-protected accounts, re-enroll devices, or extract the 32-byte Security Domain Secret from memory. The flaws do not break cryptography but target how Chrome stores device keys, re-enrolls devices, and checks user verification. No CVEs are listed and there are no confirmed exploits in the wild as of Aug 3, 2026. Mitigations include requiring userVerification, attesting newly enrolled keys, strengthening re-registration/recovery checks, restricting local passkey state access, and avoiding logging sensitive data. It’s unclear if SDS rotation or revocation is possible with current fixes.

ISO 27001 in a Passwordless World: The Passkey Migration Playbook
technology7 months ago

ISO 27001 in a Passwordless World: The Passkey Migration Playbook

The article argues that enterprises should migrate from password-based authentication to passkeys (FIDO2/WebAuthn) to strengthen security and stay compliant with ISO/IEC 27001, detailing how passkeys work, which controls they map to, practical migration steps, risk considerations (device loss, downgrade attacks), and best practices for phased rollout and documentation, with Passwork offering migration support.

PoisonSeed Attack Downgrades FIDO2 MFA Using Novel Phishing Tactics
security1 year ago

PoisonSeed Attack Downgrades FIDO2 MFA Using Novel Phishing Tactics

PoisonSeed threat actors are bypassing FIDO2 security keys by exploiting the cross-device sign-in feature in WebAuthn, tricking users into approving login requests from fake portals. This attack does not exploit a flaw in FIDO2 but abuses a legitimate feature, prompting organizations to implement additional security measures such as geographic restrictions and Bluetooth authentication. The attack highlights evolving methods to circumvent phishing-resistant authentication systems.

The Rise of Passkeys: A Password-Free Future
technology2 years ago

The Rise of Passkeys: A Password-Free Future

Bitwarden, a popular password manager, is introducing support for passkeys in its browser extensions. Passkeys offer a more secure and convenient alternative to traditional passwords, utilizing device authentication methods such as face recognition or fingerprint scanning. This feature is being rolled out gradually, following similar support from Apple, Google, and other password managers. Passkeys are generated using WebAuthn technology, with one key stored by the website and a private key stored on the user's device. While passkeys are not yet widely supported, more websites are adopting them as a login option. Bitwarden currently supports passkeys in browser extensions but plans to add support in its mobile app in the future.

Google Prompts Users to Create Passkeys for Passwordless Logins
technology3 years ago

Google Prompts Users to Create Passkeys for Passwordless Logins

Google is prompting users to set up passkey login for their Google accounts, offering a fast, secure, and passwordless approach to logins using pin, face, or fingerprint authentication on devices. While passwords will still be part of the login process, Google aims to make passkeys the new standard. Passkeys can replace traditional passwords by utilizing device authentication methods such as Face ID, fingerprint sensors, or Windows Hello. Passkeys are stored on the device and can be backed up or reauthenticated through phone numbers, email addresses, or hardware security keys. Google has introduced passkey support across its products and many leading websites and apps also support passkeys.

"Passkeys: The Future of Account Security and Convenience"
technology3 years ago

"Passkeys: The Future of Account Security and Convenience"

Nintendo has introduced support for passkeys, a passwordless sign-in method that allows users to access their online accounts using their device's authentication methods such as fingerprint or face scan. Passkeys, built on WebAuthn technology, generate two keys - one stored by the website or service and a private key stored on the user's device. Nintendo joins other online services like TikTok, Apple, PayPal, and 1Password in offering passkey support as a more secure alternative to passwords.

Passkey Support Goes Mainstream with 1Password and WhatsApp
technology3 years ago

Passkey Support Goes Mainstream with 1Password and WhatsApp

Password manager 1Password has announced the general availability of passkey support, a new login technology that replaces passwords with authentication systems built into a user's own device. Users can now create, manage, and sign in to supported websites with passkeys via 1Password's mobile apps and web browser extensions. The update does not yet include the ability to replace the master password with a passkey, but that feature is expected to arrive later this year. Passkeys work by utilizing the device's authentication methods, such as Face ID or fingerprint sensors, and are built on WebAuthn technology. While passkeys are stored on the device, backup options are available in case of loss or damage. Other password managers and platforms have also added passkey support, but 1Password's Universal Sign On is touted as superior due to its cross-platform compatibility and syncing capabilities.

Apple's Password-Free Future: iOS 17 Beta Introduces Passkey Support and Secure Sharing.
technology3 years ago

Apple's Password-Free Future: iOS 17 Beta Introduces Passkey Support and Secure Sharing.

Apple IDs now support passkeys, which can replace traditional passwords with your device's own authentication methods. Passkeys work across multiple devices and are built on WebAuthn tech. Once created, the passkey syncs across all of your Apple devices, letting any of them use the biometric logins set up on that system to sign in with your Apple ID. Passkeys are supported on Apple.com, icloud.com, and anywhere else your Apple account is linked to, but only if you have the first beta for iOS 17, iPadOS 17, or macOS Sonoma.

"Passwordless Sign-On Technology Expands to 1Password and Google Workspace Users"
technology3 years ago

"Passwordless Sign-On Technology Expands to 1Password and Google Workspace Users"

Password manager 1Password has launched its public beta for passkeys, a new login technology that allows users to replace passwords with authentication systems built into their devices. Passkeys are a new type of passwordless login technology developed by the FIDO Alliance, designed to provide better security and convenience compared to traditional passwords and user verification methods like 2FA or SMS. Passkeys allow users to replace traditional passwords when logging into websites and services with their device’s own authentication methods.