New Google passkey attack could bypass fingerprint protection on infected PCs
India, Aug. 4 -- Passkeys are meant to end many of the risks tied to passwords. They resist phishing, cannot be reused across sites, and do not expose a shared secret that attackers can simply steal from a database.
But new research from Palo Alto Networks' Unit 42 shows that passkeys can still be undermined when malware is already running on a Windows PC.
The researchers described three attack paths against synced passkeys stored through Chrome and Google Password Manager. The techniques do not break Web Authentication, or WebAuthn, cryptography. Instead, they target the systems around it: device trust, browser state, re-enrollment, cloud recovery, and server-side verification.
There is no evidence that the attacks have been used in t...
Click here to read full article from source
To read the full article or to get the complete feed from this publication, please
Contact Us.