[24205] in Privacy_Forum
[ PRIVACY Forum ] New attack reveals the truth about passkeys
daemon@ATHENA.MIT.EDU (Lauren Weinstein)
Tue Aug 11 12:46:06 2026
Date: Tue, 11 Aug 2026 09:20:17 -0700
From: Lauren Weinstein <lauren@vortex.com>
To: privacy-dist@vortex.com
Message-ID: <20260811162017.GA25260@vortex.com>
Content-Disposition: inline
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="us-ascii"; Format="flowed"
Errors-To: privacy-bounces+privacy-forum=mit.edu@vortex.com
New attack reveals the truth about passkeys
The new "pass-ta-key" attack emphases what I've been saying all along
about passkeys. If you're using passkeys -- heavily promoted by Google
and other firms -- and your device is infected, you can lose
EVERYTHING on EVERY account that is "protected" by passkeys. This is
unlike the situation where password protected accounts would typically
not be undermined unless you entered the password on an infected
device. But because passkeys (or password managers not protected by a
global password) hold all the keys to your accounts, they provide a
"one stop shopping" mechanism to destroy your digital life. Passkeys
are good at stopping phishing attacks, but they bring their own risks,
which can be even worse. -L
- - -
--Lauren--
Lauren Weinstein
lauren@vortex.com (https://www.vortex.com/lauren)
Lauren's Blog: https://lauren.vortex.com
Mastodon: https://mastodon.laurenweinstein.org/@lauren
Signal: By request on need to know basis
Founder: Network Neutrality Squad: https://www.nnsquad.org
PRIVACY Forum: https://www.vortex.com/privacy-info
Co-Founder: People For Internet Responsibility
_______________________________________________
privacy mailing list
https://lists.vortex.com/mailman/listinfo/privacy