[24205] in Privacy_Forum

home help back first fref pref prev next nref lref last post

[ PRIVACY Forum ] New attack reveals the truth about passkeys

daemon@ATHENA.MIT.EDU (Lauren Weinstein)
Tue Aug 11 12:46:06 2026

Date: Tue, 11 Aug 2026 09:20:17 -0700
From: Lauren Weinstein <lauren@vortex.com>
To: privacy-dist@vortex.com
Message-ID: <20260811162017.GA25260@vortex.com>
Content-Disposition: inline
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="us-ascii"; Format="flowed"
Errors-To: privacy-bounces+privacy-forum=mit.edu@vortex.com


New attack reveals the truth about passkeys

The new "pass-ta-key" attack emphases what I've been saying all along
about passkeys. If you're using passkeys -- heavily promoted by Google
and other firms -- and your device is infected, you can lose
EVERYTHING on EVERY account that is "protected" by passkeys. This is
unlike the situation where password protected accounts would typically
not be undermined unless you entered the password on an infected
device. But because passkeys (or password managers not protected by a
global password) hold all the keys to your accounts, they provide a
"one stop shopping" mechanism to destroy your digital life. Passkeys
are good at stopping phishing attacks, but they bring their own risks,
which can be even worse. -L

 - - -
--Lauren--
Lauren Weinstein 
lauren@vortex.com (https://www.vortex.com/lauren)
Lauren's Blog: https://lauren.vortex.com
Mastodon: https://mastodon.laurenweinstein.org/@lauren
Signal: By request on need to know basis
Founder: Network Neutrality Squad: https://www.nnsquad.org
         PRIVACY Forum: https://www.vortex.com/privacy-info
Co-Founder: People For Internet Responsibility
_______________________________________________
privacy mailing list
https://lists.vortex.com/mailman/listinfo/privacy

home help back first fref pref prev next nref lref last post