New Pass-ta-key attack reveals all the things we didn't know about passkeys

A security researcher identified the 'Pass-ta-key' attack, which can extract passkeys from the Google Password Manager on Windows. The research clarifies that passkeys are not always stored in hardware-level security chips, contrary to popular belief.
Why it matters
This highlights a critical misunderstanding regarding the security architecture of passkeys, which are increasingly being adopted as a replacement for traditional passwords.
NOW YOU KNOW New Pass-ta-key attack reveals all the things we didn’t know about passkeys Why passkey apps treat Windows differently than other operating systems.
35 Credit: Aurich Lawson | Getty Images Credit: Aurich Lawson | Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Last week a researcher outlined what he said was a “novel attack surface” in passkeys, the new authentication paradigm that offers a more secure alternative over password-based methods. In fact, the attacks demonstrated in the post are neither novel nor unique to passkeys. This distinction is important because the research has generated confusion among end users and security professionals as they assess whether this new mechanism is truly safe to use.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in