Close Menu
Techy101 –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    PSVR Dolphin Game ‘Jupiter & Mars: Definitive Edition’ Hits Switch This Week

    September 7, 2026

    Get The Entire Metro Series For Under $9 Ahead Of Metro 2039’s Release

    September 7, 2026

    Hottest Female Fortnite Skins: The 25 Best in Chapter 7 Season 4

    September 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • PSVR Dolphin Game ‘Jupiter & Mars: Definitive Edition’ Hits Switch This Week
    • Get The Entire Metro Series For Under $9 Ahead Of Metro 2039’s Release
    • Hottest Female Fortnite Skins: The 25 Best in Chapter 7 Season 4
    • My Favorite Home Security Reveal at IFA Was AI, but Not How You Think
    • Samsung Galaxy A07s debuts with a 6.7-inch screen, 5,000mAh battery
    • Proteomic Aging Clocks Track Biological Age Reversal in Rentosertib Trial – Unite.AI
    • Onimusha: Way of the Sword has already sold over 1 million copies
    • Buddy The Unicorn Kicked Out Of Halloween Horror Nights
    Facebook X (Twitter) Instagram Pinterest YouTube LinkedIn TikTok
    Techy101 –Techy101 –
    • Home
    • Laptops
    • Mobiles
    • Gaming
    • Gadgets
    • Apps
    • AI
    • How To
    • Reviews
    Techy101 –
    Home»Laptops»Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
    Laptops

    Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google

    By RepublisherAugust 4, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Passkeys have been pushed as the safer successor to passwords. It promised protection from phishing, credential reuse, and password leaks. Google even claims that it cannot be copied or accidentally handed to someone else. But it might not be as secure as the company wants it to be.

    Security researchers (Via BleepingComputer) have now found three ways malware can undermine those promises for passkeys synced through Google Password Manager. The techniques, collectively named Pass-ta-key, target Google Password Manager inside Chrome on Windows computers equipped with a Trusted Platform Module. Every attack requires malware to already be running on the victim’s computer.

    The researchers did not break the cryptography behind passkeys. They exploited weaknesses in device trust, account recovery, onboarding, and how services verify that the user actually unlocked their device.

    I can log into my Google account on Windows by using a passkey. Digital Trends

    Malware can impersonate your trusted computer

    The first Pass-ta-key technique lets malware use Chrome’s TPM-backed device identity to request a valid passkey response from Google’s cloud authenticator. It requires no administrator privileges, biometric scan, PIN, device unlock, or interaction from the victim. Google’s service sees the request as coming from a trusted computer and returns the authentication response needed to sign in.

    Websites are supposed to check a flag confirming that the user verified their identity. Unit 42 found that GitHub correctly rejected the attack, while eBay accepted it despite supposedly requiring verification. eBay fixed that gap after the researchers reported it.

    The more advanced Silver Pass-ta-key attack can force Chrome to register a verification key controlled by the attacker. That key is then treated as proof that the victim entered a PIN or used biometrics, allowing account access from another computer after the original device goes offline.

    Digital Trends

    The worst attack steals the keys themselves

    The Golden Pass-ta-key technique targets the master secret used to encrypt every passkey synced through a Google account. Researchers initially found that Chrome exposed this secret in plain text through its internal FIDO logs. Google removed it from the logs following disclosure. However, Unit 42 says the key still temporarily appears inside Chrome’s process memory during device registration or recovery. Malware can extract it and decrypt the victim’s synced passkeys.

    The stolen master key could reportedly expose existing and future passkeys. Unit 42 adds that Google’s current implementation provides no method to rotate or revoke that secret after it has been compromised. Passkeys remain substantially safer against phishing and password leaks. Google’s documentation still accurately describes those advantages. This research shows that malware already inside your computer can attack the infrastructure surrounding the passkey instead.



    Source link

    Break figured future Google Hackers Passkeys pushed Safer synced Ways
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleKynseed Review (Switch eShop) | Nintendo Life
    Next Article How To Get Shiny In Big Walk For Big Makeover Achievement/Trophy
    Republisher
    • Website

    Related Posts

    Mobiles

    Google Translate now works in the background for Android users

    September 7, 2026
    Apps

    I can’t switch from Samsung to the Google ecosystem because of this single app

    September 7, 2026
    Laptops

    AI burned a lifeline job for thousands in a poor African nation and raised another crisis

    September 7, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    PSVR Dolphin Game ‘Jupiter & Mars: Definitive Edition’ Hits Switch This Week

    September 7, 2026

    AMD is apparently gearing up to raise GPU prices right after Nvidia’s steep hike

    August 1, 2026

    LanceDB Vector Database Guide: Features anndPython Demo

    August 1, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Latest Post

    PSVR Dolphin Game ‘Jupiter & Mars: Definitive Edition’ Hits Switch This Week

    September 7, 2026

    AMD is apparently gearing up to raise GPU prices right after Nvidia’s steep hike

    August 1, 2026

    LanceDB Vector Database Guide: Features anndPython Demo

    August 1, 2026
    Recent Posts
    • PSVR Dolphin Game ‘Jupiter & Mars: Definitive Edition’ Hits Switch This Week
    • Get The Entire Metro Series For Under $9 Ahead Of Metro 2039’s Release
    • Hottest Female Fortnite Skins: The 25 Best in Chapter 7 Season 4
    • My Favorite Home Security Reveal at IFA Was AI, but Not How You Think
    • Samsung Galaxy A07s debuts with a 6.7-inch screen, 5,000mAh battery

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest YouTube LinkedIn TikTok
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    • Disclaimer
    © 2026 techy101. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.