Close Menu
Techy101 –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    New iPhone 18 Pro price rises perhaps not as bad as some feared

    September 9, 2026

    Leaked Persona 6 Achievements Reveal Setting and Key Story Details

    September 9, 2026

    The Coolest Thing I Saw at IFA 2026: The Coolest, Quietest, Thinnest Laptop Concept

    September 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • New iPhone 18 Pro price rises perhaps not as bad as some feared
    • Leaked Persona 6 Achievements Reveal Setting and Key Story Details
    • The Coolest Thing I Saw at IFA 2026: The Coolest, Quietest, Thinnest Laptop Concept
    • Arm unveils CSS for Mobile 2 with Mali G2-Ultra NX GPU, C2-Ultra and Pro CPU cores
    • PowerWash Simulator devs FuturLab laid off staff and cancelled an unrevealed project earlier this year, but certainly kept quiet about it
    • ‘Battlestar Galactica’ Meets ‘Hunger Games’ in 100-Episode Action Thriller That’s Free on Streaming
    • Jeep’s Recon Isn’t An Electric Wrangler, And You’ll Know It Behind The Wheel
    • Girl Scouts Unleash Treats for Dogs and Allergy-Safe Cookies for Humans
    Facebook X (Twitter) Instagram Pinterest YouTube LinkedIn TikTok
    Techy101 –Techy101 –
    • Home
    • Laptops
    • Mobiles
    • Gaming
    • Gadgets
    • Apps
    • AI
    • How To
    • Reviews
    Techy101 –
    Home»Laptops»Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
    Laptops

    Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google

    By RepublisherAugust 4, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Passkeys have been pushed as the safer successor to passwords. It promised protection from phishing, credential reuse, and password leaks. Google even claims that it cannot be copied or accidentally handed to someone else. But it might not be as secure as the company wants it to be.

    Security researchers (Via BleepingComputer) have now found three ways malware can undermine those promises for passkeys synced through Google Password Manager. The techniques, collectively named Pass-ta-key, target Google Password Manager inside Chrome on Windows computers equipped with a Trusted Platform Module. Every attack requires malware to already be running on the victim’s computer.

    The researchers did not break the cryptography behind passkeys. They exploited weaknesses in device trust, account recovery, onboarding, and how services verify that the user actually unlocked their device.

    I can log into my Google account on Windows by using a passkey. Digital Trends

    Malware can impersonate your trusted computer

    The first Pass-ta-key technique lets malware use Chrome’s TPM-backed device identity to request a valid passkey response from Google’s cloud authenticator. It requires no administrator privileges, biometric scan, PIN, device unlock, or interaction from the victim. Google’s service sees the request as coming from a trusted computer and returns the authentication response needed to sign in.

    Websites are supposed to check a flag confirming that the user verified their identity. Unit 42 found that GitHub correctly rejected the attack, while eBay accepted it despite supposedly requiring verification. eBay fixed that gap after the researchers reported it.

    The more advanced Silver Pass-ta-key attack can force Chrome to register a verification key controlled by the attacker. That key is then treated as proof that the victim entered a PIN or used biometrics, allowing account access from another computer after the original device goes offline.

    Digital Trends

    The worst attack steals the keys themselves

    The Golden Pass-ta-key technique targets the master secret used to encrypt every passkey synced through a Google account. Researchers initially found that Chrome exposed this secret in plain text through its internal FIDO logs. Google removed it from the logs following disclosure. However, Unit 42 says the key still temporarily appears inside Chrome’s process memory during device registration or recovery. Malware can extract it and decrypt the victim’s synced passkeys.

    The stolen master key could reportedly expose existing and future passkeys. Unit 42 adds that Google’s current implementation provides no method to rotate or revoke that secret after it has been compromised. Passkeys remain substantially safer against phishing and password leaks. Google’s documentation still accurately describes those advantages. This research shows that malware already inside your computer can attack the infrastructure surrounding the passkey instead.



    Source link

    Break figured future Google Hackers Passkeys pushed Safer synced Ways
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleKynseed Review (Switch eShop) | Nintendo Life
    Next Article How To Get Shiny In Big Walk For Big Makeover Achievement/Trophy
    Republisher
    • Website

    Related Posts

    Apps

    Google Chat is closing a major gap with this overdue messaging update

    September 9, 2026
    Laptops

    Suunto Run 2 Review – Trusted Reviews

    September 9, 2026
    Reviews

    Why I’m a standing desk convert: 6 ways it leveled up my life

    September 9, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    New iPhone 18 Pro price rises perhaps not as bad as some feared

    September 9, 2026

    AMD is apparently gearing up to raise GPU prices right after Nvidia’s steep hike

    August 1, 2026

    LanceDB Vector Database Guide: Features anndPython Demo

    August 1, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Latest Post

    New iPhone 18 Pro price rises perhaps not as bad as some feared

    September 9, 2026

    AMD is apparently gearing up to raise GPU prices right after Nvidia’s steep hike

    August 1, 2026

    LanceDB Vector Database Guide: Features anndPython Demo

    August 1, 2026
    Recent Posts
    • New iPhone 18 Pro price rises perhaps not as bad as some feared
    • Leaked Persona 6 Achievements Reveal Setting and Key Story Details
    • The Coolest Thing I Saw at IFA 2026: The Coolest, Quietest, Thinnest Laptop Concept
    • Arm unveils CSS for Mobile 2 with Mali G2-Ultra NX GPU, C2-Ultra and Pro CPU cores
    • PowerWash Simulator devs FuturLab laid off staff and cancelled an unrevealed project earlier this year, but certainly kept quiet about it

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest YouTube LinkedIn TikTok
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    • Disclaimer
    © 2026 techy101. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.