Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Summary
An in-depth look at novel attack classes against passwordless authentication, focusing on Google's synced passkey ecosystem and the cloud authenticator. It describes Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key attacks that enable account takeover via malware on the victim's device and by bypassing user verification, including potential mitigations for relying parties and onboarding flows. The piece concludes that endpoint compromise remains a critical risk and calls for stronger UV validation and memory-protection measures.