New Pass-ta-key attack reveals all the things we didn’t know about passkeys
Summary
Ars Technica discusses Pass-ta-key, a malware-assisted attack on passkeys that targets Windows-specific storage in Google's Password Manager. The piece clarifies that FIDO2 specs do not mandate TPM storage; most platforms store passkeys in the cloud or locally, with Windows being the main exception. It argues the attack surface is not novel, but highlights that device compromise still exposes all stored keys, emphasizing the ongoing need for device security even with passwordless authentication.