Pass-ta-key Attack: New Passkey Vulnerabilities Revealed

Passkeys stored in applications like the Google Password Manager app for Windows can be extracted by malware, according to security firm Palo Alto Networks. While recent research sparked user confusion regarding whether passkeys are exclusively protected inside hardware-based trusted platform modules, industry specifications managed by the FIDO Alliance do not mandate dedicated hardware storage for passkeys across most platforms.

Understanding the Pass-ta-key Attack Method Against Google Password Manager

A recent security post by Palo Alto Networks researcher Arie Olshtein outlined an attack method called Pass-ta-key. According to the research, this technique targets Windows machines infected with malware to obtain all passkeys stored within the Google Password Manager app.

The research generated confusion among end users and security professionals. Many believed that passkeys are exclusively stored inside the trusted platform manager, which is a secure enclave located on a hardened silicon chip designed to protect sensitive cryptographic keys on Windows devices.

Did you know?

The name “Pass-ta-key” combines the word passkey with the phrase “pass the key,” alongside a linguistic nod to a plate of pasta.

FIDO Alliance Specifications and Local Storage Realities

The extraction of passkeys from software managers comes down to industry standards. According to the FIDO Alliance, the FIDO 2 specifications do not mandate that passkeys reside within trusted platform managers or any other dedicated hardware secure enclaves.

Most software platforms and third-party credential managers store passkeys outside of dedicated hardware components. Microsoft stands as the primary industry holdout, offering users the specific option to store passkeys directly within the Windows TPM, a recommendation mostly targeted at enterprise environments rather than everyday consumers.

Pro Tip for Security Assessment

When evaluating credential storage, verify whether your software provider relies on software-based vaults or dedicated hardware enclaves like a TPM or StrongBox.

Frequently Asked Questions

Are passkeys always stored in hardware?

No. According to the FIDO Alliance specifications, passkeys are not required to be kept in a trusted platform manager or other dedicated hardware.

What is the Pass-ta-key attack?

Described by Palo Alto Networks researcher Arie Olshtein, Pass-ta-key is a method where malware on an infected Windows machine can obtain passkeys stored inside the Google Password Manager app.

Which platform primarily stores passkeys in a TPM?

Microsoft offers users the option to store passkeys in the Windows TPM, a setting mostly recommended for enterprise deployments.

Stay Updated on Cybersecurity Trends

Explore more of our cybersecurity articles or drop a comment below to share your thoughts on authentication standards.

Google Chrome Passkeys Under Attack: What You Need to Know!

Leave a Comment