Pass-ta-key Attack Exposes Passkey Storage Flaws on Windows

TL;DR. A new attack dubbed Pass-ta-key can extract passkeys stored in Google Password Manager for Windows, challenging common assumptions about passkey security and storage. - Pass-ta-key exploits how Google Password Manager stores passkeys locally on Windows machines, bypassing the trusted platform module. - FIDO 2 specifications do not mandate TPM storage, allowing local storage for easier syncing across devices. - This research clarifies why passkey apps treat Windows differently, impacting user security perceptions.

Sources

Back to QLANKR News