Pass-ta-key Attack Exposes Passkey Storage Flaws on Windows
TL;DR. A new attack dubbed Pass-ta-key can extract passkeys stored in Google Password Manager for Windows, challenging common assumptions about passkey security and storage. - Pass-ta-key exploits how Google Password Manager stores passkeys locally on Windows machines, bypassing the trusted platform module. - FIDO 2 specifications do not mandate TPM storage, allowing local storage for easier syncing across devices. - This research clarifies why passkey apps treat Windows differently, impacting user security perceptions.
- Arie Olshtein's Pass-ta-key attack demonstrates extraction of passkeys from Google Password Manager on Windows.
- The attack targets local storage of passkeys on Windows machines, not the trusted platform module (TPM).
- FIDO 2 specifications permit local passkey storage, contradicting common belief that TPMs are mandatory.
- Local storage facilitates passkey syncing across devices, a trade-off for widespread adoption.
- Microsoft allows TPM storage for enterprises, but most platforms use local storage for consumers.