Culture

Palo Alto Networks exposes malware threats to passkeys

A new Palo Alto Networks report reveals how malware can bypass enterprise passkey protections, warning organizations that passwordless security fails once an endpoint is compromised.

Computerworld AI5 days agoCulture
Image: Computerworld AI

Palo Alto Networks' Unit 42 research division has disclosed a series of security bypasses, collectively named Pass-ta-key, that allow malware on a compromised device to hijack accounts protected by passkeys. The researchers outlined three distinct attack methods. The standard Pass-ta-key attack allows threat actors to take over accounts secured by Google-synced passkeys without needing privilege escalation, device unlocking, or any user interaction.

The second method, dubbed Silver Pass-ta-key, tricks Google Cloud Authenticator into registering a false biometric unlock, giving attackers complete account access without needing the victim's physical device during authentication. The third variant, Golden Pass-ta-key, enables attackers to extract all of a target's synced passkeys in bulk, allowing them to be sold or traded on credential black markets.

Security experts emphasize that these attacks do not break the underlying cryptography of passkeys. Instead, they exploit weak implementation procedures, such as onboarding flows, recovery mechanisms, and unvalidated trust signals. According to Justin Greis, CEO of Acceligence, the issue stems from the fact that "implementations haven't caught up" to the actual standards. Many real-world services currently accept logins without validating the user-verified flag in the authentication response, effectively turning multi-factor authentication back into a single factor.

To defend against these post-compromise threats, analysts urge organizations to enforce strict server-side user verification. Experts recommend using hardware-bound security keys, such as YubiKeys, for highly sensitive and privileged accounts, as physical keys cannot be harvested in bulk. Additionally, security teams are advised to treat browser-synced passkeys as an unacceptable risk for high-level access and to establish clear policies distinguishing between synced and device-bound credentials.

This is our own summary of reporting by Computerworld AI

More in Culture