Technology News

Passkey Attacks Show How to Bypass Phishing‑Resistant MFA

Three research teams reveal methods to defeat passkey protections

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.

Passkeys are touted as next‑generation credentials that replace passwords and resist phishing.

Recent research shows that attackers can defeat passkey protections by reusing signed authentication material that Windows exposes.

The first technique leverages a Windows feature that signs authentication requests, allowing attackers to replay the signed data and impersonate a legitimate user.

The second attack exploits the cloud‑synced passkey system that many devices use, where malware already present on the victim’s machine can extract and reuse the passkey data stored in the cloud.

The third method, described by researchers, uses a compromised authentication token from a malicious application that has been granted the same permissions as a passkey.

Together, the findings demonstrate that passkeys do not automatically provide immunity against phishing‑style attacks.

The researchers stressed that the cryptographic primitives remain sound; the vulnerability lies in how the credentials are managed and exposed by the operating system and cloud services.

Security teams are advised to review the handling of signed authentication material and to limit the scope of cloud‑synced credentials to reduce the attack surface.

Passkey Attacks Show How to Bypass Phishing‑Resistant MFA

Passkeys are touted as next‑generation credentials that replace password…

Passkeys are touted as next‑generation credentials that replace password…

Passkeys are touted as next‑generation credentials that replace passwords and resist phishing.

Recent research shows that attackers can defeat passkey protections by reusing signed authentication material that Windows exposes.

The first technique leverages a Windows feature that signs authenticatio…

The first technique leverages a Windows feature that signs authenticatio…

The first technique leverages a Windows feature that signs authentication requests, allowing attackers to replay the signed data and impersonate a legitimate user.

The second attack exploits the cloud‑synced passkey system that many devices use, where malware already present on the victim’s machine can extract and reuse the passkey data stored in the cloud.

The third method, described by researchers, uses a compromised authentic…

The third method, described by researchers, uses a compromised authentic…

The third method, described by researchers, uses a compromised authentication token from a malicious application that has been granted the same permissions as a passkey.

Together, the findings demonstrate that passkeys do not automatically provide immunity against phishing‑style attacks.

The researchers stressed that the cryptographic primitives remain sound;…

The researchers stressed that the cryptographic primitives remain sound;…

The researchers stressed that the cryptographic primitives remain sound; the vulnerability lies in how the credentials are managed and exposed by the operating system and cloud services.

Security teams are advised to review the handling of signed authentication material and to limit the scope of cloud‑synced credentials to reduce the attack surface.