Interestana
Home/News/Pass-ta-key Attack Exploits Google Password Manager Vulnerability
Ars Technica3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Pass-ta-key Attack Exploits Google Password Manager Vulnerability

Pass-ta-key Attack Exploits Google Password Manager Vulnerability

A researcher recently detailed a novel attack surface affecting passkeys, an authentication method designed to be more secure than traditional passwords. This attack, dubbed "Pass-ta-key," which combines "passkey" with "pass the key" and a playful nod to pasta, has generated confusion regarding the true security of this new authentication mechanism. Arie Olshtein, a researcher at Palo Alto Networks, explained in a post last week how the Pass-ta-key attack can extract all passkeys stored within the Google Password Manager (GPM) application for Windows, provided the machine is compromised by malware. This revelation surprised many users who believed passkeys were exclusively stored within the Trusted Platform Module (TPM). The TPM is a secure enclave built into hardened silicon chips, specifically designed to store cryptographic keys and other highly sensitive data on Windows devices. The apparent ability of the Pass-ta-key attack to extract an entire set of passkeys from GPM, despite the perceived security of TPM storage, has led to questions about how this extraction was possible. The research highlights a potential vulnerability in how passkeys are managed and accessed by applications, even when underlying hardware security features are in place. Passkeys represent a significant shift in digital security, aiming to eliminate the need for users to remember and manage complex passwords. They utilize public-key cryptography, where a unique cryptographic key pair is generated for each service or website. One key, the private key, is stored securely on the user's device, while the corresponding public key is registered with the service. Authentication then involves the device using the private key to cryptographically sign a challenge from the service, proving ownership without ever transmitting the private key itself. This method is designed to be resistant to phishing and credential stuffing attacks that plague password-based systems. However, the Pass-ta-key attack suggests that the security of passkeys may depend not only on the secure storage of private keys but also on the security of the applications that manage and interact with these keys. If malware can compromise the application layer, it may be able to intercept or exfiltrate the passkeys before they are fully secured or during their use. The implications of this attack are significant for both end-users and the broader cybersecurity community, necessitating a re-evaluation of passkey implementation and security protocols. It underscores the importance of robust endpoint security and vigilance against malware, even when employing advanced authentication technologies. Further analysis is required to understand the precise mechanisms by which the Pass-ta-key attack bypasses or exploits the intended security of passkey storage and management within the Google Password Manager on Windows.

Original source — read the full reporting at the publisher:

Read on Ars Technica

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next