Interestana
Home/News/New Passkey Attacks Bypass Phishing-Resistant MFA
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

New Passkey Attacks Bypass Phishing-Resistant MFA

New Passkey Attacks Bypass Phishing-Resistant MFA

Three distinct research initiatives presented last week have detailed novel methods for circumventing passkey security, a technology designed to replace passwords and offer phishing resistance. These attacks do not involve breaking the underlying cryptography but instead exploit vulnerabilities in how passkeys are implemented and managed. One method involves reusing signed authentication material that Windows had exposed, effectively tricking systems into believing a legitimate authentication had occurred. This attack leverages the trust placed in signed data by the operating system, allowing an attacker to impersonate a user without needing the user's credentials or direct interaction.

Another demonstrated attack abuses cloud-synced passkey systems. This technique relies on malware already present on a victim's machine to access and exfiltrate passkey data that is synchronized across devices via cloud services. Once the synchronized passkey material is obtained, an attacker can use it to authenticate to services that the victim uses, bypassing the need for the user's consent or knowledge. This highlights a significant risk associated with the convenience of cloud synchronization, as a compromise on one device can lead to widespread compromise across all synced accounts.

A third attack vector focuses on bypassing phishing-resistant multi-factor authentication (MFA) by exploiting the passkey mechanism itself. While passkeys are designed to be phishing-resistant, these new methods find ways around this protection. The researchers indicated that these attacks are not theoretical and have been demonstrated in practice, posing a tangible threat to users relying on passkeys for secure authentication. The findings underscore the ongoing challenge of securing digital identities, even with advanced authentication methods.

These revelations come at a time when passkeys are being increasingly adopted by major technology companies, including Apple, Google, and Microsoft, as a successor to passwords. The goal of passkeys is to provide a more secure and user-friendly authentication experience by using public-key cryptography and eliminating the need for users to remember complex passwords or be vulnerable to phishing attempts that trick them into revealing credentials. The research, however, suggests that the ecosystem is not yet entirely impervious to sophisticated attack strategies. The researchers have not yet publicly disclosed the full technical details of their findings to allow for mitigation efforts before widespread exploitation.

The implications of these attacks are significant for the future of authentication. While passkeys offer substantial security improvements over traditional passwords, these new findings necessitate a re-evaluation of the security architecture surrounding them. The attacks highlight the importance of securing the entire authentication chain, including operating system integrations, cloud synchronization mechanisms, and the endpoint devices themselves. Further research and development are expected to focus on patching these newly identified vulnerabilities and strengthening the overall security posture of passkey implementations.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next