New Pass-ta-key attack exposes hidden passkey vulnerabilities

▼ Summary
– A researcher described a “novel attack surface” in passkeys, but the attacks are neither novel nor unique to passkeys, causing confusion among users and professionals.
– The Pass-ta-key attack, outlined by Arie Olshtein of Palo Alto Networks, can extract all passkeys from Google Password Manager for Windows on malware-infected machines.
– Many believed passkeys are stored exclusively in the TPM, but FIDO 2 specifications do not mandate such dedicated hardware storage.
– Most platforms and third-party passkey managers do not store passkeys in dedicated hardware like TPMs or secure enclaves.
– Microsoft is a rare exception, offering optional TPM storage for passkeys, primarily recommended for enterprises rather than consumers.
A security researcher’s recent disclosure has sparked fresh debate about the safety of passkeys, the increasingly popular authentication method touted as a more robust replacement for traditional passwords. The findings, however, are being met with skepticism from experts who argue the so-called novel threat is neither groundbreaking nor exclusive to this technology. The confusion surrounding the research could leave everyday users and IT professionals questioning whether they should trust this newer login mechanism.
The attack, dubbed Pass-ta-key, a playful twist on “pass the key” and a nod to the Italian dish, was detailed last week by Arie Olshtein, a researcher with Palo Alto Networks. Olshtein demonstrated how the technique could swipe every passkey stored in the Google Password Manager (GPM) application for Windows, provided the machine had already been compromised with malware.
The revelation caught many off guard, largely because of a widespread assumption that passkeys are locked away inside the Trusted Platform Module (TPM). This hardened silicon enclave is designed to safeguard cryptographic keys and other sensitive data on Windows devices. If that were the case, observers wondered, how could Pass-ta-key manage to pull the entire vault of credentials from the app?
The reality is more nuanced. The FIDO 2 specifications, overseen by the industry consortium FIDO Alliance, do not require passkeys to reside in a TPM or any comparable dedicated hardware component. These secure elements go by various names depending on the platform, including secure enclaves, trusted execution environments, and StrongBoxes. In practice, the vast majority of platforms and third-party password managers skip this hardware entirely when storing passkeys. The notable exception is Microsoft, which offers users the option to keep passkeys inside the Windows TPM, though this choice is primarily pitched at enterprise customers rather than the general public.
(Source: Ars Technica)




