Pass-ta-key attack: passkeys aren't malware-proof — but the threat isn't new
Researcher Arie Olshtein of Palo Alto Networks described the Pass-ta-key attack, which can steal all passkeys stored in Google Password Manager for Windows on a malware-infected machine. However, security experts stress that the technique is neither novel nor unique to passkeys — any data on an infected system is at risk. The confusion stems from a widespread but mistaken belief that passkeys are inherently immune to malware theft.
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!