Synced passkey security issues could allow account takeover

Synced passkey security issues could allow account takeover

The attacks can misuse trusted workflows to take over passkey-protected accounts, but the attacker must have first breached defenses and planted malware; analysts say the issue is flaws in supporting processes.

Excerpt from: Passkey security issues could allow account takeover

Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.

J. Wolfgang Goerlich, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.

“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”

Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”

Read the full article: https://www.csoonline.com/article/4205751/report-passkey-security-issues-could-allow-account-takeover.html

Wolf’s Additional Thoughts

In 2021-2023, in presentations such as Street Cred and Mistaken Identity, I warned of this exact type of attack. Credential theft and re-use is only possible when the authenticator can be copied, cloned, and replayed. That’s exactly what synced passkeys allow. It’s frustrating but entirely unsurprising to see this happen. If you must shared passkeys, use enterprise credential managers like 1Password and others.


This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.

Posted by