Can somebody steal a passkey?
New research says malware can reach Google's synced passkeys on Windows. Here is what has to go wrong first, and why a clean computer is the whole defense.
Palo Alto Networks has a threat research group called Unit 42, and on August 3 one of its researchers published a paper describing three new ways to attack passkeys. The researchers nicknamed them Pass-ta-key. The coverage that followed used words like “cracked” and “master key,” and if you met one of those headlines in a Facebook feed you would reasonably conclude that passkeys are finished.
They are not. A passkey is the login that uses your face, fingerprint, or device PIN instead of a password, and I have told you here more than once to turn them on. I still would. The research is real though, and one piece of it is genuinely unpleasant.
Somebody has to already be on your computer
The paper says it in its own disclaimer. All three attacks rely on malware already running on the victim’s device.
The scope is narrower still. This is Google Password Manager, in Chrome, on Windows, on a machine with a TPM security chip. Not an iPhone, not a Mac, not an Android phone.
Which does a lot of work. If someone is running their own software on your computer as you, they can already read the passwords saved in your browser, ride the sessions you are signed into, and watch the bank tab you left open. The passkey did not fail in that scenario. The computer was already compromised.
What the researchers actually did
…
…
To read the full article for free, go to www.freshfromcache.com/can-passkeys-be-stolen/
While you are there, check out The Cache. Your free stash of tech help: short guides to spot scams, phishing, protect your accounts, and fix a slow computer.
If you are new, try Starting Here for the guided tour. Pick the thing that’s bugging you, or the topic you’ve been meaning to get a handle on. These are hand-picked, not just the newest.





Is this why we have 2 step authenticators now?