Singapore Herald
Image default
Tech

Hackers Can Steal Google Passkeys Using New Pass-Ta-Key Malware Attack

Google introduced Passkeys and thought that the problem of passwords getting stolen would be curbed. However, it has now been revealed by researchers that they have found a way for malware to hijack passkey-protected accounts through Google Password Manager, highlighting an important exception: passkeys can be very secure, but the software around them still has some vulnerabilities.
Passkeys are a password replacement based on public-key cryptography. Rather than having a secret code, all people get a key pair where the private key never leaves their devices, and the website only ever sees the public key and signed challenges. Because there is nothing reusable to phish or reuse on another site, passkeys are marketed as “phishing resistant” and safer than passwords stored in a browser or password manager.
According to the research cited by Malwarebytes, the malware infected Windows computers and presented three possible attack scenarios to steal Google-synchronised passkeys. Google Password Manager can synchronize passkeys between devices, which is convenient since one doesn’t want to register a new passkey every time someone purchases a new computer. Now, there are three types of “Pass-Ta-Key.” The regular one is where malware on the victim’s computer silently asks Chrome and Google’s cloud to create a valid passkey login, with no biometric or PIN prompt needed.
Another one is the Silver Pass-Ta-Key malware that abuses device re-enrollment to register its own user verification key, then logs in as the victim from the attacker’s machine without physically touching the device. Last is the Golden Pass-Ta-Key, where the malware extracts Google’s security domain secret (the master encryption key), decrypts all synced passkeys, and can reuse them anywhere, even after losing access to the original device.
As for staying safe, the researchers have said that all users should make sure that their systems and software are patched as soon as they can. Apart from that, users have also been advised to use up-to-date real-time anti-malware protection. Last but not least, don’t interact with attachments or links coming from suspicious sources.

Related posts

Nasa Artemis II Launch Live Updates: NASA’s Artemis II Mission Successfully Launches On Historic Moon Journey

Bruce M. Hampton

Big Tech Is Betting Billions On AI And Your Future Could Be Part Of It

Bruce M. Hampton

Moto G77 Power Launched In India, Check Price, Specs, And Release Date

Bruce M. Hampton