TECH FLOW Svět Androida
← Back to the stream
bleepingcomputer.com · picked by Petr Mišák · 57d ago

New malware can extract passkeys from Google Password Manager

Source preview: New malware can extract passkeys from Google Password Manager
AI summary

Security researchers from Palo Alto Networks' Unit 42 discovered three attacks called Pass-ta-key that allow malware on Windows devices to abuse synced passkeys from Google Password Manager and take over user accounts. The attacks require malware to already be running on the computer and exploit weaknesses in how Chrome and Google's cloud authenticator handle device trust, onboarding, recovery, and synced credentials.

The summary is written by AI from the source; it isn’t the newsroom’s opinion. For details, read the source.

16 people have already opened the source

Tip author’s note

Malware can access all your passwords in Google Password Manager and breach most of your services. If Google remains silent on this, I recommend switching to Bitwarden or a similar solution and deleting passwords from Google Password Manager.

AI questions & answers
What are passkeys and why are they considered more secure than passwords?

Passkeys are a passwordless authentication method based on cryptographic keys stored on a user's device used to sign in to online accounts. Unlike passwords, passkeys cannot be guessed, reused, or easily stolen through phishing, and they enable authentication using a PIN or biometrics such as fingerprints or facial recognition.

How do the three Pass-ta-key attack variants differ from each other?

The basic Pass-ta-key allows unprivileged malware to impersonate a trusted device and obtain an authentication response; Silver Pass-ta-key enables an attacker to register their own user-verification key with Google's authenticator; Golden Pass-ta-key is the most severe and allows extraction of the master key that encrypts all synced passkeys from Google Password Manager.

What mitigations do security researchers recommend?

Researchers recommend that websites require and properly validate user verification, credential managers should validate newly registered device keys and harden recovery processes, and system should prevent master keys from becoming accessible in browser memory.

Questions and answers are written by AI about the topic, not taken from the source; they aren’t the newsroom’s opinion.
Related from the stream
Mentions