HeadlinesBriefing favicon HeadlinesBriefing.com

Pass‑ta‑key attack exposes Windows passkey storage gaps

Ars Technica •
×

A researcher at Palo Alto Networks, Arie Olshtein, described a Pass‑ta‑key attack that can harvest all passkeys stored in the Google Password Manager app for Windows when the machine is infected with malware. The technique exploits the fact that passkeys on Windows are kept in encrypted cloud blobs rather than the TPM, while other platforms store them locally. The FIDO Alliance specifications do not require TPM storage, and only Microsoft offers users the option to keep passkeys in the Windows TPM, mainly for enterprises. Because Windows apps run with full user privileges and sandboxing only protects one direction, malware can read data from sandboxed apps, a problem not seen on macOS, iOS, or Android. Consequently, third‑party managers like 1Password, Dashlane, and GPM for Windows store passkeys in the cloud, retrieving a TPM key only at authentication time. The attack is not novel—any compromised device logged into a sensitive account is vulnerable—but it highlights the unique risks of Windows passkey storage. Dan Goodin, Senior Security Editor at Ars Technica, notes that passkeys are meant to eliminate shared secrets, not to survive device compromise. Once a Windows device is infected, all stored data, including passkeys, can be stolen.

Key entities include Google, Microsoft, FIDO Alliance, 1Password, Dashlane, Arie Olshtein, and Dan Goodin (San Francisco‑based).