Report: Passkey security issues could allow account takeover

Chronological Source Flow
Back

AI Fusion Summary

A Palo Alto Networks Unit 42 report reveals that attackers can bypass passkey protections to achieve account takeover. Analysts emphasize that these attacks require a prior successful intrusion. The vulnerabilities do not stem from the underlying cryptography of passkeys but from weaknesses in surrounding procedures. Specifically, researchers exploited gaps in onboarding flows, recovery mechanisms, and unvalidated trust signals. Acceligence CEO Justin Greis noted that the issues reside in the seams around the technology's implementation.
Community Comments
Loading updates...
0