Unit 42 discloses three novel attack classes against Google's synced passkey ecosystem on Windows TPM devices, collectively nicknamed 'Pass-ta-key.' All three require pre-existing unprivileged malware on the victim's endpoint. The Pass-ta-key attack silently signs cloud authenticator requests using the extracted TPM-backed device identity key. The Silver Pass-ta-key attack exploits Chrome's deferred UV key onboarding to register an attacker-controlled verification key, enabling persistent remote access without the victim's device. The Golden Pass-ta-key attack extracts the Security Domain Secret from Chrome's process memory during forced re-onboarding, enabling decryption of all synced passkeys. Key gaps include lack of UV flag validation by relying parties, absence of attestation verification for newly registered UV keys, and exposure of the SDS to the client environment.
Passwordless Auth
1 post
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication