Forgot your password?
typodupeerror

Submission Summary: 0 pending, 1 declined, 0 accepted (1 total, 0.00% accepted)

Submission + - 39 New Passkey Authentication Compromises + Bad UI = Passwords on Paper? (bleepingcomputer.com)

eqteam writes: We all saw this coming: "There are now at least 39 publicly documented methods, attack paths, research techniques, and exploitation scenarios involving passkeys and the infrastructure around them. Many already have working proof of concept tools or published research showing exactly how the techniques can be executed. Some are already appearing in real world attack patterns."

According to the above-quoted (sponsored) Bleeping Computer article: "A modern passkey authentication ceremony crosses an extraordinary number of trust boundaries. It can involve the web application, browser, operating system, password manager, cloud synchronization service, mobile device, Bluetooth transport, account recovery system, enrollment process, help desk, and ultimately the human being approving the authentication.

Researchers are attacking almost every one of those layers. Published techniques now include assertion mining, assertion replay, circuit breaker attacks, assertion phishing, browser hooking, assertion capture, challenge injection, detour replay, user verification manipulation, and user presence manipulation."

Furthermore, intrepid users who enable Passkey authentication end up turning it off because they can't figure out how to make it work across devices (thanks to confusing implementations that aren't consistent across platforms and operating systems). Additionally, Passkey adoption is pretty slow, with only 872 websites implementing Passkey authentication per this research paper titled The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web presented at the 2026 USENIX Security Symposium.

With 2FA being deprecated by many large orgs and biometric authentication options proving to look like Swiss cheese, what are we to do besides going back to writing down passwords on paper while we wait for the technology to get better?

Slashdot Top Deals

If the code and the comments disagree, then both are probably wrong. -- Norm Schryer

Working...