Pass-ta-key Takes Advantage Of Some Assumptions When Grabbing Your Windows Passkeys
Definitely Not Blessed By His Noodly Appendage
Passkeys are a somewhat new attempt to find something to replace passwords, session cookies, MFA and all the other ways we have to use on the internet to verify both that we are indeed who we say we are and that we’re authorized to access the resource being queried. If you’re not quite clear on what passkeys are, Ars Technica posted a great primer a few years back. In brief they are paired cryptographic keys, one public on the site you created an account and one private which is located on the specific device you used when creating the key. If the pairing checks out you get to log in without needing to enter a password or other verification method.
The assumption most had was that those local passkeys were stored securely on the local system, be it TPM chips, secure enclaves or whatever the OS calls it’s protected area. The problem is that storing it in such a way means that you can’t replicate your passkeys to another device. If you can only use a passkey on one device without creating it again from scratch then people are unlikely to adopt it because it would be a bit of a PITA. The FIDO Alliance decided that the OS on the local device would protect attackers from cloning passkeys on compromised machines and they were right, apart from Windows, and therefore storing passkeys in these secure locations would be optional and not required.
Windows tends to run everything with the same privileges as the logged in user, other OSes tend towards least access and that is where Pass-ta-key comes in. Pass-ta-key is the oddly named vulnerability discovered by a researcher at security firm Palo Alto Networks. They proved that if a Windows machine is compromised by malware, an attacker could steal any and all local passkeys stored in the Google Password Manager app. It is unclear if other password manager apps suffer the same vulnerability but it is not impossible that they could also be vulnerable to Pass-to-key.
The attacker has several ways to take advantage of Pass-ta-key, such as making an infected machine look like an iPhone, accessing a user’s Google Password Manager and triggering the convenient copy mechanism to migrate your passkeys to a new device to get a copy of all your passkeys. While this means Pass-ta-key is not exactly the novel attack it was billed as but it is still dangerous. You can get more details from Ars Technica if you want.
Arie Olshtein, a researcher at security firm Palo Alto Networks, described in a post last week how Pass-ta-key could obtain all passkeys stored in the Google Password Manager app (GPM) for Windows when it’s running on a machine infected with malware.
More Tech News From Around The Web
- Chrome adopts what may be the best protection yet against account takeovers @ Ars Technica
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days @ Bleeping Computer
- Sandworm hackers target IT pros with trojanized WireGuard VPN client @ Bleeping Computer
- A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices On a Call @ Slashdot
- Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list @ The Register
- Linus Torvalds says AI has made ‘huge’ Linux kernel updates the new normal @ The Register
- First Rival Android App Store Arrives In the US Play Store @ Slashdot
- The PC OS That Would Have Blown Your Mind Back In 1984 @ Hackaday
- Giveaway: Win an Ocypus Sigma L36 PRO 360mm AIO and Sigma F36 ARGB Fan @ TweakTown


