Pass-ta-key Takes Advantage Of Some Assumptions When Grabbing Your Windows Passkeys

Source: Ars Technica Pass-ta-key Takes Advantage Of Some Assumptions When Grabbing Your Windows Passkeys

Definitely Not Blessed By His Noodly Appendage

Passkeys are a somewhat new attempt to find something to replace passwords, session cookies, MFA and all the other ways we have to use on the internet to verify both that we are indeed who we say we are and that we’re authorized to access the resource being queried.  If you’re not quite clear on what passkeys are, Ars Technica posted a great primer a few years back.   In brief they are paired cryptographic keys, one public on the site you created an account and one private which is located on the specific device you used when creating the key.  If the pairing checks out you get to log in without needing to enter a password or other verification method.

The assumption most had was that those local passkeys were stored securely on the local system, be it TPM chips, secure enclaves or whatever the OS calls it’s protected area.  The problem is that storing it in such a way means that you can’t replicate your passkeys to another device. If you can only use a passkey on one device without creating it again from scratch then people are unlikely to adopt it because it would be a bit of a PITA.  The FIDO Alliance decided that the OS on the local device would protect attackers from cloning passkeys on compromised machines and they were right, apart from Windows, and therefore storing passkeys in these secure locations would be optional and not required.

Windows tends to run everything with the same privileges as the logged in user, other OSes tend towards least access and that is where Pass-ta-key comes in.  Pass-ta-key is the oddly named vulnerability discovered by a researcher at security firm Palo Alto Networks.  They proved that if a Windows machine is compromised by malware, an attacker could steal any and all local passkeys stored in the Google Password Manager app.  It is unclear if other password manager apps suffer the same vulnerability but it is not impossible that they could also be vulnerable to Pass-to-key.  

The attacker has several ways to take advantage of Pass-ta-key, such as making an infected machine look like an iPhone, accessing a user’s Google Password Manager and triggering the convenient copy mechanism to migrate your passkeys to a new device to get a copy of all your passkeys.   While this means Pass-ta-key is not exactly the novel attack it was billed as but it is still dangerous.  You can get more details from Ars Technica if you want.

Arie Olshtein, a researcher at security firm Palo Alto Networks, described in a post last week how Pass-ta-key could obtain all passkeys stored in the Google Password Manager app (GPM) for Windows when it’s running on a machine infected with malware.

Video News

About The Author

Jeremy Hellstrom

Call it K7M.com, AMDMB.com, or PC Perspective, Jeremy has been hanging out and then working with the gang here for years. Apart from the front page you might find him on the BOINC Forums or possibly the Fraggin' Frogs if he has the time.

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Podcasts

Archive & Timeline

Previous 12 months
Explore: All The Years!