None
DE
New Pass-ta-key attack reveals all the things we didn't know about passkeys
[]
Ars Technica
Last week a researcher outlined what he said was a “novel attack surface” in passkeys, the new authentication paradigm that offers a more secure alternative over password-based methods.
In fact, the attacks demonstrated in the post are neither novel nor unique to passkeys.
If passkeys are stored in the TPM, then how was Pass-ta-key able to extract the entire set of passkeys stored by the app, they wanted to know.
In fact, most platforms and third-party software for managing passkeys do not store passkeys in such dedicated hardware.
Virtually the lone holdout is Microsoft, which gives users the option to store passkeys in the Windows TPM.