39 New Methods That Compromise Passkey Authentication
Researchers have identified 39 methods to compromise passkey authentication, exposing vulnerabilities in the infrastructure and user interfaces involved.
Intelligence analysis by Qwen 2.5 (3B)

Security researchers have uncovered 39 new methods to compromise passkey authentication, highlighting vulnerabilities in the web application, browser, and user interfaces.
Imagine you have a special code to log in to your favorite website. Researchers found 39 ways that bad guys could trick you into giving them that code. It's like having a secret door, but someone figured out how to open it from the outside.
Analysis
{"heading_1":"The Cryptography Distinction","paragraph_1":"Some of the most consequential attacks do not steal an existing passkey at all. They simply create another one. Published techniques include shadow passkeys, enrollment vishing, attacker phone enrollment, attacker controlled passkey registration, help desk takeover, temporary credential abuse, SIM based recovery, reverse vishing, and migration pretext attacks.","paragraph_2":"Consider what happens when an attacker gains enough control over the enrollment and recovery processes. They can create a new passkey or manipulate existing ones, compromising the security of the authentication process.","paragraph_3":"This highlights the need for enterprises to strengthen their identity assurance measures, including robust enrollment and recovery processes, to prevent such attacks.","heading_2":"Phishing Resistance vs. Deception Resistance","heading_3":"Enrollment and Recovery Create Another Opening"}
Key points
- Researchers have identified 39 new methods to compromise passkey authentication.
- The cryptography inside FIDO2 can remain intact while the account is still compromised.
- Phishing resistance at the cryptographic protocol layer does not guarantee deception resistance across the user interface layers.
- Enrollment and recovery processes can be manipulated to create new passkeys or compromise existing ones.
- Enterprises need to strengthen their identity assurance measures to prevent such attacks.
By understanding these new threats, enterprises can strengthen their security measures and prevent bad guys from tricking people into giving them their special login codes.
If enterprises don't take these new threats seriously, bad guys might be able to trick people into giving them their special login codes, even if the code itself is secure.



