News

Enterprise Passkey Security Under Threat: Malware Exploits Implementation Flaws

4 min read Editorial

A recent report from Palo Alto Networks Unit 42 has raised significant concerns in the cybersecurity community, revealing that malware can bypass passkey protections in enterprise environments. The findings highlight critical vulnerabilities in the implementation and surrounding workflows of passkey systems, rather than the underlying cryptography itself.

The report details three categories of attacks, collectively dubbed “Pass-ta-key.” These attacks exploit weaknesses in onboarding, recovery, and device trust mechanisms, allowing attackers to compromise accounts protected by passkeys. This development is particularly concerning given the widespread adoption of passkeys as a replacement for passwords in enterprise settings.

Understanding the Pass-ta-key Attack Vectors

The Palo Alto Networks report outlines three distinct attack vectors that demonstrate how malware can misuse passkey workflows:

Advertisement
  • Pass-ta-key: This attack involves an attacker taking over an account protected by a Google-synced passkey using malware running on the victim’s device. Notably, this does not require privilege escalation, device unlock, or user interaction, making it a stealthy threat.
  • Silver Pass-ta-key: In this scenario, an attacker tricks the Google Cloud Authenticator into believing the victim has unlocked the device with biometrics. This leads to full account takeover without the attacker needing to use the victim’s device during authentication.
  • Golden Pass-ta-key: This attack allows an attacker to extract all synced passkeys in a form that can be shared or sold on the credential black market, posing a long-term risk to account security.
A close-up of a hand holding a smartphone displaying a passkey authentication screen, with a faint malware icon hovering
Illustration of passkey authentication on a mobile device, reflecting the potential for malware interference.

Implementation Flaws, Not Cryptographic Failures

Experts emphasize that these attacks do not break the underlying cryptography of passkeys. Instead, they exploit the “seams” around it, such as onboarding flows, recovery mechanisms, and trust signals that were not being validated. This distinction is crucial for understanding where the actual risk lies.

Justin Greis, CEO of consulting firm Acceligence, stated, “The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated.” This insight helps security teams focus on the right areas for improvement.

Brian Levine, executive director of FormerGov, advised organizations to require user verification and validate the user-verified flag in authentication responses. He noted that researchers found real-world services accepting logins without this validation, which effectively reduces a multi-factor login back to a single factor, undermining the security benefits of passkeys.

The Role of Prior Penetration

Frank Dickson, group VP for security at IDC, stressed that these attacks assume a prior successful penetration of the environment. “This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house,” he said. “The real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean.”

While the assumption of prior penetration might seem limiting, it is a realistic scenario given that such penetration can result from a single privileged user clicking a malicious link or attachment. This highlights the importance of comprehensive endpoint security and user training.

A network diagram showing interconnected devices with some nodes highlighted in red, symbolizing compromised endpoints i
Diagram illustrating potential points of compromise in an enterprise network, relevant to the passkey security discussion.

Recommendations for CISOs

Or Finkelstein, head of marketing at Secret Double Octopus, agreed that CISOs have become complacent about how systems support passkeys. He advised looking at how user verification is enforced, how enrollment and recovery work, and having clear policies on whether credentials are synced or device-bound.

J. Wolfgang Goerlich, a cybersecurity consultant, pointed out that synced passkeys reintroduced the risk of credential theft, which the original FIDO2 specification aimed to eliminate by binding private keys to physical authenticators. He recommended requiring device-bound authenticators for all privileged and sensitive access.

Goerlich also warned that “a passwordless system is exactly as strong as the flow that re-establishes it,” urging security teams to model, monitor, and rehearse responses to re-enrollment attacks. This proactive approach can help mitigate the risks associated with passkey implementation.

What This Means for Enterprise Security

The Palo Alto Networks report serves as a stark reminder that while passkeys offer significant security benefits, their implementation and surrounding processes are critical. Enterprises must ensure that user verification is enforced, device trust is properly validated, and recovery mechanisms are secure.

By addressing these implementation flaws, organizations can better protect their accounts and maintain the integrity of their passwordless strategies. Security teams should prioritize regular audits and updates to their passkey policies to stay ahead of emerging threats.

How to Get It

For organizations looking to enhance their passkey security, the first step is to review current implementation practices against the recommendations outlined by security experts. This includes enforcing user verification, validating trust signals, and establishing clear policies for credential synchronization.

Additionally, investing in comprehensive endpoint security solutions and user training programs can help prevent the initial penetration that these attacks rely on. By taking a holistic approach to passkey security, enterprises can mitigate the risks highlighted in the Palo Alto Networks report.

Source: Computerworld

Over to you: How is your organization addressing the implementation challenges of passkeys in light of these findings?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement