arstechnica.com 8/11/2026, 11:57:37 AM · external

Here's why the new Pass-ta-key attack is mostly a nothingburger

Here's why the new Pass-ta-key attack is mostly a nothingburger
CyberSIXT Evidence Panel Source marked as original reporting

A recent study introduced a supposed new attack method named Pass-ta-key, targeting passkeys in Google Password Manager on Windows. This attack highlights that passkeys, contrary to common belief, are not exclusively stored in secure hardware (TPM) but can be found in unencrypted local storage. Additionally, the research emphasizes that other platforms store passkeys locally, making them vulnerable if the device is infected with malware.

The Windows operating system, due to its broader app privileges, is particularly susceptible. While the risks of compromised devices are well-known, the study seeks to clarify the misunderstanding surrounding passkey security and the implications of malware on device safety.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline