• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

New Pass-ta-key attack reveals all the things we didn’t know about passkeys

August 11, 2026
Share on FacebookShare on Twitter

Unbeknownst to me until I began research for this article, all platforms other than those running Windows store passkeys locally on the device. The shift to local storage came a few years ago after OS and third-party application developers realized that passkeys had no chance of gaining widespread usage unless they could easily be synced to all of a user’s devices. Requiring TPM storage made syncing impossible. The only way to load them into the TPM of a new device would be to re-create each one individually.

Ultimately, architects of the FIDO specifications decided that it was generally safe to store passkeys on the devices. The thinking was that app permissions are so granular that malware lurking on the device would have no ability to access the private keys that form the lynchpin of passkey security. Malware installed on a device running macOS, iOS, and Android, for instance, has no ability to defeat this isolation unless the OS itself is compromised through some sort of exotic zero-day exploit. So far, these assumptions have been proven correct in real-world practice.

The lone exception is Windows. Unlike all the other platforms, Windows apps generally run with all the privileges of the user, whereas other platforms encourage the restriction of the privileges of each application by default. While Windows provides some sandboxing protections designed to isolate apps, it doesn’t prevent unsandboxed apps, such as malware, from accessing the data of a sandboxed app. That is, the sandbox only protects in one direction. Sandboxing technologies on other platforms are much more protective.

That means Windows malware has decidedly fewer problems accessing data used by a separate app. Passkey architects have been keenly aware of this difference, which is largely necessary for Windows backward-compatibility reasons. With no confidence that passkeys stored on a Windows device won’t be harvested in the event of a malware infection, many third-party developers opted for a new design—storing the passkeys in end-to-end encrypted blobs located in the cloud. Server-stored passkeys are now the design used not just by GPM for Windows, but 1Password, Dashlane, and other third-party apps for the Microsoft OS as well.

Next Post

ChatGPT will let you book a table mid-chat through Yelp

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Best Pokémon TCG deal: The Mega Moonlit Clefable ex Tin is now under $35 on Amazon
  • Best Loadouts In Call Of Duty: Black Ops 7 Season 6 Multiplayer
  • iPhone 20 display leak teases massive upgrade over iPhone 18 Pro
  • Which one is right for you and where can you buy it?
  • Googlebooks dissected: Are they for you?

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously