Skip to content
Ars Technica·

🔒Pass-ta-key Attack Exposes Passkeys in Google Password Manager

Your passkeys aren't as secure as you think on Windows

TL;DR

A new attack, Pass-ta-key, exploits vulnerabilities in the Google Password Manager app for Windows. Malware can steal all stored passkeys when running on an infected machine. This affects users relying on TPM storage.

Pass-ta-key exposes a critical vulnerability in how passkeys are managed within the Google Password Manager app on Windows devices. The attack leverages malware to extract passkeys, undermining their security benefits over traditional passwords. Developers and IT teams need to be cautious about storing sensitive data locally, especially on platforms like Windows where apps often run with full user privileges. Pass-ta-key can obtain all stored passkeys when the GPM app is running on an infected machine, highlighting a significant risk for users who rely on TPM storage without additional security measures.

Pass-ta-key Attack Exposes Passkeys in Google Password Manager — Ars Technica

Key Points

1

Malware can extract all passkeys stored in the Google Password Manager app on Windows, compromising security.

2

Windows apps typically run with full user privileges, making them more susceptible to such attacks compared to other platforms.

3

Pass-ta-key uses malware access to Google accounts and TPM-stored keys to retrieve secret passkeys from infected machines.

4

The most powerful attack variant allows the infected machine to masquerade as an iPhone, transferring keys seamlessly.

5

Server-stored passkeys are now preferred by many third-party apps for Windows, including 1Password and Dashlane.

Why It Matters

If you're using Google Password Manager on a Windows device with local storage enabled, your passkeys are at risk. Malware can steal all stored passkeys, compromising security. Smaller teams should consider cloud-stored options or stricter app permissions to mitigate this threat.

passkeysGoogle Password ManagerWindows SecurityTPM Storage

Frequently Asked Questions

Why does this matter?

If you're using Google Password Manager on a Windows device with local storage enabled, your passkeys are at risk. Malware can steal all stored passkeys, compromising security. Smaller teams should consider cloud-stored options or stricter app permissions to mitigate this threat.

What happened?

A new attack, Pass-ta-key, exploits vulnerabilities in the Google Password Manager app for Windows. Malware can steal all stored passkeys when running on an infected machine. This affects users relying on TPM storage.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 2,944 builders reading daily.

Also get