Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them.
According to Token, attackers can target authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries. These methods do not require breaking FIDO2 cryptography.
The findings show that passkey-based authentication can still face attacks focused on the surrounding systems and processes. The documented methods concern how authentication is implemented, synchronized, enrolled, and recovered rather than a direct defeat of the underlying cryptography.
Comments
0No comments yet. Be the first to comment.