Post #4365006
2026-08-03 21:59 UTC
You might wonder why this is a problem if an attacker has to compromise you first to exploit it.
Let's talk infostealers. If you have a user that somehow gets an infostealer—say, via supply chain attack and no fault of their own—but they have excellent credential hygiene, with MFA for everything sensitive, you might think you dodged a bullet.
But uh oh! If they're using passkeys in Chrome, turns out the stealers now have a way to get a credential that, in many cases, bypasses the MFA requirement. The user "doing the right thing" has now become a liability because of Google's implementation.
Replies (2)
-
@mttaggart@infosec.exchange 2026-08-03 21:59
Here's a refresher on passkeys/WebAuthn for those interested: https://blog.trailofbits.com/2025/05/14/the-cryptography-behind-passkeys/
-
@wronglang@bayes.club 2026-08-03 22:44
@mttaggart@infosec.exchange yeah... they just managed to replicate vulnerabilities from ssh agents in a more complex application If I wanted my passkeys unencrypted I already have text files for that...