Elektrine lite

← Feed

@mttaggart@infosec.exchange

Post #4365007

2026-08-03 19:58 UTC

This is fantastic research from Unit42. My takeaway here is that passkeys are still much better than passwords, and Chrome as a credential manager is still a terrible idea. Use a separate password manager. https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/

Replies (1)

  • @mttaggart@infosec.exchange 2026-08-03 21:59

    You might wonder why this is a problem if an attacker has to compromise you first to exploit it. Let's talk infostealers. If you have a user that somehow gets an infostealer—say, via supply chain attack and no fault of their own—but they have excellent credential hygiene, with MFA for everything sensitive, you might think you dodged a bullet. But uh oh! If they're using passkeys in Chrome, turns out the stealers now have a way to get a credential that, in many cases, bypasses the MFA requirement. The user "doing the right thing" has now become a liability because of Google's implementation.

    Open ##4365006