A researcher demonstrated Pass-ta-key, an attack that extracts passkeys from Google Password Manager on infected Windows machines, challenging the common misconception that passkeys are always stored exclusively in TPMs. The FIDO2 specifications do not mandate hardware-backed storage, and many platforms store passkeys locally in software, which this attack exploits.
Background
Passkeys are emerging as a password-free authentication standard backed by FIDO2, widely promoted as more secure than traditional passwords. This attack highlights the gap between public perception of passkey security and the actual implementation realities.
- Source
- Ars Technica
- Published
- Aug 11, 2026 at 07:30 PM
- Score
- 6.0 / 10