HomeTechnologyNew Pass-ta-key attack reveals all the things we didn't know about passkeys

New Pass-ta-key attack reveals all the things we didn't know about passkeys

TechnologyAugust 11, 2026
2 min read
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Why passkey apps treat Windows differently than other operating systems.
Reading Settings

Last week, a researcher outlined what he said was a “novel attack surface” in passkeys, the new authentication paradigm that offers a more secure alternative to password-based methods. In fact, the attacks demonstrated in the post are neither novel nor unique to passkeys. This distinction is important because the research has generated confusion among end users and security professionals as they assess whether this new mechanism is truly safe to use.

The attack is called Pass-ta-key—a blending of the word passkey with the phrase “pass the key” and a nod to a plate of pasta. Arie Olshtein, a researcher at security firm Palo Alto Networks, described in a post last week how Pass-ta-key could obtain all passkeys stored in the Google Password Manager app (GPM) for Windows when it’s running on a machine infected with malware.

This came as a surprise to many people because they believed passkeys are stored exclusively in the trusted platform manager (TPM), the locked-down enclave in a hardened silicon chip that’s reserved for storing cryptographic keys and other highly sensitive information on Windows machines. If passkeys are stored in the TPM, then how was Pass-ta-key able to extract the entire set of passkeys stored by the app, they wanted to know.

Read full article

Comments

Source: Ars Technica

Share this article

Related Articles

Elon Musk, Sam Altman, and the Misreading of Science Fiction
Aug 115 hours ago

Elon Musk, Sam Altman, and the Misreading of Science Fiction

Beyond Elon Musk’s interpretation of The Odyssey, Silicon Valley leaders have often misunderstood classic books like Foundation and The Hitchhiker’s Guide to the Galaxy. It’s evident in their tech.

6a5a54e5103c3bf8e37e5b2d15 min read
Read More