Passkeys strengthen authentication with public key cryptography, but 39 publicly documented attack methods show that threats now focus on the surrounding software, enrollment, recovery, and user-interface layers. Dedicated biometric hardware, combined with strict service configuration, can greatly reduce the attack surface and better protect enterprise identities. #SpecterOps #PassThePasskey #FIDO2 #WebAuthn #Token
Keypoints
- Passkeys protect against password theft, but attackers are targeting surrounding trust boundaries instead.
- Researchers have documented 39 methods involving passkeys and related infrastructure.
- Attackers can manipulate authentication prompts, browser behavior, and Windows WebAuthn flows without stealing private keys.
- Shared, synced, exported, and recovered passkeys expand the attack surface across devices and cloud services.
- Dedicated biometric hardware and hardened enrollment and recovery controls reduce most of these risks.