frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
26•jchanimal•1h ago

Comments

ted_dunning•57m ago
It is hard to find the content for all of the glitzy ads on this site.
ikidd•54m ago
There's ads?
ted_dunning•40m ago
But when you do, there are glaring holes these people uncovered.
Groxx•52m ago
"You must enable DRM to play some audio or video on this page" pops up in the strangest places...
Terr_•11m ago
"Oh no, someone might pirate my advertisement and show it off to people for free!"
colemannugent•44m ago
>4. Using the hash of that handshake, the attacker interacts with the victim’s TPM and uses the extracted identity key to sign the handshake hash together with the assertion request

Huh? If you have this level of local privileges you can just read session cookies from the browsers store? I guess stealing all the keys is notable, but you can manipulate any password manager with this level of access right?

What's the threat model here, that synced passkeys should be secure in even in situations involving compromised clients? How?

ted_dunning•38m ago
It's not that simple. The stolen file has no clear text passwords and ideally, these passwords can only be decrypted on the right hardware with user confirmation. Of course, eternal and repeated confirmation requests are an anti pattern all their own, but the cloud attestation service not verifying the hardware sounds like a really glaring omission.
colemannugent•25m ago
It kinda is. If they use Chrome and it's cloud backed password manager, odds are they use GMail. That plus full access to a trusted device (which you have in this scenario) allows you to change their Google account password. Boom, full persistence.

I can think of at least a dozen easier ways to do nefarious things with this level of access that are at least that simple. As an example, faking user attribution would be trivial.

How could Google patch this? If the client is compromised and the attacker can manipulate the local TPM or it's equivalent there's no defense.

vel0city•37m ago
At least for accounts you want to keep very secure, session cookies are probably very time-limited. Stealing a passkey ensures persistent access in the future.

But I largely agree, if they're able to do this on your system you're already hacked and they can do a ton of very bad things.

MBCook•27m ago
Boy I’m so tired of people trying to make clever attack names. They don’t help remember things, there are too many.

So all 3 “pass-ta-key” attacks are not attacks on passkeys, they’re attacks on the Google vault.

And if you get access to the vault, then you get everything. OK. And if you get access to a synced traditional password vault, then you get everything.

So… meh. These are bugs, they will be fixed. Good on them for disclosing them. But this does not prove that passkeys are terrible. This does not make them less secure than random passwords.

If it wasn’t for the fact that they just happen to be getting passkeys, seems like this wouldn’t be worth a headline or discussing at all. And if they have this level of access, then they also get all the standard password credentials in the vault too, right?

nixpulvis•24m ago
Have we standardized a way to backup and export passkeys yet? Do websites commonly allow multiple passkeys to be registered?
ecesena•16m ago
There’s FIDO CXF/CXP: https://fidoalliance.org/specs/cx/cxf-v1.0-ps-errata-2026030...

To my understanding both Apple Passwords and the Android equivalent allow you to export passkeys to a different app (password manager), but I haven’t tried it yet.

If anyone has direct experience I appreciate to know how it was.

Gigachad•6m ago
I had a click around Apple Passwords on macos and I could not find a way to move my passkeys to another app. I could only see a way to share them with other Apple Passwords users.
tptacek•20m ago
These are endpoint malware attacks, not attacks on Passkeys per se. This is already a game-over position for an attacker to be in.
Gigachad•5m ago
>that synced passkeys should be secure in even in situations involving compromised clients?

I think that is the idea actually. By using secure hardware features it is in theory possible to secure the passkeys even in the case of compromised clients. Like how the iphone uses a security coprocessor to store the decryption keys and face id info out of the reach of iOS.

But this isn't overly concerning since it's still at a minimum as secure as passwords in a local compromise situation.

Terr_•14m ago
The right questions. The ability to set up an alternate key in advance is functionally similar to being able to make a backup.

If I had my 'druthers:

1. You can register multiple keys, such as for different devices. Like 5-10, not two.

2. There are two categories of keys: "Regular" and "Backup/Recovery".

3. Attempting to use a Backup Recovery key prompts to user to confirm that they want to discard all regular keys and promote the backup key(s) to the new regular.

In this way, a compromised backup key can't be used secretively.

libexpat now funded by the City of Munich for up to 6 months

https://blog.hartwork.org/posts/libexpat-city-of-munich-open-source-sabbatical/
82•spyc•1h ago•3 comments

Eight Myths on Software Engineering and GenAI

https://queue.acm.org/detail.cfm?id=3807963
17•tchalla•52m ago•2 comments

DuckDB – Data power tools for your laptop, now in Clojure (2023)

https://techascent.com/blog/just-ducking-around.html
41•sourdecor•2h ago•3 comments

I am retiring from fulltime writing (& pseudonymity) to launch Guardian Angel

https://twitter.com/gwern/status/2084739205071343837
127•mattsterett•3h ago•56 comments

Mistral's Shieldstral: 3B open-weights model for multimodal moderation

https://mistral.ai/news/shieldstral/
295•riadsila•8h ago•70 comments

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
26•jchanimal•1h ago•16 comments

IP and DNS Leaks in WebKit Affecting Proxy Browsers and iCloud Private Relay

https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/
22•lapcat•1h ago•2 comments

Pi's Minimalism Is Its Advantage

https://earendil.com/posts/pi-autoresearch-and-databricks/
54•luispa•2h ago•11 comments

We finally learned to center a div, then browsers added sidebars

https://seg6.space/posts/center-div/
41•seg6•2h ago•28 comments

Show HN: Simple algorithm and color space to generate diverse skin tones

https://toneyalexander.github.io/inclusive-color-space/
455•automatoney•9h ago•85 comments

AI fuels more than half of cybercrime in Africa as scams surge – Interpol

https://www.africanews.com/2026/08/04/ai-fuels-more-than-half-of-cybercrime-in-africa-as-digital-...
121•bookofjoe•2h ago•72 comments

FIPS 140-3 is not a security guarantee, and auditors know it

https://808bits.com/articles/fips-140-3-not-a-security-guarantee/
16•meehow•1h ago•7 comments

In Memory of My Wife, Elise Cawley, with Thanks for 36 Wonderful Years

https://writings.stephenwolfram.com/2026/08/in-memory-of-my-wife-elise-cawley-1961-2026-with-than...
845•jdcampolargo•5h ago•45 comments

Zigbee vs. Matter over Thread:Understanding IoT Protocol Performance in Practice

https://arxiv.org/abs/2603.04221
6•teleforce•32m ago•1 comments

Show HN: Maple-Preview – ternary 20B MoE running at 120 tok/s on a iPhone

https://deepgrove.ai/maple-preview
38•edwardbzhang•4h ago•12 comments

Waymo in Dallas

https://waymo.com/blog/shorts/dallas-open-to-all/
237•xnx•6h ago•320 comments

Third-party cyber evaluations involving OpenAI models

https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/
36•glub•3h ago•4 comments

DeepSeek V4 Flash on a Single AMD MI300X

https://github.com/ryanzhou/deepseek-v4-flash-mi300x
364•zhoutong•14h ago•87 comments

Video2NAND – Abusing video codecs for great computational power

https://sharedobject.blog/posts/vp8-combinatorial-logic/
25•firer•2d ago•4 comments

Bugtraq Is Back

https://lists.securityfocus.com/hyperkitty/list/bugtraq@securityfocus.com/thread/CHKLXLA7SJEWLDFH...
5•bashtoni•37m ago•1 comments

Truemetrics (YC S23) Is Hiring in Berlin – GTM Lead

https://www.ycombinator.com/companies/truemetrics/jobs/bIQQ7tP-founding-gtm-lead
1•truemetricsIngo•7h ago

Flowise Is Shutting Down

https://flowiseai.com/sunset
4•llmgraph•40m ago•2 comments

Show HN: SIMD Viterbi Decoder in Rust

https://github.com/brian-armstrong/fec
10•brian-armstrong•2h ago•0 comments

Show HN: A little physical breakout clone

https://brontosaurusrex.github.io/physical/v7/
8•brontosaurusrex•4d ago•5 comments

Thanks FedEx, This Is Why We Keep Getting Phished (2024)

https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-getting-phished/
210•stymaar•3h ago•57 comments

Oxide Computer raises $445M (SEC Form D)

https://www.sec.gov/Archives/edgar/data/1795071/000179507126000002/xslFormDX01/primary_doc.xml
174•depr•4h ago•75 comments

Keyv and friends compromised in active Shai-Hulud supply chain attack

https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
227•cimi_•13h ago•120 comments

Don't stop early: Case-folding source code at memory speed

https://github.blog/engineering/architecture-optimization/dont-stop-early-case-folding-source-cod...
47•sbulaev•4d ago•13 comments

Most tech revolutions made work worse for employees

https://www.thisandthat.chat/blog/most-tech-revolutions-made-work-worse-for-employees/
96•jreynar•9h ago•71 comments

When AI Benchmarks Plateau: A Systematic Study of Benchmark Saturation

https://arxiv.org/abs/2602.16763
75•doppp•8h ago•79 comments