New Pass-ta-key attack reveals all the things we didn't know about passkeys
Ars Technica Dan Goodin
A security researcher described the “Pass-ta-key” attack method for passkeys, but the report said the underlying behavior is not actually new to passkey systems. The post’s key claim was that it can obtain all passkeys stored in the Google Password Manager app on Windows when the machine is infected with malware. As a result, readers were urged to separate passkeys being protected by the TPM from the reality that compromised machines can still let attackers extract what the app accesses.
Why it matters
Why passkey apps treat Windows differently than other operating systems.