New Pass-ta-key attack reveals all the things we didn't know about passkeys
摘要
上周有研究人员披露了针对通行密钥的“Pass-ta-key”攻击,可窃取Windows版Google密码管理器中存储的全部通行密钥。该攻击并非新型漏洞,也非通行密钥独有,但引发了用户和安全专家对这一新认证机制安全性的困惑。许多人误以为通行密钥仅存储在受硬件保护的TPM芯片中,而此次攻击表明,在感染恶意软件的设备上,应用层存储的通行密钥同样面临被提取的风险。
Last week a researcher outlined what he said was a “novel attack surface” in passkeys, the new authentication paradigm that offers a more secure alternative over password-based methods. In fact, the attacks demonstrated in the post are neither novel nor unique to passkeys. This distinction is important because the research has generated confusion among end users and security professionals as they assess whether this new mechanism is truly safe to use.
The attack is called Pass-ta-key—a blending of the word passkey with the phrase “pass the key” and a nod to a plate of pasta. Arie Olshtein, a researcher at security firm Palo Alto Networks, described in a post last week how Pass-ta-key could obtain all passkeys stored in the Google Password Manager app (GPM) for Windows when it’s running on a machine infected with malware.
This came as a surprise to many people because they believed passkeys are stored exclusively in the trusted platform manager (TPM), the locked-down enclave in a hardened silicon chip that’s reserved for storing cryptographic keys and other highly sensitive information on Windows machines. If passkeys are stored in the TPM, then how was Pass-ta-key able to extract the entire set of passkeys stored by the app, they wanted to know.
转载信息
评论 (0)
暂无评论,来留下第一条评论吧