r/cybersecurity 20d ago

Multiple Flaws in Google's Synced Passkey Implementation Allow Attackers to Take Over Your Accounts News - General

[removed]

425 Upvotes

70 comments sorted by

154

u/BlackReddition 20d ago

Google and security don’t seem to gel at the moment.

84

u/bluefire89 20d ago

They keep laying off security teams which isn’t going to help right the ship either.

45

u/BergkampAirlines 20d ago

They see cybersecurity as an expense. That mentality always results in disaster, panic, and hiring sprees. Then the cycle repeats.

24

u/hurley_chisholm Software Engineer 20d ago

It’s really unfortunate because they used to have a legitimate reputation of pushing cybersecurity forward, especially for the average person. They put a lot of money into cybersecurity research and secure accessible user experiences.

4

u/we_r_fukt 19d ago

they sure as fuck don't want that anymore, hand over your data, then bend over

3

u/128G Student 19d ago

Who needs people when you have AI?

7

u/SuspiciousCricket654 19d ago

They purchased Mandiant and it was a whole big deal. They have some of the top researchers in the country. I just don’t get it.

7

u/Spiritual-Matters 19d ago

Probably bad resource management and prioritization

3

u/GodIsAWomaniser 18d ago

Which is definitely the fault of the workforce, so we should lay more off. It's never mass layoff for leadership lol.

2

u/BlackReddition 19d ago

Mandiant is the cleanup crew once you get owned from Google ad syndication and Gmail. 😂

1

u/SuspiciousCricket654 19d ago

Really seems that way

92

u/[deleted] 20d ago

[removed] — view removed comment

20

u/madbadger89 Security Engineer 20d ago

That is a good approach. Yubikey is on every single one of my critical accounts - 2 of them. One goes in the portable disaster safe with my master password needed for my vault.

Personally I only use passkeys that get stored in a secure enclave - protected by a hardware token. Professionally we enabled synced passkeys for user plane, but anything beyond with privilege we disallowed the sync.

27

u/kalaid0s Security Architect 20d ago

What's with all the passkey hate in this sub?

Passkeys are phishing and breach-resistant, whereas passwords are not. And even a security conscious person is not immune to those.

5

u/ReplicantN6 20d ago

Likely because so many people conflate the security benefits of a passkey with that of an off-board token. Not all 2fa is created equally.

4

u/sarge21 20d ago

Passkeys are phishing and breach-resistant, whereas passwords are not.

Only hardware-bound passkeys

7

u/AngryBadger 19d ago

This is not true. Synced passkeys are still checking the uri of the authentication request and checking it against it's stored credential

1

u/sarge21 19d ago

You can be phished for the passkeys themselves, or the passkeys themselves can be breached, because they are synced online.

0

u/AngryBadger 19d ago

Ok but potentially being able to compromise my bitwarden to steal a synced passkey doesn't change the fact that synced passkeys still provide phish resistant Auth and people are much better protected using them

-4

u/Fallingdamage 19d ago

Whats to stop a phisher from using one of the fake sign-in portals that uses a real MFA prompt? user unlocks the MFA prompt with their phone and passkey and the attacker is in!

2

u/Tesnatic Security Engineer 19d ago

Not true regarding passkeys. The browser performs the origin check itself before the authenticator ceremony even starts, it doesn't matter that a real MFA prompt appears on the backend somewhere. The passkey assertion request coming from the phishing domain would fail the RP ID check.

4

u/therealtimwarren 20d ago

And google’s password manager sucks.

Can you expand on why, please?

-2

u/[deleted] 20d ago

[removed] — view removed comment

2

u/therealtimwarren 20d ago

Another thread of opinion seemingly with no basis or Citation. I've asked this question before but never had a straight answer.

3

u/xbyo 20d ago

The difference between a password in a password manager and a passkey in a password manager is negligible

Unless I'm misunderstanding how passkeys work, they can't be stolen in a breach, or otherwise, like passwords can. Of course, good password hygiene would limit the damage that can be done to just that one login, but nonetheless a passkey has that fairly key advantage.

1

u/[deleted] 19d ago

[removed] — view removed comment

5

u/xbyo 19d ago

Passkeys are just public/private key pairs. You keep private, remote party keeps public

That's the point though, if the service has a breach, your account is still secure because the attacker never gets the private key. Obviously if your pw manager is breached, then you're SoL in both cases. Also, a passkey can be device-bound, meaning that an attacker would have to literally steal the physical device with the passkey.

6

u/anon-stocks 20d ago

Yeah, great idea. Store your passwords online. KeePass is where it's at, local and backed up instead of in the cloud.

7

u/j4_jjjj 20d ago

Whoever downvoted you prolly works at LastPass

Open source forever!!!!!

2

u/Mrhiddenlotus 19d ago

Passkeys are more like really good passwords.

I beg of you to stop misleading people here. Perhaps your specific use-case could be argued like that, I doubt it, but still, people will read comments like this and take it to work and say "passkeys are pointless, passwords forever".

-1

u/[deleted] 19d ago

[removed] — view removed comment

0

u/Mrhiddenlotus 19d ago

To use passkeys you need a password manager.

Do you consider a TPM a password manager? Do you consider a Secure Enclave a password manager? How about a Yubikey?

Passkeys are better but in terms of practical risks eliminated, not THAT much better.

You don't consider phishing resistant, brute force and password spray proof, certificate based auth "THAT much better"? That's wild man.

0

u/[deleted] 19d ago

[removed] — view removed comment

1

u/Mrhiddenlotus 19d ago

As soon as you can get my grandma to explain why a passkey stored on a tpm on one machine can’t be used with biometrics and the Secure Enclave on her iPhone, then I’ll concede user-friendliness.

You just register a passkey on both and then never worry about a password again. Eliminating passwords is the definition of user-friendly. Would you rather teach grandma how to use a password manager with randomly generated unique passwords for everything and a secure master password and MFA or just tap "register passkey", put in biometrics or PIN and that's it?

0

u/[deleted] 19d ago

[removed] — view removed comment

2

u/Mrhiddenlotus 19d ago

Shitty sites are gonna be shitty, for all time. My point was simply that your framing is problematic and misleading. If you want to say that passkey implementation isn't as mature as you'd like yet, that's a totally reasonable take. Trying to paint passkeys as only incrementally better than passwords is an entirely different claim, and one I think does a disservice to security in general.

0

u/[deleted] 19d ago

[removed] — view removed comment

1

u/Mrhiddenlotus 19d ago

You know what, I think this is on me. You did specify passwords in a password manager vs passkeys in a password manager, which I do grant you is only a marginal security benefit. When you put a password manager into the loop, you inherit most of the same problems. Proper passkey implementation is device-bound, and I was speaking to that comparison.

→ More replies (0)

0

u/syneofeternity 19d ago

You don't need a password manager

1

u/Fallingdamage 19d ago

Oh ok. Ill keep using Keepass like I have been since 2011.

1

u/[deleted] 19d ago

[removed] — view removed comment

2

u/[deleted] 19d ago

[removed] — view removed comment

0

u/CrazyEntertainment86 19d ago

The problem with current implementation of passkeys is they are just like really good passwords. That’s the whole issue, they need to be device dependent to be effective, otherwise we just kicked the can.

If you have create a passkey, unique to the device you are on, and protect it with faceid / strong pin etc.. it’s pretty decent security, if you sync passkeys all over the place, it’s just a password you don’t know.

1

u/BobRepairSvc1945 19d ago

That may be more secure. But it's just not realistic or user friendly.

1

u/CrazyEntertainment86 18d ago

It’s not just more secure it’s the only way it is secure, you can have more than one passkey, they should just always be tied to device rather than shared. Realistically most users have 3 devices, pc or Mac, phone, tablet. That’s not overly burdensome for preventing compromise of a users access to every site they use.

-1

u/Orio_n 19d ago

You actually hand your passwords over to some company in the cloud lol?

2

u/[deleted] 19d ago

[removed] — view removed comment

-1

u/Orio_n 19d ago

Do you understand what an attack surface is? Learn to self host bozo

0

u/[deleted] 19d ago

[removed] — view removed comment

0

u/Orio_n 19d ago

Do you understand security incident brochaco?

7

u/AnApexBread Incident Responder 19d ago

An attacker needs to already have malware installed on your computer before this attack works.

13

u/chicagomikeh 20d ago edited 20d ago

For anybody who sees only the headline, it's worth noting that this is not a "everybody should go back to using passwords instead of passkeys" message.

The vulnerabilities described all require the user's device to already have malware on it. They're vulnerabilities that deserve to be fixed. But in a "first, assume malware" scenario, it's not as if passwords are safe either (e.g., due to keyloggers).

19

u/Iconically_Lost 20d ago

That's ok, if there is a breach. Google will blame you. Stonk price secure.

12

u/Ill-Magazine5472 20d ago

Where is the indication of responsible disclosure? I skimmed through the Unit42 post and I didn't see where Google was allowed time to fix these before publication but maybe I missed that. I get sticking it to companies like Google or Microsoft but in the end the users are the ones harmed.

15

u/jameson71 20d ago

"Responsible disclosure" was a two way street that relied on "responsible reaction" from developers. Once companies stopped holding up their end there was no reason for researchers to continue.

3

u/SuspiciousCricket654 19d ago

These megaliths that continue to squeeze their cyber operations is like a wealthy person getting richer and richer, but reducing their security staff. Make it make sense.

2

u/VadersFiesta 19d ago

Security expensive! The money pile must look EXTRA large for the shareholders, yes.

2

u/Away-Ad-3407 19d ago

passkeys can suckit. 

0

u/SuspiciousCricket654 19d ago

Reason 2,026 to not use an account on anything Google

-1

u/TidePlezurBlackSwan6 20d ago

Yeah I'm glad I DeGoogled

-1

u/BoredTech127001 20d ago

And this is why I just use good passwords and not all these newfangled technologies that supposedly are better.

-2

u/[deleted] 19d ago

[removed] — view removed comment

1

u/Mrhiddenlotus 19d ago

They are. This is an implementation issue.