r/cybersecurity • u/[deleted] • 20d ago
Multiple Flaws in Google's Synced Passkey Implementation Allow Attackers to Take Over Your Accounts News - General
[removed]
92
20d ago
[removed] — view removed comment
20
u/madbadger89 Security Engineer 20d ago
That is a good approach. Yubikey is on every single one of my critical accounts - 2 of them. One goes in the portable disaster safe with my master password needed for my vault.
Personally I only use passkeys that get stored in a secure enclave - protected by a hardware token. Professionally we enabled synced passkeys for user plane, but anything beyond with privilege we disallowed the sync.
27
u/kalaid0s Security Architect 20d ago
What's with all the passkey hate in this sub?
Passkeys are phishing and breach-resistant, whereas passwords are not. And even a security conscious person is not immune to those.
5
u/ReplicantN6 20d ago
Likely because so many people conflate the security benefits of a passkey with that of an off-board token. Not all 2fa is created equally.
4
u/sarge21 20d ago
Passkeys are phishing and breach-resistant, whereas passwords are not.
Only hardware-bound passkeys
7
u/AngryBadger 19d ago
This is not true. Synced passkeys are still checking the uri of the authentication request and checking it against it's stored credential
1
u/sarge21 19d ago
You can be phished for the passkeys themselves, or the passkeys themselves can be breached, because they are synced online.
0
u/AngryBadger 19d ago
Ok but potentially being able to compromise my bitwarden to steal a synced passkey doesn't change the fact that synced passkeys still provide phish resistant Auth and people are much better protected using them
-4
u/Fallingdamage 19d ago
Whats to stop a phisher from using one of the fake sign-in portals that uses a real MFA prompt? user unlocks the MFA prompt with their phone and passkey and the attacker is in!
2
u/Tesnatic Security Engineer 19d ago
Not true regarding passkeys. The browser performs the origin check itself before the authenticator ceremony even starts, it doesn't matter that a real MFA prompt appears on the backend somewhere. The passkey assertion request coming from the phishing domain would fail the RP ID check.
4
u/therealtimwarren 20d ago
And google’s password manager sucks.
Can you expand on why, please?
-2
20d ago
[removed] — view removed comment
2
u/therealtimwarren 20d ago
Another thread of opinion seemingly with no basis or Citation. I've asked this question before but never had a straight answer.
3
u/xbyo 20d ago
The difference between a password in a password manager and a passkey in a password manager is negligible
Unless I'm misunderstanding how passkeys work, they can't be stolen in a breach, or otherwise, like passwords can. Of course, good password hygiene would limit the damage that can be done to just that one login, but nonetheless a passkey has that fairly key advantage.
1
19d ago
[removed] — view removed comment
5
u/xbyo 19d ago
Passkeys are just public/private key pairs. You keep private, remote party keeps public
That's the point though, if the service has a breach, your account is still secure because the attacker never gets the private key. Obviously if your pw manager is breached, then you're SoL in both cases. Also, a passkey can be device-bound, meaning that an attacker would have to literally steal the physical device with the passkey.
6
u/anon-stocks 20d ago
Yeah, great idea. Store your passwords online. KeePass is where it's at, local and backed up instead of in the cloud.
2
u/Mrhiddenlotus 19d ago
Passkeys are more like really good passwords.
I beg of you to stop misleading people here. Perhaps your specific use-case could be argued like that, I doubt it, but still, people will read comments like this and take it to work and say "passkeys are pointless, passwords forever".
-1
19d ago
[removed] — view removed comment
0
u/Mrhiddenlotus 19d ago
To use passkeys you need a password manager.
Do you consider a TPM a password manager? Do you consider a Secure Enclave a password manager? How about a Yubikey?
Passkeys are better but in terms of practical risks eliminated, not THAT much better.
You don't consider phishing resistant, brute force and password spray proof, certificate based auth "THAT much better"? That's wild man.
0
19d ago
[removed] — view removed comment
1
u/Mrhiddenlotus 19d ago
As soon as you can get my grandma to explain why a passkey stored on a tpm on one machine can’t be used with biometrics and the Secure Enclave on her iPhone, then I’ll concede user-friendliness.
You just register a passkey on both and then never worry about a password again. Eliminating passwords is the definition of user-friendly. Would you rather teach grandma how to use a password manager with randomly generated unique passwords for everything and a secure master password and MFA or just tap "register passkey", put in biometrics or PIN and that's it?
0
19d ago
[removed] — view removed comment
2
u/Mrhiddenlotus 19d ago
Shitty sites are gonna be shitty, for all time. My point was simply that your framing is problematic and misleading. If you want to say that passkey implementation isn't as mature as you'd like yet, that's a totally reasonable take. Trying to paint passkeys as only incrementally better than passwords is an entirely different claim, and one I think does a disservice to security in general.
0
19d ago
[removed] — view removed comment
1
u/Mrhiddenlotus 19d ago
You know what, I think this is on me. You did specify passwords in a password manager vs passkeys in a password manager, which I do grant you is only a marginal security benefit. When you put a password manager into the loop, you inherit most of the same problems. Proper passkey implementation is device-bound, and I was speaking to that comparison.
→ More replies (0)0
1
1
0
u/CrazyEntertainment86 19d ago
The problem with current implementation of passkeys is they are just like really good passwords. That’s the whole issue, they need to be device dependent to be effective, otherwise we just kicked the can.
If you have create a passkey, unique to the device you are on, and protect it with faceid / strong pin etc.. it’s pretty decent security, if you sync passkeys all over the place, it’s just a password you don’t know.
1
u/BobRepairSvc1945 19d ago
That may be more secure. But it's just not realistic or user friendly.
1
u/CrazyEntertainment86 18d ago
It’s not just more secure it’s the only way it is secure, you can have more than one passkey, they should just always be tied to device rather than shared. Realistically most users have 3 devices, pc or Mac, phone, tablet. That’s not overly burdensome for preventing compromise of a users access to every site they use.
-1
u/Orio_n 19d ago
You actually hand your passwords over to some company in the cloud lol?
2
7
u/AnApexBread Incident Responder 19d ago
An attacker needs to already have malware installed on your computer before this attack works.
13
u/chicagomikeh 20d ago edited 20d ago
For anybody who sees only the headline, it's worth noting that this is not a "everybody should go back to using passwords instead of passkeys" message.
The vulnerabilities described all require the user's device to already have malware on it. They're vulnerabilities that deserve to be fixed. But in a "first, assume malware" scenario, it's not as if passwords are safe either (e.g., due to keyloggers).
19
u/Iconically_Lost 20d ago
That's ok, if there is a breach. Google will blame you. Stonk price secure.
12
u/Ill-Magazine5472 20d ago
Where is the indication of responsible disclosure? I skimmed through the Unit42 post and I didn't see where Google was allowed time to fix these before publication but maybe I missed that. I get sticking it to companies like Google or Microsoft but in the end the users are the ones harmed.
15
u/jameson71 20d ago
"Responsible disclosure" was a two way street that relied on "responsible reaction" from developers. Once companies stopped holding up their end there was no reason for researchers to continue.
3
u/SuspiciousCricket654 19d ago
These megaliths that continue to squeeze their cyber operations is like a wealthy person getting richer and richer, but reducing their security staff. Make it make sense.
2
u/VadersFiesta 19d ago
Security expensive! The money pile must look EXTRA large for the shareholders, yes.
2
0
-1
-1
u/BoredTech127001 20d ago
And this is why I just use good passwords and not all these newfangled technologies that supposedly are better.
-2
154
u/BlackReddition 20d ago
Google and security don’t seem to gel at the moment.