Important Alerts

Passkeys

Passkeys

New Passkey Vulnerability Discovered: Should You Stop Using Passkeys?

For years, cybersecurity experts have encouraged users to move away from traditional passwords and adopt passkeys instead. Major technology companies, including Google, Microsoft, and Apple, have promoted passkeys as a more secure way to protect online accounts.

However, newly released security research has uncovered vulnerabilities involving Google Password Manager’s implementation of synced passkeys on Windows devices. Naturally, headlines about a new passkey vulnerability may make users wonder whether passkeys are still safe.

Before you stop using them, though, it’s important to understand what researchers actually discovered and what it means for your online security.

What Are Passkeys?

Passkeys are a modern authentication method designed to replace traditional passwords. Instead of typing a password, you use a device you already own and unlock it with a fingerprint, facial recognition, PIN, or other screen-lock method.

Unlike passwords, passkeys cannot simply be guessed or reused across multiple websites. In addition, they provide strong protection against phishing because there isn’t a traditional password for you to accidentally enter into a fraudulent website.

For these reasons, passkeys are widely considered an important advancement in online security.

To learn more about how they work,
visit Google’s Passkeys information page.

What Did Security Researchers Discover?

Recently, researchers from Palo Alto Networks Unit 42 identified new attack techniques involving passwordless authentication and synced passkeys.

The researchers demonstrated three attacks involving Google-synced passkeys:

  • Pass-ta-key
  • Silver Pass-ta-key
  • Golden Pass-ta-key

Importantly, the researchers did not break the cryptography behind passkeys themselves.

Instead, the research demonstrates ways an attacker could take advantage of weaknesses surrounding how passkeys are stored, synchronized, or authenticated after gaining access to a Windows device.

You can read more about the technical research directly from Palo Alto Networks Unit 42.

Here’s the Important Part

Some headlines may make it sound as though criminals have suddenly found a way to “hack passkeys.” The reality is more complicated.

The demonstrated Pass-ta-key attack begins with malware already running on the victim’s Windows computer.

In other words, an attacker cannot simply sit somewhere on the internet and guess your passkey the way criminals may attempt to guess or steal a password.

First, the Windows device must already be compromised.

That’s an important distinction. Once malware is successfully running on a computer, an attacker may already have significant opportunities to steal information or interfere with the user’s activity.

Therefore, this research highlights the importance of protecting the device that stores credentials, rather than proving that the basic concept behind passkeys is broken.

Are Passkeys Still Safer Than Passwords?

For most users, yes.

Traditional passwords have several weaknesses. For example, they can be:

  • Reused across multiple websites
  • Stolen through phishing emails
  • Exposed in data breaches
  • Guessed through automated attacks
  • Accidentally entered into fake websites

Passkeys eliminate or greatly reduce many of these risks because there is no conventional password for an attacker to steal through a phishing page.

In fact, Google continues to describe passkeys as providing stronger protection against threats such as phishing.

The new research is important. However, it demonstrates potential weaknesses in specific passkey implementations and surrounding systems rather than proving that passkey technology itself is fundamentally unsafe.

Microsoft Is Moving Even Further Toward Passkeys

Interestingly, the Pass-ta-key research comes as Microsoft is moving even further toward phishing-resistant authentication.

Microsoft has announced that passkeys will become the default authentication experience in Microsoft Entra ID for users currently enabled for SMS or voice authentication beginning September 1, 2026.

Then, on February 1, 2027, Microsoft-provided SMS and voice authentication will be retired in Microsoft Entra ID.

Why the change?

According to Microsoft, SMS and voice authentication provide significantly weaker protection against phishing and account compromise than passkeys and other phishing-resistant authentication methods.

Microsoft recommends transitioning affected users to passkeys or another phishing-resistant authentication method before the deadline.

For businesses using Microsoft Entra ID, now is a good time to review how employees authenticate and begin preparing for the transition.

You can review the dates and requirements in Microsoft’s official Passkeys and SMS/Voice Retirement documentation.

What Does Microsoft’s Announcement Tell Us?

Microsoft’s decision provides some important context for the recent passkey vulnerability news.

Despite newly discovered attack techniques, the technology industry is not abandoning passkeys. Instead, companies continue moving away from authentication methods that are more susceptible to phishing and other attacks.

At the same time, security researchers are testing passkey systems and identifying weaknesses that developers can address.

That’s how cybersecurity technology improves.

Researchers look for vulnerabilities. Technology companies investigate the findings and develop protections. Then, security standards and products continue to evolve.

How Can You Protect Yourself?

Although the new research is technical, the steps everyday users and small businesses can take are surprisingly straightforward.

Keep Your Devices Updated

First, install Windows, browser, and security updates when they become available.

Updates frequently contain security fixes for newly discovered vulnerabilities. Therefore, postponing updates for long periods can unnecessarily expose your computer to known security problems.

Use Trusted Security Software

Because the demonstrated Pass-ta-key attack depends on malware being present on the Windows computer, protecting the device itself remains extremely important.

Reliable antivirus or endpoint security software can help identify and block malicious programs before they compromise the system.

Be Careful About Downloads

Malware frequently reaches computers through unsafe downloads, malicious email attachments, fraudulent websites, or compromised software.

For this reason, only install software from sources you trust. Likewise, be cautious about unexpected attachments and links, even when they appear to come from familiar companies.

Continue Using Passkeys

Despite the recent security research, there is currently no reason for the average user to abandon passkeys.

In fact, passkeys still provide significant protection against one of today’s most common online threats: phishing.

Google continues to support passkeys, while Microsoft is actively moving more users toward them.

Use Strong Multi-Factor Authentication When Passkeys Aren’t Available

Not every website supports passkeys yet.

If an account still requires a password, use a strong, unique password that isn’t used anywhere else. In addition, enable multi-factor authentication whenever possible.

Whenever you have a choice between authentication methods, consider stronger options such as an authenticator app, security key, or another phishing-resistant method instead of relying only on SMS.

Should You Stop Using Passkeys?

No.

The recent research is important because it identifies weaknesses that technology companies can address. However, it does not mean passkeys have suddenly become unsafe.

In fact, Microsoft’s decision to move users away from SMS and voice authentication toward passkeys reinforces the broader cybersecurity industry’s move toward phishing-resistant authentication.

For the average user, passkeys remain one of the strongest defenses against phishing and stolen passwords.

At the same time, the Pass-ta-key research offers an important reminder: even strong authentication cannot fully protect an already compromised computer.

That’s why account security and device security need to work together.

What Should Businesses Do Now?

For small businesses, this news provides a good opportunity to review basic cybersecurity practices.

First, make sure computers and browsers are receiving regular security updates. Next, review how employees sign in to important business accounts.

Businesses using Microsoft Entra ID should also determine whether employees are still relying on SMS or voice authentication and begin preparing for Microsoft’s upcoming changes.

Most importantly, don’t interpret the latest passkey headlines as a reason to return to passwords.

Instead, use the news as a reminder to strengthen the entire security picture, including authentication, device security, software updates, employee awareness, and safe browsing habits.

What About Apple Users?

Apple users can continue using passkeys as well. The recently discovered Pass-ta-key vulnerabilities discussed here focus on Google Password Manager and compromised Windows computers, rather than Apple’s native passkey system.

Apple supports passkeys on iPhone, iPad, and Mac, with passkeys synchronized through iCloud Keychain and protected by Apple’s security features. As with any device, keeping your operating system and software updated remains important.

If you use Google Password Manager on a Windows computer in addition to your Apple devices, however, the research may still be relevant to you because the issue involves the Google/Windows environment rather than simply whether you own an iPhone.

Final Thoughts

Cybersecurity is constantly evolving. As new technologies become more widely used, researchers continue looking for weaknesses so those weaknesses can be addressed.

The recent Pass-ta-key research is a reminder that no security system is perfect. However, it does not mean passkeys have become unsafe.

In fact, major technology companies continue moving toward passkeys and other phishing-resistant authentication methods while moving away from weaker options such as SMS and voice authentication.

Ultimately, the best defense is a combination of updated devices, trusted security software, cautious browsing habits, and strong authentication methods.

Staying informed about new cybersecurity developments can help you make smarter decisions and better protect both your personal information and your business.

Contact Us, if you have any questions.

Get Started

Give us a call or drop us a note and let’s see what we can do for you!