
Times Now News reports that researchers have found a malware attack called 'Pass-Ta-Key' that can steal Google-synchronised passkeys from Windows computers. The malware exploits vulnerabilities in Google Password Manager, which syncs passkeys…
Times Now News reports that researchers have found a malware attack called 'Pass-Ta-Key' that can steal Google-synchronised passkeys from Windows computers. The malware exploits vulnerabilities in Google Password Manager, which syncs passkeys between devices for convenience, bypassing the biometric or PIN prompts that are meant to protect the private key.
Three attack scenarios have been identified: a regular version that silently creates a valid login; a 'Silver' version that registers its own verification key for remote login; and a 'Golden' version that extracts Google's master encryption key to decrypt and reuse all synced passkeys. Researchers advise users to keep systems patched, use real-time anti-malware protection, and avoid suspicious links or attachments.
The hype around passkeys as an 'unhackable' replacement for passwords was always overblown. This malware exploit of Google Password Manager shows that security relies not just on cryptography, but on the software and devices that handle it. The real test will be how quickly Google patches the flaw and whether it revises its marketing to acknowledge that convenience, like syncing passkeys across devices, creates new attack surfaces. Users must ask: is auto-sync worth the risk?
Source: timesnownews.com
This story was synthesised by AI from the source linked above.