New 'Pass-ta-key' exploit shows passkeys aren’t always hardware-protected
A researcher demonstrated that the Pass-ta-key technique can extract all passkeys stored in Google Password Manager on a compromised Windows PC, challenging the belief that they reside only in TPM hardware.
Last week, Palo Alto Networks researcher Arie Olshtein published a walkthrough of a new attack dubbed Pass-ta-key, which can harvest all passkeys saved in Google Password Manager on a Windows system infected with malware. The exploit undermines the common perception that passkeys are locked away in the TPM, a tamper-resistant chip designed for cryptographic material. In reality, the FIDO 2 standards overseen by the FIDO Alliance allow passkeys to be stored in various secure environments, such as software-based enclaves, and most vendors, including Google, use these non-hardware solutions.
Microsoft remains the only major provider offering an optional TPM storage path, primarily aimed at corporate users rather than consumers. Olshtein’s demonstration clarifies that the security of passkeys depends on the implementation choices of each platform, not an inherent hardware guarantee. The revelation has sparked discussion among security professionals about the true resilience of the emerging authentication method.
Why it matters
It shows that passkey security can vary by implementation, affecting users' trust in password-less login systems.
In this story