Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:

IPv6:

 

UpOrDown
Ping
MTR
Smokeping
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc
IP Extractor

Passkeys Debate Sparks Security Controversy

Image © Arstechnica
A security researcher’s claim draws scrutiny over passkeys and endpoint security.

A recent Ars Technica analysis questions SquareX’s Defcon-published claims that passkeys can be stolen, arguing the study leans into hype rather than a proven vulnerability.

The research describes “Passkeys Pwned” as a browser-extension attack that hijacks the registration flow, binding a malware-generated keypair to a legitimate domain such as gmail.com, potentially granting attackers access to cloud apps.

Security experts say the attack relies on endpoint compromise or social engineering, and does not reveal a flaw in passkeys themselves, whose private keys remain on the user’s device under the FIDO/WebAuthn model.

Critics, including security engineer Kenn White, have characterized the report as a dubious marketing pitch; Ars Technica’s Dan Goodin notes that passkeys remain highly resistant to phishing when endpoints are secured.

Overall, passkeys offer strong defense against credential theft, but researchers warn that client-side risks must be part of any security evaluation as technology evolves, and that public debates should distinguish proof-of-concept demonstrations from foundational vulnerabilities.

 

Arstechnica

Notícias relacionadas

Ligga lança fibra com IA via Inner AI
Oi busca plano novo e assessores
Receita desmente fake news sobre MEI e limite
Ericsson traça redes futuras com IA e APIs
Ceará terá relógio atômico de césio em data center
Pix bate recorde com 297 milhões de transações

O ISP.Tools sobrevive graças aos anúncios.

Considere a possibilidade de desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento de cookies

Usamos cookies para melhorar sua experiência em nosso site.

Ao usar nosso site, você concorda com os cookies. Saiba mais sobre o site