Pass-ta-key Extracts All Google Password Manager Passkeys on Infected Windows PCs as TPM Use Proves Limited
Updated
Updated · Ars Technica · Aug 11
Pass-ta-key Extracts All Google Password Manager Passkeys on Infected Windows PCs as TPM Use Proves Limited
2 articles · Updated · Ars Technica · Aug 11
Summary
Arie Olshtein said his Pass-ta-key attack can pull all passkeys stored in Google Password Manager for Windows when malware is already running on the PC.
The finding stirred confusion because many users assumed passkeys are kept inside a TPM, where malware could not simply extract them.
FIDO2 does not require passkeys to be stored in dedicated hardware, and most platforms and third-party managers do not use TPMs or similar secure enclaves for local passkey storage.
Microsoft is a notable exception, offering TPM-backed passkey storage on Windows, though it mainly recommends that option for enterprise users rather than consumers.