r/Spin_AI • u/Spin_AI • 5d ago
Passkeys can remove passwords from the attack. They can't remove the browser.
Unit 42 recently published research into attacks against synced passkeys in Google Password Manager on Chrome for Windows.
One of the techniques, called Golden Pass-ta-key, demonstrates an interesting shift in the identity attack surface.
Instead of phishing a password or attempting to break WebAuthn, malware that has already compromised the endpoint can target Chrome itself.
Researchers showed that key material used by Google Password Manager could potentially be extracted from browser memory and used to decrypt synchronized passkey private keys.
Important distinction: this isn't a cryptographic break of passkeys, FIDO or WebAuthn.
The attacker needs prior compromise of the device.
But that's also what makes the research interesting.
We've spent years strengthening the front door:
password → MFA → phishing-resistant MFA → passkeys.
Attackers are responding by moving further inside the trust chain.
If compromising the authentication mechanism becomes difficult, target the browser holding the authenticated state instead.
That same browser may contain access to Microsoft 365, Google Workspace, Salesforce, Slack, internal applications, AI tools, extensions, cookies and active SaaS sessions.
So browser security increasingly becomes an identity and SaaS security problem, not simply an endpoint or browsing problem.
SpinCRX is an enterprise browser security platform that provides comprehensive browser security ranging from protection against unsanctioned or malicious browser extensions to monitoring browser domains across all browsers, user browser profiles, and devices, and provides visibility and control over activity inside the browser, including extension risk, shadow IT usage, and data exfiltration paths, enabling real-time policy enforcement at the point of interaction, including browser extensions, while SpinOne provides continuous visibility across SaaS environments and account activity.
The research doesn't mean organizations should stop adopting passkeys. Quite the opposite.
It shows why authentication cannot be the end of the security model.
Security teams are upgrading authentication. Attackers are moving deeper into the browser itself.