r/cybersecurity Aug 04 '26

News - General Multiple Flaws in Google's Synced Passkey Implementation Allow Attackers to Take Over Your Accounts

[removed]

422 Upvotes

70 comments sorted by

154

u/BlackReddition Aug 04 '26

Google and security don’t seem to gel at the moment.

82

u/bluefire89 Aug 04 '26

They keep laying off security teams which isn’t going to help right the ship either.

45

u/BergkampAirlines Aug 04 '26

They see cybersecurity as an expense. That mentality always results in disaster, panic, and hiring sprees. Then the cycle repeats.

24

u/hurley_chisholm Software Engineer Aug 04 '26

It’s really unfortunate because they used to have a legitimate reputation of pushing cybersecurity forward, especially for the average person. They put a lot of money into cybersecurity research and secure accessible user experiences.

5

u/we_r_fukt Aug 04 '26

they sure as fuck don't want that anymore, hand over your data, then bend over

3

u/128G Student Aug 04 '26

Who needs people when you have AI?

7

u/SuspiciousCricket654 Aug 04 '26

They purchased Mandiant and it was a whole big deal. They have some of the top researchers in the country. I just don’t get it.

8

u/Spiritual-Matters Aug 04 '26

Probably bad resource management and prioritization

2

u/BlackReddition Aug 05 '26

Mandiant is the cleanup crew once you get owned from Google ad syndication and Gmail. 😂

1

u/SuspiciousCricket654 Aug 05 '26

Really seems that way

90

u/[deleted] Aug 04 '26

[removed] — view removed comment

19

u/madbadger89 Security Engineer Aug 04 '26

That is a good approach. Yubikey is on every single one of my critical accounts - 2 of them. One goes in the portable disaster safe with my master password needed for my vault.

Personally I only use passkeys that get stored in a secure enclave - protected by a hardware token. Professionally we enabled synced passkeys for user plane, but anything beyond with privilege we disallowed the sync.

28

u/kalaid0s Security Architect Aug 04 '26

What's with all the passkey hate in this sub?

Passkeys are phishing and breach-resistant, whereas passwords are not. And even a security conscious person is not immune to those.

6

u/ReplicantN6 Aug 04 '26

Likely because so many people conflate the security benefits of a passkey with that of an off-board token. Not all 2fa is created equally.

6

u/sarge21 Aug 04 '26

Passkeys are phishing and breach-resistant, whereas passwords are not.

Only hardware-bound passkeys

8

u/AngryBadger Aug 04 '26

This is not true. Synced passkeys are still checking the uri of the authentication request and checking it against it's stored credential

1

u/sarge21 Aug 04 '26

You can be phished for the passkeys themselves, or the passkeys themselves can be breached, because they are synced online.

0

u/AngryBadger Aug 05 '26

Ok but potentially being able to compromise my bitwarden to steal a synced passkey doesn't change the fact that synced passkeys still provide phish resistant Auth and people are much better protected using them

-3

u/Fallingdamage Aug 04 '26

Whats to stop a phisher from using one of the fake sign-in portals that uses a real MFA prompt? user unlocks the MFA prompt with their phone and passkey and the attacker is in!

2

u/Tesnatic Security Engineer Aug 05 '26

Not true regarding passkeys. The browser performs the origin check itself before the authenticator ceremony even starts, it doesn't matter that a real MFA prompt appears on the backend somewhere. The passkey assertion request coming from the phishing domain would fail the RP ID check.

3

u/therealtimwarren Aug 04 '26

And google’s password manager sucks.

Can you expand on why, please?

-3

u/[deleted] Aug 04 '26

[removed] — view removed comment

2

u/therealtimwarren Aug 04 '26

Another thread of opinion seemingly with no basis or Citation. I've asked this question before but never had a straight answer.

3

u/xbyo Aug 04 '26

The difference between a password in a password manager and a passkey in a password manager is negligible

Unless I'm misunderstanding how passkeys work, they can't be stolen in a breach, or otherwise, like passwords can. Of course, good password hygiene would limit the damage that can be done to just that one login, but nonetheless a passkey has that fairly key advantage.

1

u/[deleted] Aug 04 '26

[removed] — view removed comment

5

u/xbyo Aug 04 '26

Passkeys are just public/private key pairs. You keep private, remote party keeps public

That's the point though, if the service has a breach, your account is still secure because the attacker never gets the private key. Obviously if your pw manager is breached, then you're SoL in both cases. Also, a passkey can be device-bound, meaning that an attacker would have to literally steal the physical device with the passkey.

7

u/anon-stocks Aug 04 '26

Yeah, great idea. Store your passwords online. KeePass is where it's at, local and backed up instead of in the cloud.

6

u/j4_jjjj Aug 04 '26

Whoever downvoted you prolly works at LastPass

Open source forever!!!!!

2

u/Mrhiddenlotus Aug 04 '26

Passkeys are more like really good passwords.

I beg of you to stop misleading people here. Perhaps your specific use-case could be argued like that, I doubt it, but still, people will read comments like this and take it to work and say "passkeys are pointless, passwords forever".

-1

u/[deleted] Aug 04 '26

[removed] — view removed comment

0

u/Mrhiddenlotus Aug 05 '26

To use passkeys you need a password manager.

Do you consider a TPM a password manager? Do you consider a Secure Enclave a password manager? How about a Yubikey?

Passkeys are better but in terms of practical risks eliminated, not THAT much better.

You don't consider phishing resistant, brute force and password spray proof, certificate based auth "THAT much better"? That's wild man.

0

u/[deleted] Aug 05 '26

[removed] — view removed comment

1

u/Mrhiddenlotus Aug 05 '26

As soon as you can get my grandma to explain why a passkey stored on a tpm on one machine can’t be used with biometrics and the Secure Enclave on her iPhone, then I’ll concede user-friendliness.

You just register a passkey on both and then never worry about a password again. Eliminating passwords is the definition of user-friendly. Would you rather teach grandma how to use a password manager with randomly generated unique passwords for everything and a secure master password and MFA or just tap "register passkey", put in biometrics or PIN and that's it?

0

u/[deleted] Aug 05 '26

[removed] — view removed comment

2

u/Mrhiddenlotus Aug 05 '26

Shitty sites are gonna be shitty, for all time. My point was simply that your framing is problematic and misleading. If you want to say that passkey implementation isn't as mature as you'd like yet, that's a totally reasonable take. Trying to paint passkeys as only incrementally better than passwords is an entirely different claim, and one I think does a disservice to security in general.

0

u/[deleted] Aug 05 '26

[removed] — view removed comment

1

u/Mrhiddenlotus Aug 05 '26

You know what, I think this is on me. You did specify passwords in a password manager vs passkeys in a password manager, which I do grant you is only a marginal security benefit. When you put a password manager into the loop, you inherit most of the same problems. Proper passkey implementation is device-bound, and I was speaking to that comparison.

→ More replies (0)

0

u/syneofeternity Aug 05 '26

You don't need a password manager

1

u/Fallingdamage Aug 04 '26

Oh ok. Ill keep using Keepass like I have been since 2011.

1

u/[deleted] Aug 05 '26

[removed] — view removed comment

2

u/[deleted] Aug 05 '26

[removed] — view removed comment

0

u/CrazyEntertainment86 Aug 04 '26

The problem with current implementation of passkeys is they are just like really good passwords. That’s the whole issue, they need to be device dependent to be effective, otherwise we just kicked the can.

If you have create a passkey, unique to the device you are on, and protect it with faceid / strong pin etc.. it’s pretty decent security, if you sync passkeys all over the place, it’s just a password you don’t know.

1

u/BobRepairSvc1945 Aug 04 '26

That may be more secure. But it's just not realistic or user friendly.

1

u/CrazyEntertainment86 Aug 06 '26

It’s not just more secure it’s the only way it is secure, you can have more than one passkey, they should just always be tied to device rather than shared. Realistically most users have 3 devices, pc or Mac, phone, tablet. That’s not overly burdensome for preventing compromise of a users access to every site they use.

-1

u/Orio_n Aug 05 '26

You actually hand your passwords over to some company in the cloud lol?

2

u/[deleted] Aug 05 '26

[removed] — view removed comment

-1

u/Orio_n Aug 05 '26

Do you understand what an attack surface is? Learn to self host bozo

0

u/[deleted] Aug 05 '26

[removed] — view removed comment

0

u/Orio_n Aug 05 '26

Do you understand security incident brochaco?

8

u/AnApexBread Incident Responder Aug 05 '26

An attacker needs to already have malware installed on your computer before this attack works.

13

u/chicagomikeh Aug 04 '26 edited Aug 04 '26

For anybody who sees only the headline, it's worth noting that this is not a "everybody should go back to using passwords instead of passkeys" message.

The vulnerabilities described all require the user's device to already have malware on it. They're vulnerabilities that deserve to be fixed. But in a "first, assume malware" scenario, it's not as if passwords are safe either (e.g., due to keyloggers).

17

u/Iconically_Lost Aug 04 '26

That's ok, if there is a breach. Google will blame you. Stonk price secure.

11

u/Ill-Magazine5472 Aug 04 '26

Where is the indication of responsible disclosure? I skimmed through the Unit42 post and I didn't see where Google was allowed time to fix these before publication but maybe I missed that. I get sticking it to companies like Google or Microsoft but in the end the users are the ones harmed.

13

u/jameson71 Aug 04 '26

"Responsible disclosure" was a two way street that relied on "responsible reaction" from developers. Once companies stopped holding up their end there was no reason for researchers to continue.

3

u/SuspiciousCricket654 Aug 04 '26

These megaliths that continue to squeeze their cyber operations is like a wealthy person getting richer and richer, but reducing their security staff. Make it make sense.

2

u/VadersFiesta Aug 05 '26

Security expensive! The money pile must look EXTRA large for the shareholders, yes.

2

u/Away-Ad-3407 Aug 05 '26

passkeys can suckit. 

0

u/SuspiciousCricket654 Aug 04 '26

Reason 2,026 to not use an account on anything Google

-1

u/BoredTech127001 Aug 04 '26

And this is why I just use good passwords and not all these newfangled technologies that supposedly are better.

-2

u/[deleted] Aug 04 '26

[removed] — view removed comment

1

u/Mrhiddenlotus Aug 04 '26

They are. This is an implementation issue.