Preliminary research
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Investigates cloud passkey recovery after compromise of device identity. Forced re-onboarding permits an attacker-controlled user-verification key to be registered in a pending state, supporting later remote assertions; separate sync-secret logging and recovery-memory paths illustrate how authenticator state changes the post-compromise boundary.
Record
- Researcher
- Arie Olshtein
- Published by
- Palo Alto Networks Unit 42
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Arie Olshtein, first published at the original source. Preserved copies are kept so the citation survives its host.