
Le passkey, considerate il futuro super-sicuro che dovrebbe sradicare le password convenzionali, si trovano però ad affrontare un colpo di stato virtuale. Recentemente, ricercatori di Palo Alto Networks hanno svelato tre metodi sofisticati con cui i cybercriminali possono saltare l’accesso a account Google protetti da queste ritenute impenetrabili chiavi digitali. Spoiler: non è facile, ma è possibile se si riesce a infettare il dispositivo della vittima. L’attacco più noto è ‘Pass-ta-key’. Si basa sullo sfruttamento di vulnerabilità nel password manager di Chrome e nell’Authenticator Google Cloud. Un malware presente sul PC permette all’aggressore di impersonare un dispositivo fidato, firmando richieste che il sistema crede legittime. In teoria, se l’account chiede verifica PIN o biometria, questo attacco si blocca, ma i criminali hanno preparato altre mazzinate. Con ‘Silver Pass-Ta-Key’, la minaccia diventa più insidiosa: il malware può invalidare le chiavi di verifica esistenti e registrare una chiave sotto il proprio controllo. Il sistema non se ne accorge; finisce che Google accetta semplicemente i login firmati con quella nuova chiave, aggirando totalmente qualsiasi richiesta di autenticazione utente. È come cambiare la serratura senza far suonare l’allarme. La ciliegina sulla torta (o meglio, il colpo mortale) è ‘Golden Pass-ta-key’. Questo attacco permette di rubare la master key, lo ‘security domain secret’ (SDS), che decifra tutte le passkey salvate nel password manager. Anche se Google ha già chiuso questa falla nei log, l’attaccante può estrarla dalla memoria di Chrome, rendendo il furto reversibile e devastante: non si rubano solo le chiavi attuali, ma anche quelle future dell’account. Insomma, passare alla ‘passkey’ è un salto in avanti per la sicurezza, ma ci ricorda che l’endpoint del dispositivo rimane sempre il punto debole. Un promemoria necessario prima di fidarsi ciecamente dei miracoli tecnologici.
🇬🇧 Summary in English
Passkeys were heralded as the impenetrable successor to traditional passwords, promising a bulletproof layer of digital security. However, recent findings by researchers at Palo Alto Networks have thrown a cold splash of reality on this optimistic picture. They unveiled three sophisticated methods that cybercriminals could use to hijack Google accounts protected by these supposed fortress-like passkeys. Spoiler alert: the biggest risk is malware already residing on your device. The attack, named ‘Pass-ta-key,’ exploits vulnerabilities in Chrome’s password manager and Google Cloud Authenticator. A piece of malicious software (malware) allows the attacker to convincingly impersonate a trusted device, signing requests that the system accepts as legitimate. While this attack fails if the account requires secondary verification like a PIN or biometrics, the criminals are ready with more tricks. Next up is ‘Silver Pass-Ta-Key,’ which makes the threat even sneakier. The malware can invalidate existing security keys and register new ones under its own control. The system, oblivious to the switcheroo, accepts login attempts signed by the criminal’s key, effectively bypassing any multi-factor authentication prompts. It’s like swapping out a house’s lock and telling the alarm it’s still working perfectly. The grand finale is ‘Golden Pass-ta-key,’ which allows attackers to steal the master key—the Security Domain Secret (SDS)—used to encrypt all passkeys stored in Chrome’s password manager. Even though Google patched this vulnerability from its logs, the data can still be fished out of Chrome’s process memory. Stealing the SDS means decrypting not just current keys but also *all* future passkeys for that account. It’s a catastrophic vulnerability because there’s currently no way to modify or revoke the compromised master key. The takeaway? While passkeys are an undeniable leap forward in security, they underscore a brutal reality: the endpoint device remains the weakest link in the chain.
Leggi l’articolo originale su Punto Informatico →
Fonte: Punto Informatico | Argomento: Tech News
#tecnologia #innovazione #technews