Your passkeys could be vulnerable to attack, and everyone - including you - must act

General News

Summary

This article examines a clickjack-based exploit that can hijack passkey authentication ceremonies under specific conditions. It explains that the issue does not prove passkeys or the FIDO protocol are broken, but instead highlights weaknesses in password manager behavior, website session handling, and user settings. The piece also shows how vendors such as Bitwarden, 1Password, NordPass, LastPass, and Hanko are responding with mitigations or updates. Overall, it argues that layered defenses, session binding, and stronger user verification are necessary to reduce risk.

Classifications

industries
Fintech & Banking
applications
Accounting and Taxes

AskAI Classifications

Labels
SaaS Cloud Computing Enterprise Software

Linked Companies

Microsoft
$1B+
HackerOne
$50M to $100M
Hanko
$1M to $5M