Your passkeys could be vulnerable to attack, and everyone - including you - must act
Summary
This article examines a clickjack-based exploit that can hijack passkey authentication ceremonies under specific conditions. It explains that the issue does not prove passkeys or the FIDO protocol are broken, but instead highlights weaknesses in password manager behavior, website session handling, and user settings. The piece also shows how vendors such as Bitwarden, 1Password, NordPass, LastPass, and Hanko are responding with mitigations or updates. Overall, it argues that layered defenses, session binding, and stronger user verification are necessary to reduce risk.
Classifications
industries
Fintech & Banking
applications
Accounting and Taxes
AskAI Classifications
Labels
SaaS
Cloud Computing
Enterprise Software