New Delhi: A shocking news has come to light regarding internet security. Passkeys, which were considered more secure than passwords, have now been detected targeting malware. According to researchers, accounts can be accessed by misuse of passkeys synced in Google Password Manager through infected Windows computers.
Why are passkeys considered secure?
Passkeys are considered a secure alternative to traditional passwords. It is based on public-key cryptography. It has one public and one private key. The private key does not leave the device, while the website verifies the user's identity through the public key.
For this reason, passkeys are considered more secure than common cyber attacks like phishing and password theft, but new research has indicated that if malware reaches the device or its associated software, then this security can also be in danger.
Passwords were targeted in three ways
According to research, attackers have identified three possible ways to misuse passkeys. In one approach, malware tries to create a legitimate login by using an infected computer without going through the normal verification process.
In another way, the attacker can add his user-verification key by taking advantage of the device's re-enrollment process. With this he can try to access the victim's account from his device.
In the most serious situation, malware may try to obtain secrets related to Google's security system. This may create a risk of misuse of synced passkeys by decrypting them.
How can users stay safe?
Experts advise to always keep the computer and all important software with the latest security updates. Use reliable and updated anti-malware protection. Apart from this, avoid clicking on unknown emails, suspicious links and unknown attachments. Remember, passkeys provide strong security, but secure devices and updated software are equally important.