새로운 패스키 공격이 개인 키를 복구하거나 피싱 저항 MFA를 우회하는 방법을 시연했습니다.
최근 연구에서 패스키 보호를 무너뜨리는 세 가지 방법이 발표되었습니다. 이 공격들은 암호학을 해치지 않고도 패스키 시스템의 취약점을 이용합니다. 연구자들은 윈도우가 노출한 인증 자료를 재사용하거나, 피해자의 기계에 이미 존재하는 악성코드로부터 클라우드와 동기화된 패스키 시스템을 악용했습니다.
New passkey attacks demonstrated methods to recover private keys or bypass phishing-resistant MFA.
Recent research efforts showcased three distinct methods to defeat passkey protections without compromising the underlying cryptography. The attacks involve reusing signed authentication material exposed by Windows, exploiting a cloud-synced passkey system from malware already present on the victim's machine, and other techniques. These findings highlight vulnerabilities in current passkey systems meant to enhance security against phishing.