Passkey Redaction Attacks Subvert GitHub, Microsoft Authentication
ID: cc1e2f65-b5c5-5605-b3eb-a3c3fe24cdb6
STIX ID: report--cc1e2f65-b5c5-5605-b3eb-a3c3fe24cdb6
Feed Name: Dark Reading
Date Published: 2024-07-02
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
**Executive summary:** The report explains how adversary-in-the-middle (AitM) attackers can proxy and modify login pages to remove passkey authentication options (authentication method redaction), forcing users to use less-secure fallback methods that allow capture of credentials and tokens; it provides PoC examples against GitHub and Microsoft and recommends mitigations including magic/warded links, conditional access and device-based enforcement, and requiring or encouraging multiple passkeys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
