logo

Google Authenticator: The Hidden Mechanisms of Passwordless Authentication

ID: 420ea2ef-368c-5955-ac95-7ffbda4b6724

STIX ID: report--420ea2ef-368c-5955-ac95-7ffbda4b6724

Feed Name: Palo Alto Networks Unit 42

Threat Score
30/100

Date Published: 2026-03-23

Date Updated: 2026-04-28

Author: Arie Olshtein

...
...

Palo Alto Networks Unit 42 analyzes Google Authenticator’s cloud-based passkey architecture—covering device onboarding, TPM-backed identity and user-verification keys, wrapping keys, the security domain secret (SDS), passkey creation/synchronization, and the Noise-protected WebSocket communication—to show how synced passkeys introduce a new hybrid attack surface that could enable remote device impersonation or passkey compromise; the report documents implementation details and defensive mitigations but does not report observed active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.