Skip to content
Breaking:

Passkey Security Interfaces Fail to Protect Users From Account Intrusions, Cornell Study Finds

Research highlights how platforms including Google, PayPal, and LinkedIn leave users struggling to detect and remove unauthorized passkeys issued by abusive partners.

By The Company Wire4 min read
Share
Google — Passkey Security Interfaces Fail to Protect Users From Account Intrusions, Cornell Study Finds
Google — Passkey Security Interfaces Fail to Protect Users From Account Intrusions, Cornell Study Finds. Photo: TechXplore.

While modern passkey technology is widely promoted as a secure alternative to traditional passwords, new research from Cornell University warns that the system presents severe safety hazards for survivors of intimate partner abuse. When an abuser possesses physical access to a victim's hardware and knows their password, they can silently set up an unauthorized passkey on platforms such as Google, LinkedIn, and PayPal to maintain continuous access to private digital accounts.

The findings, first reported by TechXplore, will be presented at the 35th USENIX Security Symposium taking place August 12–14 in Baltimore. The study evaluated how individuals across various technical skill levels identify and attempt to resolve malicious passkey configurations on their personal accounts.

Researchers evaluated 31 participants, including university students, community members, and clinicians from the Clinic to End Tech Abuse (CETA). Conducting simulated account compromises on two designated laptops, researchers tested whether participants could detect intrusions into Google, PayPal, and LinkedIn accounts after an adversary created an unauthorized passkey.

The results revealed widespread difficulty in mitigating account intrusions. The vast majority of participants were unable to recognize unauthorized logins originating from the attacker's device. Furthermore, most could not navigate account settings to delete the adversary's passkey, update their password, or revoke active sessions on remote devices without guidance from researchers.

The study highlighted significant usability problems with account security interfaces (ASIs) across all tested platforms. For example, one participant misinterpreted the iCloud Keychain interface—which stores synced passkeys—believing two listed passkeys represented a single key shared across two devices rather than separate credentials for the victim and the intruder.

"Our conclusion is that services need to do a lot of work to enable users to diagnose compromises to their account, and remediate any account compromise that could occur," said Alaa Daffalla, lead author of the paper and a computer science doctoral student at Cornell. Senior authors on the paper include Nicola Dell, associate professor at Cornell Tech and the Cornell Ann S. Bowers College of Computing and Information Science, and Thomas Ristenpart, computer science professor at the University of Toronto. Dell and Ristenpart co-founded CETA in 2018 to support victims of technology-facilitated abuse.

The researchers emphasized that interface shortcomings impact general consumers alongside high-risk groups. Dell noted that "understanding the security of online accounts, including emerging authentication mechanisms like passkeys, is essential for digital safety, not only for abuse survivors but for all technology users." Daffalla added that even tech-fluent participants struggled during testing, stating, "People maybe are using passkeys, but they don't understand how they work. So it's a little worrying that we still haven't gotten to a place where we are designing systems and interfaces that ensure users feel safe about their accounts."

Sources

  1. TechXplore

Company: Google

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.