Serving tech enthusiasts for over 25 years.

TechSpot means tech analysis and advice you can trust.

In brief: Tech companies are rapidly replacing passwords with passkeys because they are easier to use and more secure. However, researchers recently demonstrated that passkeys are not foolproof. The way Google's authenticator stores passkeys in Chrome allows malware to spoof passkey authentication and hijack accounts in multiple ways.

Researchers at Unit 42 recently detailed three methods by which malware on a PC can read passkey data stored in Google Chrome. The most severe method completely compromises the victim's Google passkey vault, granting attackers remote access to every account that relies on passkeys.

Google, Microsoft, Apple, and many other companies are turning away from passwords, largely because users keep setting ones like "1234." Passkeys, stored on a user's device and decrypted on cloud services via PINs and biometrics, are even considered safer than password generators and managers because there are no passwords for hackers to steal from servers. Using a PIN or biometric is also easier than remembering a password.