Passkeys are touted as safer than traditional passwords. But for people targeted by intimate partner abuse, they can often be more dangerous. Someone with access to their partner's computer and password could set up their own passkey—a cryptographic form of login used by services such as Google and LinkedIn—and invade their personal online space, potentially with dangerous consequences, new Cornell research has found.
The team conducted a lab-based study involving participants with diverse technical backgrounds to see how people identify and protect themselves from malicious use of their passkeys. The findings, the authors wrote, "paint a grim picture" of people's ability to alleviate the threat posed by such online invasions of privacy.
"Our conclusion is that services need to do a lot of work to enable users to diagnose compromises to their account, and remediate any account compromise that could occur," said Alaa Daffalla, doctoral student in computer science and lead author of a paper being presented at the 35th USENIX Security Symposium, Aug. 12–14 in Baltimore.
Senior authors are Nicola Dell, associate professor of information science at Cornell Tech, the Jacobs Technion-Cornell Institute and the Cornell Ann S. Bowers College of Computing and Information Science; and Thomas Ristenpart, professor of computer science at the University of Toronto and formerly of Cornell Tech and Cornell Bowers.










