The Bait-and-Switch of Synced Passkeys
Spensky recalled the 2017 WebAuthn draft: passkeys must be machine-bound and phishing-resistant. He rejoiced — asymmetric keys in TPMs, no way to phish. In 2023, Google and Apple announced synced passkeys. Spensky saw the message “your pass keys are securely synced across all devices” and called it a bait-and-switch. The core assumption of asymmetric cryptography — private keys remain private — was broken the moment keys got copied everywhere.
Phishing Chrome Passkeys With One Fake Login
Spensky built a phishing site that emulated keyboard strokes into a real Chrome browser. The victim typed their password and SMS code into the fake UI. The attacker then controlled the Chrome session, turned on sync, and fished the six-digit PIN protecting the passkeys. With the PIN, he changed it, locking the victim out. He exported all passkeys to a file. “I did the single dumbest fishing attack ever and got all the pass keys,” he said.
Bitwarden Passkeys Are Just as Easy to Steal
Bitwarden users are not safe. Spensky logged into a Bitwarden account via a phishing site, then used Bitwarden’s developer tools to export all passkeys. The export shows private keys, algorithms, and curves. He imported those keys into his own Bitwarden and logged into Discord with a “phishing resistant” passkey. “The technical complexity is laughable,” he said.
Why a Leaked Passkey Is Worse Than a Leaked Password
Websites never ask for a second factor with passkeys — they assume the key itself is proof. If an attacker steals a password, each site adds its own security. But a stolen passkey grants full access to every account. Spensky noted that some sites disable password-only login after a passkey is enrolled. “It is game set match,” he said. The root cause: synced passkeys copy the private key to every device, so one malware infection compromises everything.
Device-Bound Passkeys Are the Fix
Spensky urged the audience: “Friends do not let friends use synced passkeys.” Device-bound passkeys stay on the hardware — a USB token, smartphone, or TPM. They never leave the device and are truly unphishable. He offers a free app at download.allthenticate.com. He argued the big players push synced passkeys to keep users in their password managers. The original WebAuthn dream of decentralized, device-bound authentication can still work.
Q&A
Can the sync fabric itself add phishing resistance? Spensky said that just pushes the problem to the next layer — you still need a phishing-resistant key to protect the password manager. ▶ 19:39
How can users tell if a passkey is synced or device-bound? Spensky’s site passkeyweek.com lists which providers sync. He wants a UI that shows the type before generation. ▶ 21:30
Can service providers reject synced passkeys? The metadata exists, but Spensky doubts the FIDO alliance will allow providers to block synced keys. ▶ 22:32
Are phone passkeys more secure than browser ones? Phone passkeys still protect against password phishing, but once the password manager is compromised, the damage is greater than with passwords alone. ▶ 23:03
Notable Quotes
I did the single dumbest fishing attack ever and got all the pass keys. Chad Spensky · ▶ 6:44
a leaked pass key is far worse than a leaked password Chad Spensky · ▶ 12:03
you have an insecure password protecting more secure pass keys Chad Spensky · ▶ 14:54
friends do not let friends use synced pass keys Chad Spensky · ▶ 15:22
Key Takeaways
- Synced passkeys break the core promise of phishing-resistant, machine-bound authentication.
- A simple phishing site can steal every passkey from Chrome or Bitwarden.
- Use device-bound passkeys stored on USB tokens or dedicated apps.
About the Speaker(s)
Chad Spensky, Ph.D. described himself as a teenage hacker turned cybersecurity expert. He studied at UNC-CH and UCSB’s SecLab, worked at IBM Research, and was a lead researcher at MIT LL working on high-impact DoD projects. He has broken every authentication system under the sun and now builds decentralized authentication products.