
DEF CON 33 - Passkeys Pwned:Turning WebAuthn Against Itself - S Pratap Singh, J Lin, D Seetoh
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 33:40
This talk reveals critical security vulnerabilities in passkeys that could compromise authentication systems 0:15.
Key Takeaways:
• Passkeys are being widely adopted due to phishing protection, non-guessability, and reduced impact of data breaches, but lack decades of security research that passwords have undergone 1:33-3:41
• The WebAuthn flow creates a new attack surface where the browser acts as a trust anchor between the authenticator and server, making it an attractive target 11:39-12:03
• Researchers demonstrated how a malicious browser extension can hook into the credentials API, intercept passkey registration, and forge authentication responses without user biometrics 12:19-14:03
• The attack works silently across devices, with the extension even displaying normal biometric prompts while using the attacker's stored credentials 20:00-21:41
• Mitigation strategies include proper CSP policies, thorough verification processes, preventing XSS attacks, and being vigilant about browser extension permissions 27:22-33:35
The browser has effectively become the new operating system, requiring the same security controls we traditionally applied to local applications.
Sources:
- 0:15 Introduction to the topic of passkey vulnerabilities
- 1:33-3:41 Why companies are pushing passkeys and their advantages
- 11:39-12:03 How the browser becomes the trust anchor in passkey authentication
- 12:19-14:03 Explanation of the browser extension atta
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hello all and welcome to day four at Defcon. Thank you for joining to our talk. Uh we're going to talk about pass keys. Uh as you can see it's pass spawn turning web auton against itself. So a little bit about ourselves. So I'm Shia. I work as a principal software engineer at Square. Uh this is my second year at Defcon and uh second mainstage talk. So happy to be back here. Uh yeah. >> Hello everyone. I'm Johnny. I'm a front-end engineer at Square and researcher and this is my first time at Defcon. So really uh excited to see all of you here. >> Hi everyone, my name is Daniel. Uh I work as a senior front end engineer at Square X. Um this is also my first Devcon so really happy to be here. [Applause] >> Okay. So uh so so we are part of a browser security company and as part of our work we h…