
DEF CON 33 - Your Passkey is Weak: Phishing the Unphishable - Chad Spensky, Ph D
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 24:13
Synced passkeys create a false sense of security while actually increasing vulnerability to attacks 2:51-4:27. The speaker demonstrates how simple phishing attacks can steal passkeys from Chrome and Bitwarden password managers 5:25-7:04, allowing attackers to bypass security measures completely.
Key Takeaways:
• Phishing attacks can steal synced passkeys by tricking users into logging into fake sites that emulate browser logins 5:25-7:04
• Stolen passkeys are more dangerous than passwords because websites won't require additional authentication 10:21-11:03
• Device-bound passkeys that never leave the hardware are the truly secure alternative 15:00-16:11
Users should avoid synced passkeys and instead use device-bound alternatives that provide genuine phishing resistance 17:09-19:02.
Sources:
- 0:00-0:32 Introduction about the importance of security
- 2:51-4:27 Discussion of how synced passkeys represent a bait-and-switch
- 5:25-7:04 Explanation of the phishing attack against passkeys
- 10:21-11:03 Demonstration of the Bitwarden attack
- 15:00-16:11 Explanation of device-bound passkeys as the solution
- 17:09-19:02 Call to action for users to control their keys
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, let's fish some pass keys, Y'ALL. [Applause] >> I'm a short man. Bunch of other folks help me out with this. Uh, smarter, better hackers than me, but I get to come up and present it to you. So, I'll do my best to to do them justice. My core beliefs, I just want to get this out there first. Why I give these talks, why I think Defcon is important. I think it's critical that you understand the risk of the things that you're using so you can make good decisions. And I truly believe that everybody deserves to be secure on the internet even if you're not a cyber security expert. So that is the main motivation for this talk. Fishing has killed the password star. I don't know what you've heard about passwords. You can salt them. You can put them in databases. You can make them 5 million…