A researcher discovered that passkeys can be bypassed through a technique called Authentication Method Redaction Attacks, which removes phishing-resistant options from authentication menus. This matters because fewer than 5% of organizations enforce phishing-resistant policies alongside passkey deployments, leaving most vulnerable to attacks exploiting weaker fallback methods like SMS or TOTP.
Read the full article at InfoSec Write-ups - Medium
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



