Three separate teams found ways around passkeys — and one of them recovers the private key
2026-08-12Security
Black Hat and the weeks around it produced three unrelated results against phishing-resistant authentication: replayable signatures in Windows event logs, a master key pulled from Chrome's memory, and Windows Hello keys used without a PIN prompt.