By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Marketing In Asia
  • Marketing
    • Viral
    • Expert Opinions
    • News & Trends
    • Research
    • Market Podcasts
    • Market Videos
    Marketing
    This category deals with best news and updates on marketing and branding news and events.
    Show More
    Top News
    Sangeeta Mudnal
    How conversational commerce benefits marketers
    5 months ago
    Andrew Monu, VP of Marketing, LinkedIn
    Marketing in Asia Presents an Exclusive Interview with Andrew Monu, VP of Marketing, LinkedIn
    5 months ago
    Ankita Thakur
    Marketing in Asia Presents an Exclusive Interview with Ankita Thakur, Group Head of Marketing, MoneyHero Group
    5 months ago
    Latest News
    Marketing in Asia Presents an Exclusive Interview with Cris Tan, Associate Director, Publisher Development (SEA)
    5 months ago
    Time for ASEAN to Rethink a Single Currency Amid Global Trade Tensions
    5 months ago
    Marketing in Asia Presents an Exclusive Interview with Carine Chin, Head of Corporate Marketing, Etiqa Insurance Singapore
    5 months ago
    Marketing in Asia Presents an Exclusive Interview with April Tayson, Regional VP INSEAU at Adjust
    5 months ago
  • Startup
    • News from Startup world
    • Startup Stories
    • Trends and Opinions
    • Startup Podcasts
    • Startup Videos
    Startup
    News and articles from startup and venture investment world
    Show More
    Top News
    Japan’s Evolving Booze Culture: A Market in Transformation
    Japan’s Evolving Booze Culture: A Market in Transformation
    1 year ago
    text
    Safe Space™ announces partnership with National Healthcare Group as it continues to boost employee support and wellbeing
    1 year ago
    Sakshi Kalani Founder & CEO of Savy Click and Jaipur Unfolded
    AI-Powered Analytics: Sakshi Kalani on Influencer Marketing in 2025
    1 year ago
    Latest News
    Byron J. Fernandez: Minimize the stress of business crises with strong CX
    10 months ago
    Vedant Mahajan Acquires Stake in Flite: Transforming Event Technology with Innovation
    10 months ago
    Navigating the Digital Economy and Tax Challenges for SMEs
    11 months ago
    sehatUP Launches India’s First Integrated Digital Health Clinic, Pioneering Holistic Healthcare
    12 months ago
  • Business
    • Feature Stories
    • News
    • Business Podcasts
    • Business Videos
    Business
    News and press releases from business world of Asia
    Show More
    Top News
    Asean countries
    Time for ASEAN to Rethink a Single Currency Amid Global Trade Tensions
    5 months ago
    Carine Chin
    Marketing in Asia Presents an Exclusive Interview with Carine Chin, Head of Corporate Marketing, Etiqa Insurance Singapore
    5 months ago
    April Tayson, Regional VP INSEAU at Adjust
    Marketing in Asia Presents an Exclusive Interview with April Tayson, Regional VP INSEAU at Adjust
    5 months ago
    Latest News
    Exclusive Interview : Marketing In Asia with April Tayson
    2 weeks ago
    Exclusive Interview: Adeline Lim, CMO & Head of Commercial Excellence at Menarini Asia-Pacific, Shares Insights with Marketing in Asia
    4 weeks ago
    Exclusive Interview: Twilio’s Sam Richardson Talks Brand Communications with Marketing in Asia
    2 months ago
    Marketing in Asia Presents an Exclusive Interview with Cris Tan, Associate Director, Publisher Development (SEA)
    5 months ago
  • Society
    • Inspiration
    • Destinations & Travel
    • Food & Gourmet
    • People
    • Young Voices
    • Society Videos
    • Society Podcasts
    Society
    News and articles from and for societies around us
    Show More
    Top News
    Smashers Sports Acquires Delhi Franchise of WPBL: A Game-Changer in India’s Sports Entertainment
    Smashers Sports Acquires Delhi Franchise of WPBL: A Game-Changer in India’s Sports Entertainment
    10 months ago
    Resorts World Cruises Sets Sail from Dubai with New Luxury Gulf Voyages
    Resorts World Cruises Sets Sail from Dubai with New Luxury Gulf Voyages
    12 months ago
    Australia luxury property
    Australia’s Luxury Real Estate Market Soars as Affluent Buyers Seek Waterfront Dreams
    12 months ago
    Latest News
    From Taboo to Triumph: How Malaysians Are Transforming Their Intimate Health Journey
    7 months ago
    Top 5 Misconceptions About Antibiotics Malaysians Need to Stop Believing
    7 months ago
    Eagle Eye Reveals Impact of Loyalty Programs on APAC Retailers
    7 months ago
    Elevate Your Haircare in 2025 with Jung Beauty’s Luxurious Camellia Edition Treatment
    10 months ago
  • Press Release
  • Awards
    • MIA Impact Circle Stellar CxO 2023 Malaysia
    • MIA Impact Circle Stellar CxO 2023 India
    • MIA Impact Circle Stellar CxO 2023 Philippines
    • Australian Women in Business Excellence Awards
    • MIA Impact Circle Stellar CxO 2024 Singapore
    • Mia Impact Circle Stellar Cxo 2024 Hongkong Award 
    • Mia Impact Circle Stellar Cxo 2024 Indonesia Award 
Search
Technology
  • Hot
  • Trending
  • Editor’s Choice
  • NSFW
  • Reactions
  • Authors
  • Viral on Internet
Other Pages
  • My Bookmarks
  • Customize Interests
  • About Marketing In Asia
  • Business Register & Login
  • Web Stories
  • Videos
  • Disclaimer
  • Terms of Service
  • Privacy Policy
© 2024 Marketing In Asia Sdn Bhd. All Rights Reserved.
Reading: Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33
Share
Sign In
Notification Show More
Latest News
Midnight In The War room
Semperis Announces Midnight in the War Room
Press Release
Google Cloud
Google Cloud Unveils Gemini Enterprise, the Industry’s Most Comprehensive Agentic AI Platform and New Front Door for AI Agents in the Workplace
Press Release
SquareX
SquareX Research Shows AI Browsers Falling Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution
Press Release
Mastercard
Marketing in Asia interview with Johann Suchon, Senior Vice President, Loyalty Solutions, Asia Pacific at Mastercard APAC Brands Must Rewire Loyalty for a Real-Time Economy
Press Release
coursera
Coursera App in ChatGPT Goes Live in Malaysia, Bringing Trusted Learning into Everyday Conversation 
Press Release
Aa
Marketing In Asia
Aa
  • Hot
  • Trending
  • Editor’s Choice
  • NSFW
  • Reactions
  • Authors
  • Viral on Internet
  • My Bookmarks
  • Customize Interests
  • About Marketing In Asia
  • Business Register & Login
  • Startup Register & Login
Search
  • Marketing
    • Viral
    • Expert Opinions
    • News & Trends
    • Research
    • Market Podcasts
    • Market Videos
  • Startup
    • News from Startup world
    • Startup Stories
    • Trends and Opinions
    • Startup Podcasts
    • Startup Videos
  • Business
    • Feature Stories
    • News
    • Business Podcasts
    • Business Videos
  • Society
    • Inspiration
    • Destinations & Travel
    • Food & Gourmet
    • People
    • Young Voices
    • Society Videos
    • Society Podcasts
  • Press Release
  • Awards
    • MIA Impact Circle Stellar CxO 2023 Malaysia
    • MIA Impact Circle Stellar CxO 2023 India
    • MIA Impact Circle Stellar CxO 2023 Philippines
    • Australian Women in Business Excellence Awards
    • MIA Impact Circle Stellar CxO 2024 Singapore
    • Mia Impact Circle Stellar Cxo 2024 Hongkong Award 
    • Mia Impact Circle Stellar Cxo 2024 Indonesia Award 
Have an existing account? Sign In
Follow US
© 2023 Marketing In Asia Sdn Bhd. All Rights Reserved.
Marketing In Asia > Blog > Press Release > Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33
Press Release

Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33

profile
Last updated: 2025/08/29 at 4:22 PM
MIA Editor
Share
4 Min Read
SquareX
SHARE

t is no secret that passwords are highly susceptible to phishing and brute force attacks. This led to the mass adoption of passkeys, a passwordless authentication method leveraging cryptographic key pairs that allows users to log in with biometrics or a hardware key. According to FIDO, over 15 billion accounts have been passkey-enabled, with 69% of users globally enabling passkeys in at least one account. The passkey promise is simple – eliminate passwords, eliminate vulnerabilities. Yet, SquareX researchers Shourya Pratap Singh, Daniel Seetoh and Jonathan Lin disclosed a major passkey vulnerability at DEF CON 33 main stage that puts major banking, shopping and enterprise SaaS app accounts at risk. 

Passkeys work by using a pair of cryptographic keys instead of a password. The private key is securely stored on the user’s device, while the public key is stored on the website’s server. When logging in, the user authenticates locally with their biometrics, local hardware key or a PIN to access the private key. The website then verifies this signature with the matching public key to authenticate access.  This design strengthens security by tying authentication to a pre-registered device and website, eliminating the risks of stolen, reused, or weak passwords. 

Critically, all communication between the server and the user’s device is relayed through the browser. In other words, passkeys work under the assumption that the browser is “honest”. SquareX researchers demonstrated that through relatively trivial scripts and malicious browser extensions, attackers can intercept and forge the passkey registration process, allowing them to access accounts without the real device or biometrics. Even with registered passkeys, attackers can cause the passkey login to fail, forcing users to re-register their passkeys under an attacker controlled environment. 

“Passkeys are a highly trusted form of authentication, so when users see a biometric prompt, they take that as a signal for security,” says SquareX researcher Shourya Pratap Singh, “What they don’t know is that attackers can easily fake passkey registrations and authentication by intercepting the passkey workflow in the browser. This puts pretty much every enterprise and consumer application, including critical banking and data storage apps at risk.” 

Unfortunately, traditional security tools like EDR and SASE/SSE lack the necessary visibility in the browser to detect passkey exploits. From a user perspective, the attack is identical to a legitimate passkey workflow. In other words, there is zero visual indicator or network signal that can verify the legitimacy of the authentication service and/or request. Thus, the only way to prevent the exploit is to monitor and block any malicious scripts and extensions directly in the browser. 

With over 80% of enterprise data now residing in SaaS applications, passkeys are emerging as the dominant authentication method for accessing these platforms. SquareX’s research demonstrated that browsers represent the vulnerable point in passkey security and provide the grounds for multiple attack vectors that malicious actors can leverage to exploit passkeys. Vivek Ramachandran, the Founder of SquareX shares “SquareX has been actively researching new ways attackers exploit employees in the browser. Without a browser security layer, passkeys in isolation can be easily hijacked by attackers to gain unauthorized access to enterprise SaaS apps, where critical data is stored. This underscores the urgent need for Browser Detection and Response, an “EDR in the browser”, which SquareX has been pioneering.” 

As passkeys establish themselves as the authentication gold standard, enterprises must ensure robust security measures are in place to protect the environment where users and passkeys primarily operate – the browser. 

Legal Disclaimer: The Editor provides this news content "as is," without any warranty of any kind. We disclaim all responsibility and liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. For any complaints or copyright concerns regarding this article, please contact the author mentioned above.

You Might Also Like

Semperis Announces Midnight in the War Room

Google Cloud Unveils Gemini Enterprise, the Industry’s Most Comprehensive Agentic AI Platform and New Front Door for AI Agents in the Workplace

SquareX Research Shows AI Browsers Falling Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution

Marketing in Asia interview with Johann Suchon, Senior Vice President, Loyalty Solutions, Asia Pacific at Mastercard APAC Brands Must Rewire Loyalty for a Real-Time Economy

Coursera App in ChatGPT Goes Live in Malaysia, Bringing Trusted Learning into Everyday Conversation 

MIA
Get Latest Job Updates on Whatsapp and Telegram
SCIKEY Logo
Whatsapp
Telegram
TAGGED: California, insight, strategy

Sign Up For MIA Newsletter

Be keep up! Get the latest updates about the Marketing world delivered straight to your inbox.

    By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
    MIA Editor August 29, 2025 August 29, 2025
    Share This Article
    Facebook Twitter LinkedIn Email Copy Link Print
    Share
    What do you think?
    Love0
    Happy0
    Joy0
    Surprise0
    Sad0
    Angry0
    Cry0
    Previous Article Samsung Samsung Celebrates 40 Years of Appliance Innovation at IFA 2025 
    Next Article McLaren Fans to be given unparalleled access as McLaren Racing announces Mastercard as Official Naming Partner of the McLaren Formula 1 Team from 2026
    9.5k Followers Follow
    3.4k Followers Like
    1.1k Followers Follow
    214 Followers Follow
    208 Subscribers Subscribe

    Latest News

    Midnight In The War room
    Semperis Announces Midnight in the War Room
    Press Release 3 days ago
    Google Cloud
    Google Cloud Unveils Gemini Enterprise, the Industry’s Most Comprehensive Agentic AI Platform and New Front Door for AI Agents in the Workplace
    Press Release 2 weeks ago
    SquareX
    SquareX Research Shows AI Browsers Falling Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution
    Press Release 2 weeks ago
    Mastercard
    Marketing in Asia interview with Johann Suchon, Senior Vice President, Loyalty Solutions, Asia Pacific at Mastercard APAC Brands Must Rewire Loyalty for a Real-Time Economy
    Press Release 2 weeks ago

    PropertyGuru

    property guru

    You Might also Like

    Midnight In The War room
    Press Release

    Semperis Announces Midnight in the War Room

    3 days ago
    Google Cloud
    Press Release

    Google Cloud Unveils Gemini Enterprise, the Industry’s Most Comprehensive Agentic AI Platform and New Front Door for AI Agents in the Workplace

    2 weeks ago
    SquareX
    Press Release

    SquareX Research Shows AI Browsers Falling Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution

    2 weeks ago
    Mastercard
    Press Release

    Marketing in Asia interview with Johann Suchon, Senior Vice President, Loyalty Solutions, Asia Pacific at Mastercard APAC Brands Must Rewire Loyalty for a Real-Time Economy

    2 weeks ago
    //

    Get Asia to Notice You

    Quick Link

    • Contact
    • RSS Terms of Service
    • Policies & Standards
    • About Us
    • FAQ
    • Disclaimer
    • Terms Of Service
    • Privacy Policy

    Top Categories

    • Marketing
    • Startup
    • Feature Stories
    • News
    • People
    • Inspiration

    Sign Up for Our Newsletter

    Subscribe to our newsletter to get our newest articles instantly!

      Marketing In AsiaMarketing In Asia
      Follow US
      © 2024 Marketing In Asia. All Rights Reserved.
      • Disclaimer
      • Terms of Service
      • Privacy Policy