A New Threat to Your Digital Identity
Passkeys have long been hailed as the silver bullet for phishing, relying on asymmetric cryptography to replace vulnerable, shared secrets like passwords. However, a dangerous new development has surfaced: a $10,000 phishing kit named iAuthFlow v2 that claims to exploit the very authentication flows meant to keep users safe.
Unlike traditional credential harvesting, this kit employs a 'browser-in-the-middle' (AitM) approach. It intercepts the authentication process in real-time, allowing attackers to register their own rogue passkeys to an account almost immediately after a victim authenticates. This grants the attacker a backdoor that remains active even if the user manages to reset their password.
How the Attack Works
The danger lies in how the kit manipulates the login ceremony. By inserting itself between the user and the legitimate service, the kit can trick the user into a flow where the attacker's device is registered as a trusted authenticator.
- Interception: The victim interacts with a malicious site that mimics a legitimate service.
- AitM Execution: The kit captures session data and authentication requests in real-time.
- Rogue Registration: Seconds after the user authenticates, the attacker’s device registers a new passkey to the account.
- Persistence: Because the attacker now holds a registered passkey, they maintain access regardless of future password resets.
Passkeys bind cryptographically to the legitimate domain, making phishing impossible. However, the efficacy of this security relies entirely on the integrity of the registration and authentication ceremony.
— Security Research Consensus
Why Traditional Defenses Are Struggling
Security experts have long noted that passkeys are not a total panacea if implementation is flawed. For instance, if an identity provider allows for 'MFA fallbacks'—such as SMS or email codes—attackers can manipulate the flow to bypass the stronger passkey requirement entirely. The iAuthFlow v2 kit highlights that as long as there is a 'weakest link' in the authentication chain, attackers will find a way to exploit it.
To mitigate these risks, IT and security teams are being urged to monitor for suspicious registration events. Alerting on authentication flows where a user has a passkey enrolled but opts for a weaker method can be a significant indicator of an active AitM attack.
