Passkeys are usually considered one of the safest ways to log in to online accounts because they replace passwords with stronger encryption techniques. However, new research has found that under certain conditions, even passkey-protected accounts could be at risk. The third and most serious attack could extract a secret encryption key that protects synced passkeys. This can allow attackers to recover passkey credentials and use them on another device. The researchers found that these attacks do not break the cryptography behind passkeys. Instead, they exploit weaknesses in how Google Chrome, Google Password Manager and cloud synchronisation work together. Whihc is the most secure lock for private data ?

