Passkeys were introduced as a safer alternative to traditional passwords, designed to resist phishing, credential theft and password reuse. Yet new research from Cornell University suggests that the technology may create a serious and underexamined vulnerability for people experiencing intimate partner abuse. If an abusive partner gains access to a victim’s computer and account password, that person may be able to register a passkey of their own, creating a persistent route into private online accounts that can be difficult for the victim to detect or remove.
The finding comes from a laboratory study in which researchers examined how participants with varied levels of technical experience responded to an attacker-controlled passkey. The team wanted to understand whether ordinary users could recognize that an unauthorized authentication method had been added to their account and whether they could successfully regain control. The results, according to the researchers, “paint a grim picture” of users’ ability to identify and resolve this type of compromise without outside help.
Passkeys are based on public-key cryptography rather than a shared secret. When a user creates one, a private cryptographic key is stored on a device or within an approved password manager, while the associated public key is registered with an online service. During login, the device proves possession of the private key without transmitting it to the website. The process is typically unlocked through a fingerprint, facial recognition, device PIN or another local method, meaning that a website does not receive or store a conventional password that could later be stolen.
That design can provide strong protection against common attacks, but it does not eliminate the danger posed by someone who already has access to a trusted device or account credentials. An abusive partner who can unlock a computer, learn the account password or otherwise enter an account may be able to create a new passkey under their own control. Once registered, the passkey can allow the attacker to authenticate again in the future, potentially without knowing the victim’s current password. The technical strength of the passkey itself does not reveal who originally added it or whether the person using it is acting with the account holder’s consent.
The Cornell researchers tested this problem through account security interfaces, or ASIs—the screens and controls that allow users to inspect login activity, manage authentication methods and recover compromised accounts. Participants interacted with passkey systems offered by three different services. Most could not determine which login originated from the attacker’s device. Many also struggled to remove the unauthorized passkey, change the account password and sign out other active devices as a coordinated response to the intrusion.
The study also exposed the limits of security notifications as a defense. Some participants noticed or questioned emails warning them about unusual account activity, but others regarded the messages with suspicion or did not understand what the notifications were communicating. Online security alerts often compress complex technical events into brief explanations, leaving users to interpret unfamiliar terms such as passkey, device session, authentication method or security key. In an abusive relationship, where an attacker may monitor communications or react quickly to account changes, confusion can carry consequences beyond ordinary inconvenience.
The passkey management interfaces themselves were difficult for participants to follow across all three services examined. Users were not always sure how many passkeys existed, which devices they belonged to or whether deleting one would actually block the attacker. The researchers argue that an account owner should be able to answer basic questions immediately: Which authentication methods are active? When and where were they created? What devices can still access the account? Which action will remove an intruder completely? In the tested systems, those answers were not consistently clear.
“Our conclusion is that services need to do a lot of work to enable users to diagnose compromises to their account, and remediate any account compromise that could occur,” said Alaa Daffalla, a doctoral student in computer science at Cornell and lead author of the study, titled “‘Maybe There’s Only One Passkey?’: Challenges Investigating and Remediating Adversarial Passkeys.” The research is being presented at the 35th USENIX Security Symposium in Baltimore. Daffalla joined the laboratory in 2022 and has focused on the design and usability of account security interfaces.
The work grew out of Cornell’s Clinic to End Tech Abuse, or CETA, which was co-founded in 2018 by Nicola Dell, an associate professor of information science at Cornell, and Thomas Ristenpart, a professor of computer science at the University of Toronto. CETA supports survivors of intimate partner violence and has helped researchers understand how seemingly helpful technologies can be misused by someone with physical proximity, coercive control or access to a victim’s devices. The new study applies those concerns to an authentication technology increasingly promoted as the future of secure login.
“Understanding the security of online accounts, including emerging authentication mechanisms like passkeys, is essential for digital safety, not only for abuse survivors but for all technology users,” Dell said. The researchers emphasize that the problem is not necessarily that passkeys are cryptographically weak. Instead, the danger arises from the surrounding account-management experience: the ability to add an authentication method, the visibility of existing methods and the tools available when an account has already been compromised. Without effective recovery controls, a system designed to prevent remote credential theft may still provide an attacker with durable access after a brief opportunity to use the victim’s device.
The findings point to a need for services to treat passkey enrollment and removal as high-risk account events. Users may need clearer records showing when each passkey was created, the device or account that controls it and the last time it was used. Recovery workflows should make it possible to revoke suspicious passkeys, invalidate active sessions, change passwords and review other security settings from a single, understandable process. Those measures could benefit anyone whose device or account has been accessed by another person, but they may be particularly important for people facing stalking, surveillance or intimate partner abuse, for whom an invisible authentication method can become a tool of continued intrusion. The research was supported in part by grants from the National Science Foundation and by a Google Cyber Award.
Subject of Research: Passkey security, account compromise and digital safety for people experiencing intimate partner abuse
Article Title: “‘Maybe There’s Only One Passkey?’: Challenges Investigating and Remediating Adversarial Passkeys”
News Publication Date: August 13, 2026
Web References: USENIX Security Symposium study page; Cornell Chronicle story; Clinic to End Tech Abuse
References: National Science Foundation grants; Google Cyber Award
Keywords
Passkeys, cybersecurity, account security, public-key cryptography, intimate partner abuse, digital privacy, authentication, online safety, Cornell University, USENIX Security Symposium

