Thursday, August 13, 2026
Science
No Result
View All Result
  • Login
  • HOME
  • SCIENCE NEWS
  • CONTACT US
  • HOME
  • SCIENCE NEWS
  • CONTACT US
No Result
View All Result
Scienmag
No Result
View All Result
Home Science News Space

Study questions passkey safety for people experiencing intimate partner abuse

August 13, 2026
in Space
Reading Time: 4 mins read
0
Study questions passkey safety for people experiencing intimate partner abuse

Study questions passkey safety for people experiencing intimate partner abuse

65
SHARES
587
VIEWS
Share on FacebookShare on Twitter
ADVERTISEMENT

Passkeys were introduced as a safer alternative to traditional passwords, designed to resist phishing, credential theft and password reuse. Yet new research from Cornell University suggests that the technology may create a serious and underexamined vulnerability for people experiencing intimate partner abuse. If an abusive partner gains access to a victim’s computer and account password, that person may be able to register a passkey of their own, creating a persistent route into private online accounts that can be difficult for the victim to detect or remove.

The finding comes from a laboratory study in which researchers examined how participants with varied levels of technical experience responded to an attacker-controlled passkey. The team wanted to understand whether ordinary users could recognize that an unauthorized authentication method had been added to their account and whether they could successfully regain control. The results, according to the researchers, “paint a grim picture” of users’ ability to identify and resolve this type of compromise without outside help.

Passkeys are based on public-key cryptography rather than a shared secret. When a user creates one, a private cryptographic key is stored on a device or within an approved password manager, while the associated public key is registered with an online service. During login, the device proves possession of the private key without transmitting it to the website. The process is typically unlocked through a fingerprint, facial recognition, device PIN or another local method, meaning that a website does not receive or store a conventional password that could later be stolen.

That design can provide strong protection against common attacks, but it does not eliminate the danger posed by someone who already has access to a trusted device or account credentials. An abusive partner who can unlock a computer, learn the account password or otherwise enter an account may be able to create a new passkey under their own control. Once registered, the passkey can allow the attacker to authenticate again in the future, potentially without knowing the victim’s current password. The technical strength of the passkey itself does not reveal who originally added it or whether the person using it is acting with the account holder’s consent.

The Cornell researchers tested this problem through account security interfaces, or ASIs—the screens and controls that allow users to inspect login activity, manage authentication methods and recover compromised accounts. Participants interacted with passkey systems offered by three different services. Most could not determine which login originated from the attacker’s device. Many also struggled to remove the unauthorized passkey, change the account password and sign out other active devices as a coordinated response to the intrusion.

The study also exposed the limits of security notifications as a defense. Some participants noticed or questioned emails warning them about unusual account activity, but others regarded the messages with suspicion or did not understand what the notifications were communicating. Online security alerts often compress complex technical events into brief explanations, leaving users to interpret unfamiliar terms such as passkey, device session, authentication method or security key. In an abusive relationship, where an attacker may monitor communications or react quickly to account changes, confusion can carry consequences beyond ordinary inconvenience.

The passkey management interfaces themselves were difficult for participants to follow across all three services examined. Users were not always sure how many passkeys existed, which devices they belonged to or whether deleting one would actually block the attacker. The researchers argue that an account owner should be able to answer basic questions immediately: Which authentication methods are active? When and where were they created? What devices can still access the account? Which action will remove an intruder completely? In the tested systems, those answers were not consistently clear.

“Our conclusion is that services need to do a lot of work to enable users to diagnose compromises to their account, and remediate any account compromise that could occur,” said Alaa Daffalla, a doctoral student in computer science at Cornell and lead author of the study, titled “‘Maybe There’s Only One Passkey?’: Challenges Investigating and Remediating Adversarial Passkeys.” The research is being presented at the 35th USENIX Security Symposium in Baltimore. Daffalla joined the laboratory in 2022 and has focused on the design and usability of account security interfaces.

The work grew out of Cornell’s Clinic to End Tech Abuse, or CETA, which was co-founded in 2018 by Nicola Dell, an associate professor of information science at Cornell, and Thomas Ristenpart, a professor of computer science at the University of Toronto. CETA supports survivors of intimate partner violence and has helped researchers understand how seemingly helpful technologies can be misused by someone with physical proximity, coercive control or access to a victim’s devices. The new study applies those concerns to an authentication technology increasingly promoted as the future of secure login.

“Understanding the security of online accounts, including emerging authentication mechanisms like passkeys, is essential for digital safety, not only for abuse survivors but for all technology users,” Dell said. The researchers emphasize that the problem is not necessarily that passkeys are cryptographically weak. Instead, the danger arises from the surrounding account-management experience: the ability to add an authentication method, the visibility of existing methods and the tools available when an account has already been compromised. Without effective recovery controls, a system designed to prevent remote credential theft may still provide an attacker with durable access after a brief opportunity to use the victim’s device.

The findings point to a need for services to treat passkey enrollment and removal as high-risk account events. Users may need clearer records showing when each passkey was created, the device or account that controls it and the last time it was used. Recovery workflows should make it possible to revoke suspicious passkeys, invalidate active sessions, change passwords and review other security settings from a single, understandable process. Those measures could benefit anyone whose device or account has been accessed by another person, but they may be particularly important for people facing stalking, surveillance or intimate partner abuse, for whom an invisible authentication method can become a tool of continued intrusion. The research was supported in part by grants from the National Science Foundation and by a Google Cyber Award.

Subject of Research: Passkey security, account compromise and digital safety for people experiencing intimate partner abuse

Article Title: “‘Maybe There’s Only One Passkey?’: Challenges Investigating and Remediating Adversarial Passkeys”

News Publication Date: August 13, 2026

Web References: USENIX Security Symposium study page; Cornell Chronicle story; Clinic to End Tech Abuse

References: National Science Foundation grants; Google Cyber Award

Keywords

Passkeys, cybersecurity, account security, public-key cryptography, intimate partner abuse, digital privacy, authentication, online safety, Cornell University, USENIX Security Symposium

Tags: account takeover preventiondigital abuse and cybersecuritydigital security for domestic abuse survivorsintimate partner abuseonline account protection for abuse victimsonline privacy and safety in abusive relationshipspasskey security vulnerabilitiespasswordless authentication risksphishing-resistant authentication riskspublic-key cryptography security concernstechnology safety for abuse victimsuser recognition of unauthorized account access
Share26Tweet16
Previous Post

Survey reveals what people really think about generative AI

Next Post

Sulfur Redox Reactions Occur Spontaneously in Atmospheric Water Microdroplets

Related Posts

Jupiter’s Polar Regions Release H₃⁺ Ions Into Space
Space

Jupiter’s Polar Regions Release H₃⁺ Ions Into Space

August 13, 2026
Astronomers Discover First Black Hole Star, a New Astrophysical Object
Space

Astronomers Discover First Black Hole Star, a New Astrophysical Object

August 13, 2026
NMSU Team Finds Supermassive Black Holes May Forge Giant Planets
Space

NMSU Team Finds Supermassive Black Holes May Forge Giant Planets

August 12, 2026
JWST finds earliest black hole star at cosmic dawn—mirage or miracle?
Space

JWST finds earliest black hole star at cosmic dawn—mirage or miracle?

August 12, 2026
Unusual Galaxy Breakthrough Could Help Solve Dark Matter Mystery
Space

Unusual Galaxy Breakthrough Could Help Solve Dark Matter Mystery

August 12, 2026
Study warns extreme space weather may disrupt flights, expose passengers to radiation
Space

Study warns extreme space weather may disrupt flights, expose passengers to radiation

August 12, 2026
Next Post
Sulfur Redox Reactions Occur Spontaneously in Atmospheric Water Microdroplets

Sulfur Redox Reactions Occur Spontaneously in Atmospheric Water Microdroplets

  • Mothers who receive childcare support from maternal grandparents show more

    Mothers who receive childcare support from maternal grandparents show more parental warmth, finds NTU Singapore study

    27656 shares
    Share 11059 Tweet 6912
  • University of Seville Breaks 120-Year-Old Mystery, Revises a Key Einstein Concept

    1061 shares
    Share 424 Tweet 265
  • Bee body mass, pathogens and local climate influence heat tolerance

    682 shares
    Share 273 Tweet 171
  • Researchers record first-ever images and data of a shark experiencing a boat strike

    546 shares
    Share 218 Tweet 137
  • Groundbreaking Clinical Trial Reveals Lubiprostone Enhances Kidney Function

    531 shares
    Share 212 Tweet 133
Science

Embark on a thrilling journey of discovery with Scienmag.com—your ultimate source for cutting-edge breakthroughs. Immerse yourself in a world where curiosity knows no limits and tomorrow’s possibilities become today’s reality!

RECENT NEWS

  • Excess Copper Impairs Hippocampal Function in Depression, Clinical and Animal Study Finds
  • Iron-driven lignin demethoxylation may generate environmental methanol and oxidation products
  • AAT/SERPINA1 Pi*Z Variant Influences Gestation; AAT Prevents Preterm Birth in Mice
  • High Capital Costs Limit Renewable Energy’s Global Climate Mitigation Impact

Categories

  • Agriculture
  • Anthropology
  • Archaeology
  • Athmospheric
  • Biology
  • Biotechnology
  • Blog
  • Bussines
  • Cancer
  • Chemistry
  • Climate
  • Earth Science
  • Editorial Policy
  • Marine
  • Mathematics
  • Medicine
  • Pediatry
  • Policy
  • Psychology & Psychiatry
  • Science Education
  • Social Science
  • Space
  • Technology and Engineering

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 5,149 other subscribers

© 2025 Scienmag - Science Magazine

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • SCIENCE NEWS
  • CONTACT US

© 2025 Scienmag - Science Magazine

Discover more from Science

Subscribe now to keep reading and get access to the full archive.

Continue reading