BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Beyond the Ceremony: The 2026 Passkey Attack Surface
 \n   Tags: DEF CON Official Talk | Demo ðŸ’» | Tool ðŸ› \n   When: Sunday\
 , Aug 9\, 11:00 - 11:59 PDT\n   Where: LVCCW Level 1 Hall 3 1007 (Main Tra
 ck 2) and DCTV-2 - [1]Map\n\n   Description:\n\n   Passkeys are marketed a
 s phishing-resistant\, and the WebAuthn ceremony\n   at their center genui
 nely is. The catch: almost nobody runs only the\n   ceremony. Roughly five
  billion passkeys are in active use (FIDO\,\n   2026)\, yet only about a t
 hird of organizations use them as the primary\n   sign-in\, so a passkey a
 lmost always sits next to a weaker method. The\n   cryptography covers onl
 y the ceremony\, but the login rides on many\n   moving parts\, from the m
 etal to the cloud: authenticator\, cross-device\n   transport\, client\, r
 elying party\, cloud sync\, and the human who\n   recovers the account. Th
 at is where it breaks\, more often than the\n   reputation suggests: in a 
 recent audit\, all 103 live relying parties\n   tested were vulnerable to 
 at least one server-side attack.\n\n   This talk pulls the scattered resea
 rch into one pass over all of them\,\n   one attack per stop that survives
  a correct ceremony\, shown in action\,\n   heaviest on the relying party 
 where engagements land\, with a suggested\n   testing order and the source
 s to go deeper. You also get Passkey\n   Editor\, a Burp extension that de
 codes and re-encodes the vendor\n   wrappers that make this traffic unread
 able\, ships preset\n   ceremony-layer attacks\, and lets you craft any re
 lying-party\n   manipulation by hand in intercept and Repeater.\n\n   Walk
  away knowing where passkey deployments break\, with a tool to test\n   th
 em.\n\n   A curated\, non-exhaustive list of the key references behind thi
 s talk.\n\n   Cultural anchor\n\n     * Nishant Kaushik (CTO\, FIDO Allian
 ce)\, Passkeys Are Not Broken. The\n       Conversation About Them Often I
 s\n       (https://fidoalliance.org/passkeys-are-not-broken-the-conversati
 on-about-them-often-is/)\,\n       September 2\, 2025.\n\n   Specification
 s\n\n     * W3C Web Authentication Working Group\, Web Authentication\n   
     (WebAuthn) Level 3 (https://www.w3.org/TR/webauthn-3/)\; Level 2\n    
    Recommendation (https://www.w3.org/TR/webauthn-2/).\n\n     * FIDO Alli
 ance\, Credential Exchange Format (CXF) and Credential\n       Exchange Pr
 otocol (CXP)\, Working Drafts\n       (https://fidoalliance.org/specs/cx/c
 xp-v1.0-wd-20241003.html)\,\n       2024.\n\n   Academic\n\n     * Louis J
 annett\, Andreas Mayer\, Maximilian Westers\, Vladislav\n       Mladenov\,
  Christian Mainka\, Jorg Schwenk\, The State of Passkeys:\n       Studying
  the Adoption and Security of Passkeys on the Web\n       (https://www.use
 nix.org/conference/usenixsecurity26/presentation/jannett)\,\n       USENIX
  Security 2026.\n\n     * Alaa Daffalla et al.\, A Framework for Abusabili
 ty Analysis: The\n       Case of Passkeys in Interpersonal Threat Models\n
        (https://www.usenix.org/conference/usenixsecurity25/presentation/da
 ffalla)\,\n       USENIX Security 2025.\n\n     * Prince Bhardwaj and Nish
 anth Sastry (University of Surrey)\, State\n       of Passkey Authenticati
 on in the Wild: A Census of the Top 100K\n       Sites (https://arxiv.org/
 abs/2602.15135)\, PAM 2026 (Springer LNCS\n       16477).\n\n     * Jenny 
 Blessing\, Daniel Hugenroth\, Ross J. Anderson\, Alastair R.\n       Beres
 ford (University of Cambridge)\, SoK: Web Authentication and\n       Recov
 ery in the Age of End-to-End Encryption\n       (https://doi.org/10.56553/
 popets-2025-0113)\, PoPETs 2025(3).\n\n     * Matteo Scarlata\, Giovanni T
 orrisi\, Matilda Backendal\, Kenneth G.\n       Paterson (ETH Zurich / USI
 )\, Zero Knowledge (About) Encryption: A\n       Comparative Security Anal
 ysis of Three Cloud-based Password\n       Managers (https://zkae.io/)\, U
 SENIX Security 2026 (IACR ePrint\n       2026/058).\n\n     * Mazharul Isl
 am\, Sunpreet S. Arora\, Rahul Chatterjee\, Ke Coby Wang\,\n       CASPER:
  Detecting Compromise of Passkey Storage on the Cloud\n       (https://www
 .usenix.org/conference/usenixsecurity25/presentation/islam)\,\n       USEN
 IX Security 2025.\n\n     * Kemal Bicakci\, Fatih Mehmet Varli\, Muhammet 
 Emir Korkmaz\, Yusuf\n       Uzunay\, QES-Backed Virtual FIDO2 Authenticat
 ors\n       (https://arxiv.org/abs/2601.06554)\, arXiv:2601.06554\, Januar
 y\n       2026.\n\n     * Christian Catalano\, Andrea Chezzi\, Vita Santa 
 Barletta\, Franco\n       Tommasi\, Defeating FIDO2/CTAP2/WebAuthn using\n
        Browser-in-the-Middle and reflected XSS\n       (https://link.sprin
 ger.com/article/10.1007/s11416-025-00556-2)\,\n       Journal of Computer 
 Virology and Hacking Techniques 2025.\n\n     * Marco Squarcina\, Mauro Te
 mpesta\, Lorenzo Veronese\, Stefano\n       Calzavara\, Matteo Maffei\, Ca
 n I Take Your Subdomain? Exploring\n       Same-Site Attacks in the Modern
  Web\n       (https://www.usenix.org/conference/usenixsecurity21/presentat
 ion/squarcina)\,\n       USENIX Security 2021.\n\n     * Marco Casagrande\
 , Daniele Antonioli\, CTRAPS: CTAP Client\n       Impersonation and API Co
 nfusion on FIDO2\n       (https://arxiv.org/abs/2412.02349)\, arXiv:2412.0
 2349\, 2024.\n\n     * Peizhou Chen\, Vulnerability Testing for WebAuthn (
 MSc thesis\,\n       University of Twente\; companion Burp_FIDO2 extension
 )\n       (https://essay.utwente.nl/98532/)\, 2024.\n\n   Government guida
 nce\n\n     * UK National Cyber Security Centre (NCSC)\, Comparing the sec
 urity\n       properties of traditional user credentials and FIDO2 credent
 ials\n       for personal use\n       (https://www.ncsc.gov.uk/paper/tradi
 tional-user-and-fido2-credentials-personal-use)\,\n       2026.\n\n   Indu
 stry data and reports\n\n     * FIDO Alliance\, The State of Passkeys 2026
 : Global Consumer and\n       Workforce Report\n       (https://fidoallian
 ce.org/the-state-of-passkeys-2026-global-consumer-and-workforce-report/)\,
 \n       May 7\, 2026.\n\n     * FIDO Alliance\, World Passkey Day 2025 / 
 Passkey Pledge (over 1\n       billion people have activated a passkey\; 1
 5 billion accounts\n       support passkeys)\n       (https://fidoalliance
 .org/fido-alliance-launches-the-passkey-pledge-to-further-accelerate-globa
 l-movement-away-from-passwords/)\,\n       May 2025.\n\n   Industry and pr
 actitioner research\n\n     * Luke Jennings (Push Security)\, MFA downgrad
 e: how attackers are\n       getting around phishing-resistant authenticat
 ion\n       (https://pushsecurity.com/blog/mfa-downgrade-attacks)\, July 2
 025.\n\n     * Carlos Gomez (IOActive)\, Authentication Downgrade Attacks:
  Deep\n       Dive into MFA Bypass\n       (https://www.ioactive.com/authe
 ntication-downgrade-attacks-deep-dive-into-mfa-bypass/)\,\n       February
  2026.\n\n     * Netcraft\, Phishing After Passkeys: What Attacks to Expec
 t\n       (https://www.netcraft.com/blog/phishing-after-passkeys-what-atta
 cks-to-expect)\,\n       April 2026.\n\n     * Maarten Balliauw (Duende So
 ftware)\, Deep Dive: Relying Party ID\n       and origin with Passkeys\n  
      (https://duendesoftware.com/blog/20251014-deep-dive-into-relying-part
 y-id-and-origin-with-passkeys)\,\n       October 2025.\n\n     * Tobia Rig
 hi (mastersplinter)\, Passkey account-takeover research\n       and CVE-20
 24-9956 (incl. the credential-ID-collision overwrite\n       note) (https:
 //mastersplinter.work/research/passkey/)\, 2025.\n\n     * Curtis Brazzell
  (PhishU)\, Vaultjacking: One Captured PIN\, the\n       Entire Google Pas
 sword Manager Vault\n       (https://phishu.net/blogs/blog-vaultjacking-ph
 ishing-the-google-password-manager-vault-in-the-phishu-framework.html)\,\n
        May 2026.\n\n     * U-Zyn Chua (uzyn)\, Passkey has a theft-detecti
 on feature\, but\n       Apple\, Google and Microsoft broke it\n       (ht
 tps://uzyn.com/2025/passkey-has-a-theft-detection-feature-but-big-tech-bro
 ke-it/)\,\n       May 2025.\n\n     * Scott Helme\, Open-Sourcing passkeys
 -php: A Security-Focused\n       WebAuthn Library for PHP\n       (https:/
 /scotthelme.co.uk/open-sourcing-passkeys-php-a-security-focused-webauthn-l
 ibrary-for-php/)\,\n       May 2026.\n\n     * Dennis Kniep\, FIDO Cross-D
 evice Phishing (caBLE/hybrid\n       cross-device relay PoC)\n       (http
 s://denniskniep.github.io/posts/14-fido-cross-device-phishing/)\,\n       
 September 2025.\n\n     * William Brown (firstyear)\, WTF is a passkey (Op
 en Source Security\n       podcast)\n       (https://opensourcesecurity.io
 /2026/2026-01-passkey-william-brown/)\,\n       January 2026.\n\n   Confer
 ence talks (forthcoming / concurrent / recent)\n\n     * Michael Grafnette
 r (DSInternals)\, Pass-the-Passkey family of\n       attacks\n       (http
 s://www.dsinternals.com/en/black-hat-usa-26-pass-the-passkey/)\,\n       B
 lack Hat USA 2026 (forthcoming).\n\n     * Nevada Romsdahl and Kam Talebza
 deh\, SquarePhish 2.0: QR Code +\n       OAuth 2.0 Device Code Flow Phishi
 ng for the Primary Refresh Token\n       (https://disobey.fi/2026/profile/
 disobey-2026-433-squarephish-2-0-qr-code-oauth-2-0-device-code-flow-phishi
 ng-for-primary-refresh-token)\,\n       Disobey 2026.\n\n   Relying-party 
 CVEs (public record\, some of them)\n\n     * CVE-2026-46419\, Yubico java
 -webauthn-server (webauthn-server-core)\n       (https://www.yubico.com/su
 pport/security-advisories/ysa-2026-02/).\n\n     * CVE-2025-26788\, Strong
 Key FIDO Server\n       (https://nvd.nist.gov/vuln/detail/CVE-2025-26788).
 \n\n     * CVE-2024-12225\, Quarkus quarkus-security-webauthn\n       (htt
 ps://nvd.nist.gov/vuln/detail/CVE-2024-12225).\n\n     * CVE-2025-12150\, 
 Keycloak keycloak-services\, attestation-policy\n       bypass via fmt:non
 e\n       (https://github.com/advisories/GHSA-7g5x-9c4v-4w5r).\n\n     * C
 VE-2026-6856\, Keycloak\, AAGUID-allowlist bypass via packed\n       self-
 attestation (NVD record not yet published\; tracked at the\n       Keycloa
 k issue)\n       (https://github.com/keycloak/keycloak/issues/48388).\n\n 
   SpeakerBio:  Matteo Giordano\, Anvil Secure\n\n   Matteo Giordano is an 
 Italy-based offensive security specialist and\n   Security Engineer at Anv
 il Secure\, focused on application penetration\n   testing and offensive r
 esearch\, with a growing focus on AI Red Teaming\n   and GenAI security. F
 or the past year he has researched WebAuthn and\n   passkeys from an attac
 ker's perspective\, mapping the real-world attack\n   surface that sits ar
 ound the protocol's cryptographic core\, the work\n   behind this talk.\n\
 n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T185900Z
DTSTART:20260809T180000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-
 2
SUMMARY:Beyond the Ceremony: The 2026 Passkey Attack Surface
END:VEVENT
END:VCALENDAR
