{"id":38803,"date":"2026-08-06T12:41:28","date_gmt":"2026-08-06T16:41:28","guid":{"rendered":"https:\/\/www.rsa.com\/?p=38803"},"modified":"2026-08-06T12:42:15","modified_gmt":"2026-08-06T16:42:15","slug":"pass-ta-key-synced-passkey-risk-enterprise","status":"publish","type":"post","link":"https:\/\/www.rsa.com\/id\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/","title":{"rendered":"Apa yang Diungkap oleh Serangan Pass-ta-key Mengenai Risiko Kunci Akses yang Disinkronkan"},"content":{"rendered":"","protected":false},"excerpt":{"rendered":"","protected":false},"author":6,"featured_media":38808,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_searchwp_excluded":"","inline_featured_image":false,"footnotes":""},"categories":[62],"tags":[],"class_list":["post-38803","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-passwordless"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Pass-ta-key Attacks Expose the Risk of Synced Passkeys | RSA<\/title>\n<meta name=\"description\" content=\"New Unit 42 research shows malware can hijack Google&#039;s synced passkeys. See why enterprises need device-bound and hardware-rooted passkeys instead.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.rsa.com\/id\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/\" \/>\n<meta property=\"og:locale\" content=\"id_ID\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What the Pass-ta-key Attacks Reveal About the Risks of Synced Passkeys\" \/>\n<meta property=\"og:description\" content=\"Read the blog to learn why the Pass-ta-key attacks reveal the risks of synced passkeys, and how organizations can keep passwordless secure.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.rsa.com\/id\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/\" \/>\n<meta property=\"og:site_name\" content=\"RSA\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-06T16:41:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-06T16:42:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.rsa.com\/wp-content\/uploads\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-social.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Ben Lebeaux\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"What the Pass-ta-key Attacks Reveal About the Risks of Synced Passkeys\" \/>\n<meta name=\"twitter:description\" content=\"Read the blog to learn why the Pass-ta-key attacks reveal the risks of synced passkeys, and how organizations can keep passwordless secure.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.rsa.com\/wp-content\/uploads\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-social.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@bcomroe@logical-inc.com\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.rsa.com\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.rsa.com\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/\"},\"author\":{\"name\":\"Ben Lebeaux\",\"@id\":\"https:\\\/\\\/www.rsa.com\\\/#\\\/schema\\\/person\\\/5d90b65186f63c4223687eca55dc2eed\"},\"headline\":\"What the Pass-ta-key Attacks Reveal About the Risks of Synced Passkeys\",\"datePublished\":\"2026-08-06T16:41:28+00:00\",\"dateModified\":\"2026-08-06T16:42:15+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.rsa.com\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/\"},\"wordCount\":11,\"publisher\":{\"@id\":\"https:\\\/\\\/www.rsa.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.rsa.com\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.rsa.com\\\/wp-content\\\/uploads\\\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-featured.webp\",\"articleSection\":[\"Passwordless\"],\"inLanguage\":\"id-ID\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.rsa.com\\\/id\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/\",\"url\":\"https:\\\/\\\/www.rsa.com\\\/id\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/\",\"name\":\"Pass-ta-key Attacks Expose the Risk of Synced Passkeys | RSA\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.rsa.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.rsa.com\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.rsa.com\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.rsa.com\\\/wp-content\\\/uploads\\\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-featured.webp\",\"datePublished\":\"2026-08-06T16:41:28+00:00\",\"dateModified\":\"2026-08-06T16:42:15+00:00\",\"description\":\"New Unit 42 research shows malware can hijack Google's synced passkeys. See why enterprises need device-bound and hardware-rooted passkeys instead.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.rsa.com\\\/id\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/#breadcrumb\"},\"inLanguage\":\"id-ID\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.rsa.com\\\/id\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"id-ID\",\"@id\":\"https:\\\/\\\/www.rsa.com\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.rsa.com\\\/wp-content\\\/uploads\\\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-featured.webp\",\"contentUrl\":\"https:\\\/\\\/www.rsa.com\\\/wp-content\\\/uploads\\\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-featured.webp\",\"width\":1200,\"height\":630,\"caption\":\"What the Pass-ta-key Attacks Reveal About the Risks of Synced Passkeys\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.rsa.com\\\/id\\\/resources\\\/blog\\\/passwordless\\\/pass-ta-key-synced-passkey-risk-enterprise\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.rsa.com\\\/id\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What the Pass-ta-key Attacks Reveal About the Risks of Synced Passkeys\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.rsa.com\\\/#website\",\"url\":\"https:\\\/\\\/www.rsa.com\\\/\",\"name\":\"RSA\",\"description\":\"Cybersecurity and Digital Risk Management Solutions\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.rsa.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.rsa.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"id-ID\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.rsa.com\\\/#organization\",\"name\":\"RSA\",\"url\":\"https:\\\/\\\/www.rsa.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"id-ID\",\"@id\":\"https:\\\/\\\/www.rsa.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.rsa.com\\\/wp-content\\\/uploads\\\/rsa.png\",\"contentUrl\":\"https:\\\/\\\/www.rsa.com\\\/wp-content\\\/uploads\\\/rsa.png\",\"width\":2880,\"height\":1020,\"caption\":\"RSA\"},\"image\":{\"@id\":\"https:\\\/\\\/www.rsa.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"knowsAbout\":[\"multi-factor authentication\",\"passwordless authentication\",\"identity and access management\",\"identity governance and administration\",\"zero trust\",\"threat detection and response\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.rsa.com\\\/#\\\/schema\\\/person\\\/5d90b65186f63c4223687eca55dc2eed\",\"name\":\"Ben Lebeaux\",\"sameAs\":[\"https:\\\/\\\/x.com\\\/bcomroe@logical-inc.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Serangan Pass-ta-key Mengungkap Risiko Kunci Akses yang Disinkronkan | RSA","description":"Penelitian terbaru dari Unit 42 menunjukkan bahwa malware dapat membajak passkey yang disinkronkan oleh Google. Simak alasan mengapa perusahaan justru membutuhkan passkey yang terikat pada perangkat dan berakar pada perangkat keras.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.rsa.com\/id\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/","og_locale":"id_ID","og_type":"article","og_title":"What the Pass-ta-key Attacks Reveal About the Risks of Synced Passkeys","og_description":"Read the blog to learn why the Pass-ta-key attacks reveal the risks of synced passkeys, and how organizations can keep passwordless secure.","og_url":"https:\/\/www.rsa.com\/id\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/","og_site_name":"RSA","article_published_time":"2026-08-06T16:41:28+00:00","article_modified_time":"2026-08-06T16:42:15+00:00","og_image":[{"width":1200,"height":627,"url":"https:\/\/www.rsa.com\/wp-content\/uploads\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-social.webp","type":"image\/webp"}],"author":"Ben Lebeaux","twitter_card":"summary_large_image","twitter_title":"What the Pass-ta-key Attacks Reveal About the Risks of Synced Passkeys","twitter_description":"Read the blog to learn why the Pass-ta-key attacks reveal the risks of synced passkeys, and how organizations can keep passwordless secure.","twitter_image":"https:\/\/www.rsa.com\/wp-content\/uploads\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-social.webp","twitter_creator":"@bcomroe@logical-inc.com","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.rsa.com\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/#article","isPartOf":{"@id":"https:\/\/www.rsa.com\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/"},"author":{"name":"Ben Lebeaux","@id":"https:\/\/www.rsa.com\/#\/schema\/person\/5d90b65186f63c4223687eca55dc2eed"},"headline":"What the Pass-ta-key Attacks Reveal About the Risks of Synced Passkeys","datePublished":"2026-08-06T16:41:28+00:00","dateModified":"2026-08-06T16:42:15+00:00","mainEntityOfPage":{"@id":"https:\/\/www.rsa.com\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/"},"wordCount":11,"publisher":{"@id":"https:\/\/www.rsa.com\/#organization"},"image":{"@id":"https:\/\/www.rsa.com\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/#primaryimage"},"thumbnailUrl":"https:\/\/www.rsa.com\/wp-content\/uploads\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-featured.webp","articleSection":["Passwordless"],"inLanguage":"id-ID"},{"@type":"WebPage","@id":"https:\/\/www.rsa.com\/id\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/","url":"https:\/\/www.rsa.com\/id\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/","name":"Serangan Pass-ta-key Mengungkap Risiko Kunci Akses yang Disinkronkan | RSA","isPartOf":{"@id":"https:\/\/www.rsa.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.rsa.com\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/#primaryimage"},"image":{"@id":"https:\/\/www.rsa.com\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/#primaryimage"},"thumbnailUrl":"https:\/\/www.rsa.com\/wp-content\/uploads\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-featured.webp","datePublished":"2026-08-06T16:41:28+00:00","dateModified":"2026-08-06T16:42:15+00:00","description":"Penelitian terbaru dari Unit 42 menunjukkan bahwa malware dapat membajak passkey yang disinkronkan oleh Google. Simak alasan mengapa perusahaan justru membutuhkan passkey yang terikat pada perangkat dan berakar pada perangkat keras.","breadcrumb":{"@id":"https:\/\/www.rsa.com\/id\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/#breadcrumb"},"inLanguage":"id-ID","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.rsa.com\/id\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/"]}]},{"@type":"ImageObject","inLanguage":"id-ID","@id":"https:\/\/www.rsa.com\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/#primaryimage","url":"https:\/\/www.rsa.com\/wp-content\/uploads\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-featured.webp","contentUrl":"https:\/\/www.rsa.com\/wp-content\/uploads\/what-the-pass-ta-key-attacks-reveal-about-the-risks-of-synced-passkeys-rsa-featured.webp","width":1200,"height":630,"caption":"What the Pass-ta-key Attacks Reveal About the Risks of Synced Passkeys"},{"@type":"BreadcrumbList","@id":"https:\/\/www.rsa.com\/id\/resources\/blog\/passwordless\/pass-ta-key-synced-passkey-risk-enterprise\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.rsa.com\/id\/"},{"@type":"ListItem","position":2,"name":"What the Pass-ta-key Attacks Reveal About the Risks of Synced Passkeys"}]},{"@type":"WebSite","@id":"https:\/\/www.rsa.com\/#website","url":"https:\/\/www.rsa.com\/","name":"RSA","description":"Solusi Keamanan Siber dan Manajemen Risiko Digital","publisher":{"@id":"https:\/\/www.rsa.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.rsa.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"id-ID"},{"@type":"Organization","@id":"https:\/\/www.rsa.com\/#organization","name":"RSA","url":"https:\/\/www.rsa.com\/","logo":{"@type":"ImageObject","inLanguage":"id-ID","@id":"https:\/\/www.rsa.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.rsa.com\/wp-content\/uploads\/rsa.png","contentUrl":"https:\/\/www.rsa.com\/wp-content\/uploads\/rsa.png","width":2880,"height":1020,"caption":"RSA"},"image":{"@id":"https:\/\/www.rsa.com\/#\/schema\/logo\/image\/"},"knowsAbout":["multi-factor authentication","passwordless authentication","identity and access management","identity governance and administration","zero trust","threat detection and response"]},{"@type":"Person","@id":"https:\/\/www.rsa.com\/#\/schema\/person\/5d90b65186f63c4223687eca55dc2eed","name":"Ben Lebeaux","sameAs":["https:\/\/x.com\/bcomroe@logical-inc.com"]}]}},"_links":{"self":[{"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/posts\/38803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/comments?post=38803"}],"version-history":[{"count":3,"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/posts\/38803\/revisions"}],"predecessor-version":[{"id":38809,"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/posts\/38803\/revisions\/38809"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/media\/38808"}],"wp:attachment":[{"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/media?parent=38803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/categories?post=38803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rsa.com\/id\/wp-json\/wp\/v2\/tags?post=38803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}