Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Cornell Study Finds Passkeys Can Let Abusive Partners Lock Victims Out of Their Own Accounts

Passkeys were sold as the end of the password problem. Google, Apple, Microsoft and the FIDO Alliance have spent two years telling people to ditch passwords for the fingerprint-and-face-scan login system. For most threats, that pitch holds up. Passkeys can't be phished, guessed, or stuffed from a leaked database because there's no password to steal in the first place.
But a new study out of Cornell University found a hole in that pitch. Researchers presented the paper, titled "'Maybe There's Only One Passkey?': Challenges Investigating and Remediating Adversarial Passkeys," at the 35th USENIX Security Symposium in Baltimore, held August 12 to 14, 2026. The Cornell Chronicle published a writeup on August 13.
The setup: someone who already knows your password
Here's the scenario the study tested. Someone has your password and brief physical access to your unlocked device — a partner, an ex, a roommate. That person registers their own passkey on your Google, PayPal, or LinkedIn account. Under the FIDO2/WebAuthn standard that powers passkeys, once that credential is enrolled, it works independently. The abuser doesn't need your password anymore. They don't need your phone. Changing your password afterward does nothing to remove their access, because the passkey they planted is a separate, valid login method sitting quietly on your account.
Lead author Alaa Daffalla, a Cornell doctoral student in computer science, ran a lab study to see whether ordinary people could catch this and fix it. The team recruited 31 participants — a mix of college students, campus-area residents and clinicians from the Clinic to End Tech Abuse (CETA) — spanning a wide range of technical skill. Researchers played the role of a friend whose Google, PayPal or LinkedIn account had been compromised by someone who knew their password and had planted a passkey using a second laptop.
According to the Cornell Chronicle and a companion writeup from Tom Fleischman published via techxplore, the overwhelming majority of participants could not identify the attacker's login, could not remove the rogue passkey, and could not fully lock the intruder out — even after changing their password and logging out of other sessions. Some participants didn't trust the security notification emails they received. Others simply didn't understand what the notifications were telling them.
Why this isn't a knock on passkeys broadly
This isn't evidence that passkeys are bad technology. Against remote attackers — phishing crews, credential-stuffing bots, nation-state hacking operations — passkeys are a genuine upgrade, and the Cornell researchers don't dispute that. The private key never leaves the device, so there's nothing to steal over the wire. That's a real win for the vast majority of account-security threats people face.
The problem the study identifies is narrower but serious. The industry designed account security interfaces — the screens where you manage logins and connected devices — around the assumption that account compromise looks like a stranger somewhere hacking in remotely. It doesn't account for a threat model where the attacker is someone the victim knows, already has some access to their stuff, and can register credentials before the abuse is ever detected.
The National Network to End Domestic Violence's Safety Net Project has found that 97% of U.S. domestic violence programs report clients experiencing technology-facilitated abuse from partners. Between 10 and 12 million Americans experience intimate partner violence annually, according to figures cited in the Cornell research. For that population, a security feature that survives a password reset isn't a convenience. It's a liability.
What the researchers want changed
Nicola Dell, a Cornell Tech associate professor and co-founder of CETA alongside University of Toronto professor Thomas Ristenpart, emphasized the core finding: "Our conclusion is that services need to do a lot of work to enable users to diagnose compromises to their account, and remediate any account compromise that could occur," Dell said, according to the Cornell Chronicle.
Dell added that understanding passkey security "is essential for digital safety, not only for abuse survivors but for all technology users."
The study doesn't call for scrapping passkeys. It calls for better account security interfaces — clearer device lists, plainer alerts, and a remediation path that doesn't require an expert sitting next to you, the way researchers had to sit next to almost every participant in this study to help them regain control.
None of Google, PayPal, or LinkedIn have publicly responded to the specific findings as of this writing. The open question is whether Apple, Google and Microsoft — the three companies driving the industry-wide passkey push — will redesign their account recovery and device-management screens before the technology becomes the default login method it's being marketed to be.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.