08/13/2026 | Press release | Distributed by Public on 08/13/2026 07:20
Passkeys are touted as safer than traditional passwords. But for people targeted by intimate partner abuse, they can often be more dangerous.
Someone with access to their partner's computer and password could set up their own passkey - a cryptographic form of login used by services such as Google and LinkedIn - and invade their personal online space, potentially with dangerous consequences, new Cornell research has found.
The Cornell team conducted a lab-based study, involving participants with diverse technical backgrounds, to see how people identify and protect themselves from malicious use of their passkeys. The findings, the authors wrote, "paint a grim picture" of people's ability to alleviate the threat posed by such online invasions of privacy.
"Our conclusion is that services need to do a lot of work to enable users to diagnose compromises to their account, and remediate any account compromise that could occur," said Alaa Daffalla, doctoral student in computer science and lead author of "'Maybe There's Only One Passkey?': Challenges Investigating and Remediating Adversarial Passkeys," which is being presented at the 35th USENIX Security Symposium, Aug, 12-14 in Baltimore.
Senior authors are Nicola Dell, associate professor of information science at Cornell Tech, the Jacobs Technion-Cornell Institute and the Cornell Ann S. Bowers College of Computing and Information Science; and Thomas Ristenpart, professor of computer science at the University of Toronto and formerly of Cornell Tech and Cornell Bowers.
Dell and Ristenpart in 2018 co-founded the Clinic to End Tech Abuse (CETA), which supports survivors of intimate partner violence, and this latest research is an offshoot of the work done at the clinic. Daffalla joined the lab in 2022 and focused her work on account security interfaces (ASIs), which inform online users about changes to their accounts and can facilitate remediation.
"Understanding the security of online accounts, including emerging authentication mechanisms like passkeys, is essential for digital safety, not only for abuse survivors but for all technology users," Dell said.
For this study, Daffalla and the team recruited 31 participants - college students, residents near campus and CETA clinicians, representing a range of tech proficiency. Researchers played the role of a friend whose account (Google, PayPal or LinkedIn) had been compromised by someone known to them and who knew their password. Two dedicated laptops were used in the study.
The overwhelming majority of participants were unable to identify logins from the attacker's device, or to protect themselves by removing the passkey, changing the account password and logging out from other devices without assistance from the researchers. Some were suspicious of emails notifying them of unusual online activity on their account, and some struggled to understand online notifications.
In addition, the participants found passkey ASIs - available from all three services used in the study - hard to follow. One participant didn't understand that the iCloud Keychain (where passkeys across devices are managed) showed two passkeys, the victim's and the adversary's, thinking that there was only one passkey for two separate devices.
Daffalla said the lack of understanding of passkeys was surprising, particularly among people with professed tech knowledge, including clinicians.
"People maybe are using passkeys, but they don't understand how they work," she said. "So it's a little worrying that that we still haven't gotten to a place where we are designing systems and interfaces that ensure users feel safe about their accounts."
Other contributors were Rosanne Bellini, assistant professor of computer science and engineering at New York University; and Grace Myers, M.S. '26, now an AI strategist with Atlas Holdings, LLC.
This research was supported in part by grants from the National Science Foundation and by a Google Cyber Award.