Add BrightSurf on Google Email

Are passkeys safer? New study casts doubt for victims of intimate partner abuse

08.13.26 | Cornell University
Sky & Telescope Pocket Sky Atlas, 2nd Edition

Sky & Telescope Pocket Sky Atlas, 2nd Edition is a durable star atlas for planning sessions, identifying targets, and teaching celestial navigation.

CORNELL UNIVERSITY MEDIA RELATIONS OFFICE

FOR RELEASE: August 13, 2026

Kaitlyn Serrao

607-882-1140

kms465@cornell.edu

ITHACA, N.Y. - Passkeys are touted as safer than traditional passwords. But for people targeted by intimate partner abuse, new Cornell University research has found they can often be more dangerous. Someone with access to their partner’s computer and password could set up their own passkey and invade their personal online space, potentially with dangerous consequences.

The Cornell team conducted a lab-based study, involving participants with diverse technical backgrounds, to see how people identify and protect themselves from malicious use of their passkeys. The findings, the authors wrote, “paint a grim picture” of people’s ability to alleviate the threat posed by such online invasions of privacy.

“Our conclusion is that services need to do a lot of work to enable users to diagnose compromises to their account, and remediate any account compromise that could occur,” said Alaa Daffalla, doctoral student in computer science and lead author of “‘ Maybe There’s Only One Passkey?’: Challenges Investigating and Remediating Adversarial Passkeys ,” which is being presented at the 35th USENIX Security Symposium in Baltimore this week.

Senior authors are Nicola Dell , associate professor of information science and Thomas Ristenpart, professor of computer science at the University of Toronto.

Dell and Ristenpart in 2018 co-founded the Clinic to End Tech Abuse (CETA), which supports survivors of intimate partner violence, and this latest research is an offshoot of the work done at the clinic. Daffalla joined the lab in 2022 and focused her work on account security interfaces (ASIs).

“Understanding the security of online accounts, including emerging authentication mechanisms like passkeys, is essential for digital safety, not only for abuse survivors but for all technology users,” Dell said.

The overwhelming majority of study participants were unable to identify logins from the attacker’s device, or to protect themselves by removing the passkey, changing the account password and logging out from other devices without assistance from the researchers. Some were suspicious of emails notifying them of unusual online activity on their account, and some struggled to understand online notifications.

In addition, the participants found passkey ASIs – available from all three services used in the study – hard to follow.

“People maybe are using passkeys, but they don’t understand how they work,” she said. “So it’s a little worrying that that we still haven’t gotten to a place where we are designing systems and interfaces that ensure users feel safe about their accounts.”

This research was supported in part by grants from the National Science Foundation and by a Google Cyber Award.

For additional information, read this Cornell Chronicle story.

Cornell University has dedicated television and audio studios available for media interviews.

-30-

Keywords

Contact Information

Kaitlyn Serrao
Cornell University
kms465@cornell.edu

How to Cite This Article

APA:
Cornell University. (2026, August 13). Are passkeys safer? New study casts doubt for victims of intimate partner abuse. Brightsurf News. https://www.brightsurf.com/news/8OMPEG31/are-passkeys-safer-new-study-casts-doubt-for-victims-of-intimate-partner-abuse.html
MLA:
"Are passkeys safer? New study casts doubt for victims of intimate partner abuse." Brightsurf News, Aug. 13 2026, https://www.brightsurf.com/news/8OMPEG31/are-passkeys-safer-new-study-casts-doubt-for-victims-of-intimate-partner-abuse.html.