2026-09-17
Bitwarden holds first at 9.4. Several readers forwarded me headlines about Pass-ta-key this week asking whether passkeys are broken, so this update answers that directly: passkeys remain the strongest login you can use, and the research tells us where to put our attention.
Palo Alto Networks Unit 42 described three attacks against the passkeys that Google Password Manager syncs through Chrome. The basic version lets malware quietly request a valid passkey login with no fingerprint or PIN prompt. The silver version registers the attacker's own verification key through device re-enrollment. The golden version extracts the master secret that protects synced passkeys and decrypts all of them.
The detail that matters most for readers: every one of the three requires malware already running on the victim's Windows computer. A clean machine is safe from all of them.
So my advice is about the device first. Keep Windows and Chrome updated, run the built-in security tools, and treat a pirated installer as the single biggest risk to your accounts. Then give your vault its own lock. A dedicated password manager that asks for its own unlock, with a short auto-lock timer, adds a barrier between a compromised browser session and your credentials.
Bitwarden fits that setup well, with passkeys at 9.5, encryption at 9.5 and a free tier covering unlimited devices. I set its vault timeout to fifteen minutes on shared or work machines. 1Password at 9.2 holds breach record at 9.6 and encryption at 9.6, the strongest pair in this table, and its account secret key protects the vault even if the account password leaks.
Proton Pass at 9.0 keeps migration at 9.5, so moving your passkeys and passwords in from a browser store takes a single import.
Apple Passwords at 7.7 keeps passkeys at 9.2 for households fully inside Apple devices.
The ranking carries forward unchanged.
Pass-ta-key needs malware already on the PC
All three Unit 42 attacks against Google-synced passkeys require a compromised Windows machine.
Passkeys remain the strongest login
Device hygiene is the defense: updates, built-in security tools and no pirated installers.
Give the vault its own lock
A dedicated manager with its own unlock and a short auto-lock timer adds a real barrier.
1Password pairs 9.6 breach record with 9.6 encryption
Its secret key protects the vault even if the account password leaks.