CyberHappenings logo
☰

Track cybersecurity events as they unfold. Sourced timelines, daily updates. Fast, privacy‑respecting. No ads, no tracking.

Hidden Risks in Passwordless Account Recovery

First reported
Last updated
πŸ“° 1 unique sources, 1 articles

Summary

Hide β–²

Researchers at Black Hat USA 2025 highlighted significant risks associated with passwordless account recovery methods. Despite the adoption of passwordless authentication, account recovery processes often rely on insecure communication channels like email and SMS, making them vulnerable to account takeovers and permanent lockouts. The researchers tested 22 of the most visited websites and found widespread weaknesses in account recovery methods. They identified design flaws, security policy weaknesses, and missing best practices, including the lack of multifactor authentication during recovery. Users and service providers are advised to implement stronger recovery processes, including two-factor recovery options and stringent session policies.

Timeline

  1. 11.08.2025 20:53 πŸ“° 1 articles Β· ⏱ 1mo ago

    Researchers Identify Hidden Risks in Passwordless Account Recovery

    At Black Hat USA 2025, researchers highlighted the vulnerabilities in passwordless account recovery methods. They found that these methods often rely on insecure communication channels and lack multifactor authentication, making them susceptible to account takeovers and permanent lockouts. Tests on 22 of the most visited websites revealed widespread weaknesses in account recovery processes.

    Show sources

Information Snippets