YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel
YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel
arstechnica.com YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel
Sophisticated attack breaks security assurances of the most popular FIDO key.
4 comments
There's a firmware update that fixes the vulnerability. Kinda moot as long as you do updates.
EDIT: Seems you have to buy a new key for that, but the difficulty of executing the vulnerability means it probably doesn't matter anyway.
1 1 ReplyAlso requires $11k in gear and physical access to the key.
2 0 ReplyI thought these device's firmware were strictly read only and can't get updates.
2 0 ReplyApparently not.
EDIT: It seems they actually are? So I guess if you're at risk of having a national government try to break your security key, you should buy a new one.
1 0 Reply