YubiKey Side-Channel Attack
There is a side-channel attack against YubiKey access tokens that allows someone to clone a device. It’s a complicated attack, requiring the victim’s username and password, and physical access to their YubiKey—as well as some technical expertise and equipment.
Still, nice piece of security analysis.
ZN • September 6, 2024 12:27 PM
To fix it yubikey reportedly replaced the Infineon upstream library for ECC with their own in the keys’ firmware.
What is your take on that approach? Do you see it detrimental to working with the vendor to fix the original library?