|
|
|
|
|
by SahAssar
2133 days ago
|
|
If you are talking about a U2F usb stick I agree with you (I put "incredibly hard" instead of "impossible" there so that I don't get counterarguments with people reading memory with electron microscopes or similar). If you are talking plain USB mass storage for keys I disagree. |
|
That being said, it's incredibly unlikely that someone would ever sell mass storage based USB credentials because:
1. Security products are marketed based on surviving the worst case scenarios. Nobody would buy a U2F token that is "good enough for the threats you probably face".
2. By the time you've hardened any USB device from remote cloning, you're probably already done most of the work to harden it against local cloning. Might as well complete the last bits necessary in order to get the marketing benefits from point 1.