Hacker News new | ask | show | jobs
by cromd 1567 days ago
Here's an example from 2018 of someone trying to extract secrets from a Yubikey. https://duo.com/labs/research/microcontroller-firmware-recov.... Seems they don't get very far. Or it's at least very laborious. But as you say, who knows what a cutting edge lab can do. Skimming the web, it seems like people have had more success with things like Google Titan keys.
2 comments

If you are interested in this topic, the physical security chapter of Ross Anderson's Security Engineering has a nice intro. The second edition is free online https://www.cl.cam.ac.uk/~rja14/book.html
That's not a yubikey but a standard pic microcontroller not designed for security applications.

And as far as I understand he's now describing his methods there rather than particular attempts?

There's a bit about Yubikey at the very end of the article.