Hacker News new | ask | show | jobs
by nixosbestos 655 days ago
I'm trying not to blow a gasket over this, but what the fuck? This makes the Yubikey a lost a couple months back a huge risk. This makes my primary and backup Yubikeys potential risks.

They don't allow FW upgrades for dubious reasons, and they aren't issuing replacements? It's so sad that the OSS alternatives are so lacking.

Maybe time to pickup a Precursor and start taking this all a bit more seriously.

1 comments

This attack doesn't allow anyone to, e.g., bypass any PINs you may have set on your yubikey. It allows an attacker to extract your keys if and only if they can already use your yubikey.

From what I can tell, the risk is:

1. Someone takes your yubikey without your knowledge.

2. They manage to disassemble it, extract your key, and put it back together.

3. They secretly return your yubikey.

4. You continue to use your yubikey, unaware of the fact that it has been compromised.