YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel (arstechnica.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 03 Sep 2024 20:12
https://sh.itjust.works/post/24661295

#cybersecurity

threaded - newest

sun_is_ra@sh.itjust.works on 03 Sep 2024 22:49 next collapse

TLDR; the attack is very sophisticated, require hardware access and specialized tools. On the other hand its not possible to patch the vulnerability

Telorand@reddthat.com on 04 Sep 2024 15:14 collapse

To add:

All YubiKeys running firmware prior to version 5.7—which was released in May and replaces the Infineon cryptolibrary with a custom one—are vulnerable.

So if you bought your key from June onward, you are most likely in the clear.

crazyminner@lemmy.ml on 04 Sep 2024 01:17 collapse

I have two of these is there anything else more secure?