• Alphane MoonM
    link
    English
    295 months ago

    “The attacker would need physical possession of the YubiKey, Security Key, or YubiHSM, knowledge of the accounts they want to target, and specialized equipment to perform the necessary attack. Depending on the use case, the attacker may also require additional knowledge including username, PIN, account password, or authentication key.”

    • jelloeater
      link
      105 months ago

      Seems like a “blast door” type problem…

    • 𝕸𝖔𝖘𝖘
      link
      fedilink
      English
      45 months ago

      That sounds like the attacker would need to basically already know how to unlock it…

  • @Desistance
    link
    English
    155 months ago

    Not much of a vulnerability when you need physical access.

    • Mayor Poopington
      link
      English
      105 months ago

      It’s like saying a bank is vulnerable if you have enough drills and guns

    • lemmyng
      link
      fedilink
      English
      85 months ago

      On the contrary. China for example is known for accessing traveler electronics both during customs/immigration checks and in their hotels. Unless the victim carries their key on their person at all times without fault it can be cloned without them knowing.

    • @eyeon
      link
      65 months ago

      i have physical access to my own yubikey and can’t make a backup copy. someone else who only temporarily has access to it being able to do so is definitely a vulnerability.

  • @[email protected]
    link
    fedilink
    English
    75 months ago

    Its not much of a vulnerability, like locks, its not if it can be picked, it is how difficult it is to be picked, but the difference here is that the vulnerability is that a nation state actor, or a high capability actor can compromise it, and “it” being the thing that keeps your accounts safe.

    So this is like the lock that protects all your accounts can be shimmed if it ever gets out of your control type of an issue, so not to stop using them, but to keep them secured or on your person at all times.

    I hope YubiKey offers a fair upgrade program for their next series of keys and maybe a new FIDO Standard.