Close Menu
    What's Hot

    Ford Mustang Mach-E & F-150 Lightning US Sales Don’t Actually Collapse

    VF Corporation hits 61% traceability for key materials

    Prevalon Energy and Emerson Announce Global Strategic Collaboration to Deliver Integrated Power and Energy Storage Solutions for Data Centers

    Facebook X (Twitter) Instagram
    Francis Green Energy InnovationFrancis Green Energy Innovation
    • Alternative Energy
    • Energy Hub
    • Environment Issues
    • GreenBiz
    • Renewable News
    • Wind Energy
    Francis Green Energy InnovationFrancis Green Energy Innovation
    You are at:Home»Uncategorized»YubiKey vulnerability will let attackers clone the authentication device
    Uncategorized

    YubiKey vulnerability will let attackers clone the authentication device

    adminBy adminSeptember 7, 2024012 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    NinjaLab, a security research company, has discovered a vulnerability that could potentially allow bad actors to clone YubiKeys, as detailed in a security advisory. The flaw was found in the cryptographic library used in the YubiKey 5 Series, specifically in the microcontroller responsible for generating and storing secrets for security devices like bank cards and FIDO hardware tokens. YubiKeys are widely used FIDO authentication keys meant to enhance account security by requiring users to physically plug them into their computers for login. The researchers identified the vulnerability by analyzing an open platform based on Infineon’s cryptographic library utilized by Yubico. They confirmed that all YubiKey 5 models are susceptible to cloning and that the issue extends beyond this specific brand, although they have not attempted to replicate the vulnerability on other devices. Exploiting the vulnerability would require physical access to the target token, dismantling it, and using costly equipment like an oscilloscope to perform electromagnetic side-channel measurements for analysis. This security flaw, present for 14 years, may pose a threat primarily to government agencies or individuals handling sensitive information at risk of espionage, emphasizing the need for caution with YubiKeys. The researchers emphasize the importance of using YubiKeys as FIDO hardware authentication tokens for added security, highlighting that the required resources and expertise make exploiting the vulnerability challenging for most attackers.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleUK competition watchdog opens Ticketmaster probe after Oasis ticket debacle
    Next Article Over 1.4 million Ram 1500 trucks recalled to fix a bug in the anti-lock brake system
    admin
    • Website

    Related Posts

    Netflix’s The Electric State trailer shows off cartoony robots and oversized VR headsets

    October 17, 2024

    The USB-C Apple Pencil drops to a new all-time low of $65

    October 17, 2024

    DJI confirms that US customs is holding up its latest consumer drone

    October 17, 2024
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts
    8.9

    Signs of Endometriosis: What are Common and Surprising Symptoms?

    January 15, 2021492 Views

    GWEC Report Outlines Crucial Next Steps for Vietnam to Scale Investment and Achieve Offshore Wind Targets

    November 7, 2024335 Views
    8.5

    Comparison: The Maternal and Fetal Outcomes of COVID-19

    January 15, 2021292 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Comparison: The Maternal and Fetal Outcomes of COVID-19

    By adminJanuary 15, 2021

    Florida Surgeon General’s Covid Vaccine Claims Harm Public

    By adminJanuary 15, 2021

    Signs of Endometriosis: What are Common and Surprising Symptoms?

    By adminJanuary 15, 2021
    Most Popular
    8.9

    Signs of Endometriosis: What are Common and Surprising Symptoms?

    January 15, 2021492 Views

    GWEC Report Outlines Crucial Next Steps for Vietnam to Scale Investment and Achieve Offshore Wind Targets

    November 7, 2024335 Views
    Categories
    • Alternative Energy
    • Energy Hub
    • Environment Issues
    • GreenBiz
    • Renewable News
    • Uncategorized
    • Wind Energy

    Type above and press Enter to search. Press Esc to cancel.