Close Menu
    What's Hot

    VW ID. Buzz Wins Two Notable Awards

    Lululemon’s global sustainability leader departs

    OMCO Solar – Celebrating Project 100

    Facebook X (Twitter) Instagram
    Eco Planet PowerEco Planet Power
    • Alternative Energy
    • Energy Hub
    • Environment Issues
    • GreenBiz
    • Renewable News
    • Wind Energy
    Eco Planet PowerEco Planet Power
    You are at:Home»Uncategorized»YubiKey vulnerability will let attackers clone the authentication device
    Uncategorized

    YubiKey vulnerability will let attackers clone the authentication device

    adminBy adminSeptember 7, 2024002 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    NinjaLab, a security research company, has discovered a vulnerability that could potentially allow bad actors to clone YubiKeys, as detailed in a security advisory. The flaw was found in the cryptographic library used in the YubiKey 5 Series, specifically in the microcontroller responsible for generating and storing secrets for security devices like bank cards and FIDO hardware tokens. YubiKeys are widely used FIDO authentication keys meant to enhance account security by requiring users to physically plug them into their computers for login. The researchers identified the vulnerability by analyzing an open platform based on Infineon’s cryptographic library utilized by Yubico. They confirmed that all YubiKey 5 models are susceptible to cloning and that the issue extends beyond this specific brand, although they have not attempted to replicate the vulnerability on other devices. Exploiting the vulnerability would require physical access to the target token, dismantling it, and using costly equipment like an oscilloscope to perform electromagnetic side-channel measurements for analysis. This security flaw, present for 14 years, may pose a threat primarily to government agencies or individuals handling sensitive information at risk of espionage, emphasizing the need for caution with YubiKeys. The researchers emphasize the importance of using YubiKeys as FIDO hardware authentication tokens for added security, highlighting that the required resources and expertise make exploiting the vulnerability challenging for most attackers.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleUK competition watchdog opens Ticketmaster probe after Oasis ticket debacle
    Next Article Over 1.4 million Ram 1500 trucks recalled to fix a bug in the anti-lock brake system
    admin
    • Website

    Related Posts

    Apple wins $250 in Masimo smartwatch patent case

    October 26, 2024

    Lyft will have to tell drivers how much they can truly earn, with evidence

    October 26, 2024

    Waymo raises $5.6 billion to fund Austin and Atlanta expansion

    October 26, 2024
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Renewable Energy Market and Growth Update 2023

    September 15, 202311 Views

    what’s next for DOE’s hydrogen and direct air capture hubs, and how to engage in the process

    April 26, 202310 Views

    Meta will pay $1.4 billion to Texas, settling biometric data collection suit

    July 30, 20244 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Comparison: The Maternal and Fetal Outcomes of COVID-19

    By adminJanuary 15, 2021

    Florida Surgeon General’s Covid Vaccine Claims Harm Public

    By adminJanuary 15, 2021

    Signs of Endometriosis: What are Common and Surprising Symptoms?

    By adminJanuary 15, 2021
    Most Popular

    Renewable Energy Market and Growth Update 2023

    September 15, 202311 Views

    what’s next for DOE’s hydrogen and direct air capture hubs, and how to engage in the process

    April 26, 202310 Views
    Categories
    • Alternative Energy
    • Energy Hub
    • Environment Issues
    • GreenBiz
    • Renewable News
    • Uncategorized
    • Wind Energy

    Type above and press Enter to search. Press Esc to cancel.