2 ms·
The attack surface may seem smaller for USB tokens, but storing the pin for say a Yubikey allows malware to use the key without restriction. Also, these USB dev
by 4kevinking 9y ago
The attack surface may seem smaller for USB tokens, but storing the pin for say a Yubikey allows malware to use the key without restriction. Also, these USB devices don't have a UI, so you never know what you are actually approving, i.e. which username or server you are logging into.
- packetized 9y agoErm, not true - changing the Yubikey setting to require a touch for key use (S/C/E) is trivial. Malware can't use it without restriction if it requires you to physically touch it every time you want to approve use.
- 4kevinking 9y agoPoint taken. Unfortunately when you touch the key you still can't verify exactly what you are approving.
- simonvc 9y agoThere's a GPG/SSH applet for the ledger Nano S now that has a tiny screen and buttons...
- wwwv 9y agoSo, capture the auth and use it for the malware, show the user some failure and allow their retry to pass. Stupid dodgy Yubikey fails half the time.