4 ms·
Don't know who they are but there's some speculation that Yubico is Crypto AG like.
by plugger 7y ago
Don't know who they are but there's some speculation that Yubico is Crypto AG like.
- ghostpepper 7y agoCan you link to a source for that?
- plugger 7y agoHave a look at the comments regarding the recent Crypto AG story here. There's some insinuation in there.
- ghostpepper 7y agoThis one? https://news.ycombinator.com/item?id=22297963 https://news.ycombinator.com/item?id=22297963 I did a ctrl + f on both pages of comments for "yubi" with no results. Sorry if I've missed something obvious.
- motohagiography 7y agoThis is testable, and also very difficult to falsify without testing it. I'd say there is more value in doing or sponsoring the research to investigate it and I wouldn't cast aspersions on the vendors. They are better than passwords for the majority of consumer and corporate use cases. The most basic attack and test is to verify and/or reduce the entropy of secret symmetrical (AES) keys in the SE after personalization. The challenge with hardware security modules is verifying outputs from the same keys but on different devices, because the key is derived/instantiated in the secure tamper proof environment. The whole point is the key doesn't exist anywhere else. If your threat model includes the intelligence agencies of super powers, your main problem is more diplomatic than technical.
- lawnchair_larry 7y agoNot by anyone with half a clue there isn’t.
- tptacek 7y agoThis is such a lame conspiracy theory that me and lawnchair_larry are on the same side of it.