3 ms·
If you have a Yubi Key and you are worried, read this part from their report: > the adversary needs to open the device (...) Then the device must be re-package
by jacekm 2y ago
If you have a Yubi Key and you are worried, read this part from their report:
> the adversary needs to open the device (...) Then the device must be re-packaged and quietly returned to the legitimate user (...) assuming one can find a reliable way to open and close the device, we did not work on this part
Yubi Keys are supposed to be tamper-evident and you can also put tamper-evident stickers on them. I am more concerned that a determined attacker may eventually find a way to record the signals without having to remove the casing.
- mzs 2y agoOnce it's cloned can't the attacker create a new one for you that looks like the previous one you had?
- cvhc 2y agoIn the FIDO2 case, only the derived keys are extracted. The master key that derives non-resident keys isn't extracted. So I think it's not possible to really copy the key. In the cases of FIDO2 resident keys (passkey) / PIV / GPG, maybe it's possible to extract and copy the exact keys. But I guess it can be detected through attestations. And I just looked at ykman command. It doesn't seem to allow you to import a passkey to a Yubikey.