11 ms·
YubiKey still selling old stock with vulnerable firmware
FYI, YubiKey is apparently still selling old stock with firmware vulnerable to the EUCLEAK attack instead of disposing of them, as a reader of Fefe's Blog reported:
https://blog.fefe.de/?ts=99ccc8dc
- m3kw9 2y agoA lot of hardware is vulnerable but still being sold. All hardware is infact
- hobobaggins 2y agoHopefully not hardware with known vulnerabilities.
- ta988 2y agoA lot of IoT devices, cameras, alarm systems, car components have known vulns and are still sold...
- whiskey-one 2y agoIt might make sense for a product that is hard to patch due to a more complex manufacture to drain supplies before updating. For a security product that is known to be vulnerable it is not forgivable to keep shipping.
- Hackbraten 2y agoI’d say security cameras and alarm systems are security products, too.
- m3kw9 2y agoAlmost every hardware have known vulnerabilities, you can't just take things off shelves once one is found, they don't have a money printer.
- SushiHippie 2y agoRelevant bit: > Update: Ist sogar noch krasser, wie ein Leser anmerkt: > zu der Yubikey-Geschichte sei noch angemerkt, dass die aktuell sogar so dreist sind erstmal ihre Lagerbestände mit verwundbaren Keys abzuverkaufen anstatt die zu verschrotten. Hab neulich zwei von den Dingern bestellt (die teure FIPS-Variante!) und was bekomme ich geliefert? Die Keys mit der alten, verwundbaren Firmware. Hintergrund soll wohl sein, dass die zunächst Behörden und andere "priorisierte" Kunden mit den Keys mit der neuen Firmware beliefern. Machine Translation: > Update: It's even more extreme, as a reader points out: > Regarding the Yubikey story, it should be noted that they are currently so brazen as to sell off their stock of vulnerable keys instead of scrapping them. I recently ordered two of those things (the expensive FIPS version!) and what do I get delivered? The keys with the old, vulnerable firmware. The background seems to be that they are initially supplying authorities and other "prioritized" customers with the keys that have the new firmware.
- snvzz 2y agowtf. And these YubiKey aren't exactly cheap. You'd expect the price to cover whatever they have to do on their end so that you do not receive a known vulnerable device.
- consp 2y agoAFAIK key extraction is not allowed by 140-2. Weird to call it FIPS approved.
- wlonkly 2y agoFIPS certified, which means a validation certificate exists. (And it does: https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/3907 https://csrc.nist.gov/projects/cryptographic-module-validati..., issued 2021.)
- guenthert 2y agooff topic, but I'm so mesmerized, I can't help it -- the translation is just perfect, even though the original is ripe with colloquialism. Not too long ago, this was SciFi.
- Modified3019 2y agoI hadn’t noticed the announcement of the vulnerability, looks like it’s nothing I care about for my “thread model”. https://www.theverge.com/2024/9/4/24235635/yubikey-unfixable-security-vulnerability-side-channel-explot https://www.theverge.com/2024/9/4/24235635/yubikey-unfixable... >“The attacker would need physical possession of the YubiKey, Security Key, or YubiHSM, knowledge of the accounts they want to target, and specialized equipment to perform the necessary attack,” the company said in its security advisory. “Depending on the use case, the attacker may also require additional knowledge including username, PIN, account password, or authentication key.” But those aren’t necessarily deterrents to a highly motivated individual or state-sponsored attack.
- joecool1029 2y agoIf I recall RSA keys on an affected unit are also not impacted.
- noinsight 2y agoYeah, but what isn't ever(?) mentioned is, "other" ECC keys are (should be) impacted by this too, not just FIDO2, i.e. ECC smart card certificates if you're using those.
- joecool1029 2y agoThat's why I said it. I primarily use mine for signing commits with gpg. This use case isn't impacted since I use rsa keys.
- zahlman 2y agoThe attacker would need physical possession of the [key]... Depending on the use case, the attacker may also require additional knowledge including... PIN, account password, or authentication key. If you already had both these things, any vulnerability in the key's firmware would be moot, surely? It's hardly a surprise that 2FA can be compromised by compromising both factors.
- GauntletWizard 2y agoI would gladly take an old stock yubikey at a discount - my threat model doesn't have a serious need for resistance to stolen keys, because at the user level they're unlikely to not notice them missing for long enough to successfully attack and then replace to a keychain.
- telgareith 2y agoYou're joking, right?
- mynameisvlad 2y agoThe vulnerability, as another commenter mentions, is extremely hard to exploit and requires both physical access and the specific accounts to clone the key for. That may be too much of a risk for enterprises, but as a personal security key? That seems like a completely reasonable choice to make.
- GauntletWizard 2y agoNo, I'm not. I've got a bunch of yubikeys locked in lockboxes when they're not in use, serving as trust anchors for internal PKI, but also using certificate logging. If one is compromised, there's a short window until it's known, and access to the box has a very small group of people. My threat model does not include "Insider under the watchful eye of two other insiders"
- wannacboatmovie 2y ago> My threat model does not include "Insider under the watchful eye of two other insiders" Some Mastodon infosec grifter is going to name this "Insider Triple Threat".
- deleted 2y ago[deleted]
- technion 2y ago
- nine_k 2y agoIf I consider buying a security token similar to a Yubikey, I'll try hard to buy one with open firmware, and preferably open enough hardware. Something that has been independently inspected, and something that allows me to load the firmware I control and can inspect. (The ability to only load it once would be fine; an ability to securely update it would be really nice.)
- captainepoch 2y agoJust go with Nitrokey, the software is, at least, published at GitHub https://github.com/Nitrokey https://github.com/Nitrokey
- echelon 2y agoClassic strategy. Market leader is closed source. Follower attempts to be open source to gain market share despite being behind in features and market. Has this strategy ever worked? Gitlab went public, but it's barely a fraction of what GitHub is. Framework laptops aren't really all that big. Maybe Android? But it had huge backing.
- notpushkin 2y agoYeah, not enough people care about open source right now. Maybe after this incident more will! In any case you're right, if you try doing open source purely as a marketing tactic it may or may not work out. I think one good reason to do open source is because you believe it's more sustainable, or transparent, or just being decent to your customers.
- eco 2y agoBitWarden went this route against LastPass. They've had their own closed source component contoversies lately though.
- elashri 2y agoThe password manager market does not have a dominant player like Github vs Gitlab (others). Actually this would be more true if you add non commercial offerings like Keychain passwords, Google passwords and Firefox (other browsers password managers). Lastpass didn't have a majority at anytime. And their decline is related more to thei breaches and horrible practices. They are trying to be relevant now. They offered my university free subscription for all students and faculty and still people don't even consider them. At least this is among people who consider password managers. Also for bitwarden the controversy was about their SDK licence being proprietary but they re-licenced to open source [1] [1] https://news.ycombinator.com/item?id=41940580 https://news.ycombinator.com/item?id=41940580
- CarpaDorada 2y agoIf you lose your YubiKey, or any other hardware key, for all intents and purposes all your data on it is compromised. What I'm reading from <https://ninjalab.io/eucleak/ https://ninjalab.io/eucleak/> is this: >This vulnerability – that went unnoticed for 14 years and about 80 highest-level Common Criteria certification evaluations – is due to a non constant-time modular inversion. The vulnerability is therefore that the secrets can be extracted without taking the YubiKey apart, by measuring timings, thus tricking you into thinking that your YubiKey is intact (but you were already compromised the moment you could not account for the location of the YubiKey). On the other hand, a well motivated adversary can take apart your YubiKey, extract the secrets through other means (every hardware key is vulnerable to this) and finally put together a new YubiKey, identical on the outside to your old YubiKey, with the same secrets. The two scenarios are almost the same, unless you're biotagging your YubiKey (which only buys you knowledge that you've been compromised). If Yubico is selling these keys, it's because it would be too expensive for them to clearly label the firmware version on each YubiKey sold, for various reasons. I think this is a great opportunity for a competitor to arise, who hopefully allows flashing of the firmware, at a minimum. The Nitrokey seems like a good option <https://www.nitrokey.com/ https://www.nitrokey.com/>.
- palata 2y ago> The Nitrokey seems like a good option <https://www.nitrokey.com/ https://www.nitrokey.com/>. My experience with Nitrokey is different. I trust Yubico for my threat model, I just don't trust Nitrokey at all. They seem to have more products than employees and in my experience they have a history of advertising/selling features they don't have.
- palata 2y agoFor those who downvote me, let me add some context. I count 14 employees in the company picture [1]. They say "up to 20 employees". I assume not everyone is a software developer. They have 1. Nitrokey 2. NitroPhone 3. NitroTablet 4. NitroPad 5. NitroPC 6. NextBox 7. NitroWall 8. NetHSM which look like very different products. On top of this, they have consulting services and NitroChat (not clear to me if it is just a branded Matrix instance) and "Android FIDO SDK" (which for some reason points to https://hwsecurity.dev/ https://hwsecurity.dev/, which doesn't exactly seem to be a Nitrokey product). That seems like a lot for 14-20 employees. But then my experience was with the Nitrokey 3 NFC. They advertised all the main features that Yubikey had and accepted pre-orders. They claimed that the software was ready, in Rust and open source (!), and that it would just take a few months for the hardware. It took 2 years, and when I finally received my Nitrokey, none of the software was ready (it had just one feature, maybe FIDO?). Finally, it is great that it is open source, but the fact that it is flashable does not sound like a security feature to me: doesn't it mean that an attacker could flash a malicious firmware on it from a compromised computer? [1]: https://www.nitrokey.com/about https://www.nitrokey.com/about
- randompeach 2y agoI personally find token2 really nice.
- MaKey 2y agoThanks, their devices look interesting. Open source firmware and good pricing.
- jnsaff2 2y agoAnd when you do order a single key from them be prepared for a barrage of passive-aggressive sales e-mail along the lines "I wanted to discuss your rollout plan".
- atoav 2y agoThe problem here is that depending on your threat model it might be important for customers to trust Yubico not to sell out against rich/powerful attackers. This behavior adds a datapoint that speaks against them, even if they are technically correct. I do not expect a manufacturer of such hardware to be like: "Eh it is okay" when skipping the fix to their IC manufacturers fuckup saves them money, I expect them to go out of their way to protect their customers. Seen like this their refusal to replace compromised keys was already brazen, them selling compromised keys constitutes a breach of trust. I am already researching for alternatives.
- palata 2y ago> Seen like this their refusal to replace compromised keys was already brazen, Does it really sound crazy that they would not replace all the keys they ever sold? At that price, it feels like it's obviously part of the deal. If you want to buy a security key that will get audited every day by 10 experts and receive new versions delivered in your hands by approved staff, I guess you should expect to pay more than 50 bucks, right? > them selling compromised keys constitutes a breach of trust. Some anonymous reader of some blog claims it. It doesn't mean it's true, does it? For what I can see, it says on the Yubico store which version of the firmware I am getting. Can anyone confirm that they ordered the new version, received the old version and Yubico refused to exchange that?
- atoav 2y agoOf course they would like to avoid replacing every (affected) key they ever sold if they don't absolutely have to. But if they sold cars and this was a defective airbag they would have been forced to replace them. You as a manufacturer are responsible for the products you bring to market — don't want to recall your products? Then ensure they work and you don't put all your eggs in one basket. In this case Yubico is very likely not legally bound to recall, but I made a case how this is an issue of trust. You know what would have been a good move? A deal where you can order a new one at strongly reduced prices if you can show you had an affected device, or something among those lines. Or selling the affected ones for cheap and give the customers the choice. There are many ways to deal with that situation in a better way than they did and they decided to choose the one that helped their very short term bottom line the most. As a owner of an affected Yubikey I have to saybthat the whole episode put an questionmark behind thir product for me. Not because it was affected, because of how they dealt with it.
- mrtx01 2y agoThank you so much! My client was in the final stage of selecting security tokens. They have contracts with administration and their tokens need to be secure. I was strongly for yubikeys, now they will not be an option any longer. It is not so much about the flaw, but about their handling of the broken security tokens, still claiming them to be somehow secure-ish. Even if they offered us the new tokens, that wouldn't make a difference. Their claim to making the internet more secure for all, contradicts their attitude. That is really disappointing.
- TheNewsIsHere 2y agoThat seems really reactionary based on a single random report posted to HN. It’s worth actually verifying if this was intentional or accidental. They’re marketing the keys as having the new firmware. It would be really idiotic to do that and then intentionally ship old firmware. Anyone and everyone would be able to figure that out in an instant, and would severely damage their business.
- mrtx01 2y agoI was in contact with a Sr. Customer Support Specialist from Yubico and I was not impressed by their denial of a problem. The reason to get such a Hardware Token is, that the private key cannot be extracted, even if the users lose it. They have plausible deniability for fraud with the broken devices. Claiming that this would not be a problem and trying to explain why it is not a problem without considering their client could be right, is pure arrogance. Only a complete exchange of the whole management of yubico could save them, when they want to be taken seriously ever again. And of course the new management should immediately offer a cost free exchange program. D'oh.
- MaKey 2y agoThe report can be verified by visiting the product page of the YubiKey 5 NFC FIPS: https://www.yubico.com/us/product/yubikey-5-fips-series/yubikey-5-nfc-fips/ https://www.yubico.com/us/product/yubikey-5-fips-series/yubi... It is listed with the vulnerable firmware 5.4.
- cerved 2y agoWhere did this unknown individual buy the keys and when? I see a lot of smoke but where is the fire?
- deleted 2y ago[deleted]
- craig0816 2y agoThey also refuse to swap out vulnerable keys for high security environments where customers require to "update or replace any system with known vulnerabilites."
- bigjay517 2y agoIs this really true? Looking at the Yubikey Shop I see that the purchase page explicitly states that the key is shipped with Firmware 5.7 (the fixed version). If a device is received with the old firmware, I would believe that this not intentional and support would resolve the problem.
- MaKey 2y agoThey're still selling the FIPS series with firmware 5.4: https://www.yubico.com/us/product/yubikey-5-fips-series/yubikey-5-nfc-fips/ https://www.yubico.com/us/product/yubikey-5-fips-series/yubi...
- palata 2y ago> as a reader of Fefe's Blog reported My understanding is that the blog post complains about the fact that there was a security vulnerability in Yubikeys and that Yubico doesn't exchange everything they have sold until now. But it makes sense to me: I buy a Yubikey at time T, with firmware F that by design cannot be modified. I don't buy a subscription that will provide me with an updated key every month, it's a one-off. Until the security flaw was discovered, my keys were fine. So I paid 50$ per key for 4 years, I don't think it's exactly expensive. Now there are two questions for me: 1. Should I replace my keys? In my case, I don't think so (given my threat model) 2. Should I stop trusting Yubico? I don't think so. It doesn't seem like this flaw is due to a total incompetence from their part. If I stopped trusting software every time a critical flaw was discovered, I wouldn't use software anymore. The blog post then goes on claiming that Yubico pretends that they sell keys with the updated firmware (on their store, it clearly says if I am ordering a key with firmware 5.7 or not) but sell keys with older firmware. That would be pretty bad from Yubikey, but the blog gives absolutely no proof. It could as well just be an empty claim to hurt Yubico's reputation, for what I see.
- MaKey 2y agoThe FIPS Series shows firmware 5.4: https://www.yubico.com/us/product/yubikey-5-fips-series/yubikey-5-nfc-fips/ https://www.yubico.com/us/product/yubikey-5-fips-series/yubi... Instead of stopping the sale of them, they're dumping old stock on unsuspecting customers.
- palata 2y agoRight, I don't see an explanation of what it means to have firmware 5.4. Probably they should add something there.
- fmajid 2y agoHmmm. Not excusing Yubico if the report is accurate, but I ordered 4x 5C NFC to replace my old keys, and they shipped with firmware 5.7.1 which does not have that vulnerability. Perhaps because they got the FIPS version, which is actually less secure because of NSA-borked protocols, but required for government compliance, and probably sells in lower quantities. The 5.7 firmware was released in May and so new-old-stock of the vulnerable firmware should have rotated out a while ago.
- matheusmoreira 2y agoThe new set of keys I bought earlier this year are affected. Last time a vulnerability like this one was discovered, they sent me a new replacement key. It appears that's not gonna happen this time. Really disappointed.
- runjake 2y agoThe Yubico support article for this issue: https://support.yubico.com/hc/en-us/articles/15705749884444-Infineon-ECDSA-Private-Key-Recovery-Customer-Resources https://support.yubico.com/hc/en-us/articles/15705749884444-... Spoiler: none of the options are warranty replacement.
- matheusmoreira 2y agoYeah, it's really disappointing. They've replaced defective vulnerable keys before. https://www.yubico.com/support/security-advisories/ysa-2017-01/ https://www.yubico.com/support/security-advisories/ysa-2017-...