5 ms·
I hadn’t noticed the announcement of the vulnerability, looks like it’s nothing I care about for my “thread model”. https://www.theverge.com/2024/9/4/24235635/
by Modified3019 2y ago
I hadn’t noticed the announcement of the vulnerability, looks like it’s nothing I care about for my “thread model”.
https://www.theverge.com/2024/9/4/24235635/yubikey-unfixable-security-vulnerability-side-channel-explot https://www.theverge.com/2024/9/4/24235635/yubikey-unfixable...
>“The attacker would need physical possession of the YubiKey, Security Key, or YubiHSM, knowledge of the accounts they want to target, and specialized equipment to perform the necessary attack,” the company said in its security advisory. “Depending on the use case, the attacker may also require additional knowledge including username, PIN, account password, or authentication key.” But those aren’t necessarily deterrents to a highly motivated individual or state-sponsored attack.
- joecool1029 2y agoIf I recall RSA keys on an affected unit are also not impacted.
- noinsight 2y agoYeah, but what isn't ever(?) mentioned is, "other" ECC keys are (should be) impacted by this too, not just FIDO2, i.e. ECC smart card certificates if you're using those.
- joecool1029 2y agoThat's why I said it. I primarily use mine for signing commits with gpg. This use case isn't impacted since I use rsa keys.
- zahlman 2y agoThe attacker would need physical possession of the [key]... Depending on the use case, the attacker may also require additional knowledge including... PIN, account password, or authentication key. If you already had both these things, any vulnerability in the key's firmware would be moot, surely? It's hardly a surprise that 2FA can be compromised by compromising both factors.
- Sayrus 2y agoThe vulnerability allows extracting the secret key from a vulnerable device. If I remember correctly, it's after a successful auth / sign flow, which requires the login/password of the target website. I could give you my security key and you'll be able to login once. If you can extract the key, then you could login without the security key. In the context of a targeted attack, that could heavily change the impact.
- Y_Y 2y agoIf you're paranoid, of course, you're not going to trust a key that's left your possession, even if you get it back later. One it's gone it should be revoked permanently.
- chrisjj 2y agoThat presumes you'd know.
- Y_Y 2y agoIt does. If you can get my yubikey off my keyring while it's in my pocket and put it back on without my noticing then I don't know how I can defend against that.
- nativeit 2y agoSort of like how several plot points of the last Mission: Impossible movie could have been thwarted by a zipper.
- chrisjj 2y ago... in hindsight :)
- chrisjj 2y ago> If you can get my yubikey off my keyring while it's in my pocket and put it back on without my noticing Yubikey security advisory: "Due to software vulnerability, always store in pocket". :)
- croes 2y agoYou should care about a seller who sells products with known flaws.
- userbinator 2y agoEvery product has "known flaws".
- chrisjj 2y agoYou should care about the seller who conceals them at sale.
- mihaaly 2y agoAlmost every known product maker make procedures around having a vulnerable product and advertises it as 'securing your data has the utmost importance' while releasing thick stream of security patches on the back of patches, more than not making updates mandatory this way or the other. 'We may finish that later sometime after sales' kind of product development.
- lxgr 2y agoNot in this particular case. Here, it's more like "buy our new product if you care enough about the latest vulnerability; the old one is unpatchable by design".
- croes 2y agoKnown to the seller or the buyer?