4 ms·
If you lose your YubiKey, or any other hardware key, for all intents and purposes all your data on it is compromised. What I'm reading from <https://ninjalab.i
by CarpaDorada 2y ago
If you lose your YubiKey, or any other hardware key, for all intents and purposes all your data on it is compromised.
What I'm reading from <https://ninjalab.io/eucleak/ https://ninjalab.io/eucleak/> is this:
>This vulnerability – that went unnoticed for 14 years and about 80 highest-level Common Criteria certification evaluations – is due to a non constant-time modular inversion.
The vulnerability is therefore that the secrets can be extracted without taking the YubiKey apart, by measuring timings, thus tricking you into thinking that your YubiKey is intact (but you were already compromised the moment you could not account for the location of the YubiKey). On the other hand, a well motivated adversary can take apart your YubiKey, extract the secrets through other means (every hardware key is vulnerable to this) and finally put together a new YubiKey, identical on the outside to your old YubiKey, with the same secrets.
The two scenarios are almost the same, unless you're biotagging your YubiKey (which only buys you knowledge that you've been compromised). If Yubico is selling these keys, it's because it would be too expensive for them to clearly label the firmware version on each YubiKey sold, for various reasons. I think this is a great opportunity for a competitor to arise, who hopefully allows flashing of the firmware, at a minimum. The Nitrokey seems like a good option <https://www.nitrokey.com/ https://www.nitrokey.com/>.
- palata 2y ago> The Nitrokey seems like a good option <https://www.nitrokey.com/ https://www.nitrokey.com/>. My experience with Nitrokey is different. I trust Yubico for my threat model, I just don't trust Nitrokey at all. They seem to have more products than employees and in my experience they have a history of advertising/selling features they don't have.
- palata 2y agoFor those who downvote me, let me add some context. I count 14 employees in the company picture [1]. They say "up to 20 employees". I assume not everyone is a software developer. They have 1. Nitrokey 2. NitroPhone 3. NitroTablet 4. NitroPad 5. NitroPC 6. NextBox 7. NitroWall 8. NetHSM which look like very different products. On top of this, they have consulting services and NitroChat (not clear to me if it is just a branded Matrix instance) and "Android FIDO SDK" (which for some reason points to https://hwsecurity.dev/ https://hwsecurity.dev/, which doesn't exactly seem to be a Nitrokey product). That seems like a lot for 14-20 employees. But then my experience was with the Nitrokey 3 NFC. They advertised all the main features that Yubikey had and accepted pre-orders. They claimed that the software was ready, in Rust and open source (!), and that it would just take a few months for the hardware. It took 2 years, and when I finally received my Nitrokey, none of the software was ready (it had just one feature, maybe FIDO?). Finally, it is great that it is open source, but the fact that it is flashable does not sound like a security feature to me: doesn't it mean that an attacker could flash a malicious firmware on it from a compromised computer? [1]: https://www.nitrokey.com/about https://www.nitrokey.com/about
- CarpaDorada 2y agoFlashing firmware makes it easier to compromise an unattended hardware key but as I said above every hardware key could be considered compromised in this sense. Pre-order generally come with stipulations on when you receive the product and what it will be. NitroChat is them running a Matrix chat server for you, they probably intend to have integrations with their Nitrokey. The SDK mentions that it is "Offered in partnership with Hardware Security SDK by heylogin GmbH", the intend of heylogin GmbH is to charge you for commercial use of the SDK. Them having less than 20 employees makes sense, it's a niche market. What it comes down to is that YubiKeys have better integration but Nitrokeys are more fun if you want to hack on them, and it's not really a matter of security. Note that smart cards in general can be used for the same purposes, e.g. Java Cards. USB keys do not require you to carry around a card reader.
- palata 2y ago> Flashing firmware makes it easier to compromise an unattended hardware key but as I said above every hardware key could be considered compromised in this sense. Isn't there a difference between your compromised laptop being able to reflash your Nitrokey and your compromised laptop not being able to reflash your Yubikey, though? > Them having less than 20 employees makes sense, it's a niche market. Maybe, but they sell 8 different hardware products. Have you ever been involved in a hardware product? I have, and it feels like they must not put a lot of resources on them. Which is kind of proven in my experience with the fact that my Nitrokey arrived 2 years after I ordered it and by then, only a fraction of the software had been written.
- r-w 2y ago> biotagging Sorry, what does this mean? I couldn’t find anything on Google about it.