Yubico two-factor authentication key vulnerability - You got one maybe read this.

Dopious

Elite Member
Jr. VIP
Joined
Apr 4, 2009
Messages
13,911
Reaction score
70,938
@xReminisce tipped about this in a PM earlier this morning , so I thought I paste it in the forum too since she have not.

Unpatchable Yubico two-factor authentication key vulnerability breaks the security of most Yubikey 5, Security Key, and YubiHSM 2FA devices Unpatchable Yubico two-factor authentication key vulnerability breaks the security of most Yubikey 5, Security Key, and YubiHSM 2FA devices.

An unpatchable Yubico two-factor authentication key vulnerability has broken the security of most Yubikey 5, Security Key, and YubiHSM 2FA devices. The Feitian A22 JavaCard is also vulnerable. Vulnerable 2FA keys should be replaced as soon as possible, especially when used to secure cybercurrency or top-secret information.

Source: https://www.notebookcheck.net/Unpat...ity-Key-and-YubiHSM-2FA-devices.883661.0.html
 
Good old side channel attack at work again!! I don’t have a yubi key so I guess i am safe… But in any case, don’t throw them away yet lol. The attacker still has to have physical access to the hardware to do this….
 
It’s not that bad. Only effects the older keys. You’ll need physical access to the encrypted device. Also an NSA level technical set-up and know-how to actually attempt to hack the thing too. I imagine anyone who would really have to worry about this isn’t using these older keys anyway.
 
@xReminisce tipped about this in a PM earlier this morning , so I thought I paste it in the forum too since she have not.

Unpatchable Yubico two-factor authentication key vulnerability breaks the security of most Yubikey 5, Security Key, and YubiHSM 2FA devices Unpatchable Yubico two-factor authentication key vulnerability breaks the security of most Yubikey 5, Security Key, and YubiHSM 2FA devices.

An unpatchable Yubico two-factor authentication key vulnerability has broken the security of most Yubikey 5, Security Key, and YubiHSM 2FA devices. The Feitian A22 JavaCard is also vulnerable. Vulnerable 2FA keys should be replaced as soon as possible, especially when used to secure cybercurrency or top-secret information.

Source: https://www.notebookcheck.net/Unpatchable-Yubico-two-factor-authentication-key-vulnerability-breaks-the-security-of-most-Yubikey-5-Security-Key-and-YubiHSM-2FA-devices.883661.0.html
time to get back to pencil and paper, ladies and gentlemen!
 
@xReminisce tipped about this in a PM earlier this morning , so I thought I paste it in the forum too since she have not.

Unpatchable Yubico two-factor authentication key vulnerability breaks the security of most Yubikey 5, Security Key, and YubiHSM 2FA devices Unpatchable Yubico two-factor authentication key vulnerability breaks the security of most Yubikey 5, Security Key, and YubiHSM 2FA devices.

An unpatchable Yubico two-factor authentication key vulnerability has broken the security of most Yubikey 5, Security Key, and YubiHSM 2FA devices. The Feitian A22 JavaCard is also vulnerable. Vulnerable 2FA keys should be replaced as soon as possible, especially when used to secure cybercurrency or top-secret information.

Source: https://www.notebookcheck.net/Unpatchable-Yubico-two-factor-authentication-key-vulnerability-breaks-the-security-of-most-Yubikey-5-Security-Key-and-YubiHSM-2FA-devices.883661.0.html
What about flipper zero? Also has 2FA.
 
Now somehow they make a FIDO like this
I guess you can get a button - Add a security key, but I don't know how.
 

Attachments

  • photo_2025-03-21_15-19-02.jpg
    photo_2025-03-21_15-19-02.jpg
    7.2 KB · Views: 3
Back
Top