Get the latest tech news

YubiKeys Are Vulnerable To Cloning Attacks Thanks To Newly Discovered Side Channel


The YubiKey 5, the most widely used hardware token for two-factor authentication based on the FIDO standard, contains a cryptographic flaw that makes the finger-size device vulnerable to cloning when an attacker gains brief physical access to it, researchers said Tuesday. ArsTechnica: The cryptograp...

The YubiKey 5, the most widely used hardware token for two-factor authentication based on the FIDO standard, contains a cryptographic flaw that makes the finger-size device vulnerable to cloning when an attacker gains brief physical access to it, researchers said Tuesday. ArsTechnica: The cryptographic flaw, known as a side channel, resides in a small microcontroller that's used in a vast number of other authentication devices, including smartcards used in banking, electronic passports, and the accessing of secure areas. YubiKey-maker Yubico issued an advisory in coordination with a detailed disclosure report from NinjaLab, the security firm that reverse-engineered the YubiKey 5 series and devised the cloning attack.

Get the Android app

Or read this on Slashdot

Read more on:

Photo of thanks

thanks

Photo of attacks

attacks

Photo of YubiKeys

YubiKeys

Related news:

News photo

Yubikeys are vulnerable to cloning attacks thanks to side channel

News photo

Android phones will warn you of earthquakes in all 50 US states thanks to new update

News photo

'Unbreakable' quantum communication closer to reality thanks to new, exceptionally bright photons