YubiKeys are vulnerable to cloning attacks due to side channel
by Homebrewer - Wednesday September 4, 2024 at 02:17 PM
#1
For crypto holders out there, do be wary of your keys/wallets:

Quote:The YubiKey 5, the most widely used hardware token for two-factor authentication based on the FIDO standard, contains a cryptographic flaw that makes the finger-size device vulnerable to cloning when an attacker gains temporary physical access to it, researchers said Tuesday.

The cryptographic flaw, known as a side channel, resides in a small microcontroller used in a large number of other authentication devices, including smartcards used in banking, electronic passports, and the accessing of secure areas. While the researchers have confirmed all YubiKey 5 series models can be cloned, they haven’t tested other devices using the microcontroller, such as the SLE78 made by Infineon and successor microcontrollers known as the Infineon Optiga Trust M and the Infineon Optiga TPM. The researchers suspect that any device using any of these three microcontrollers and the Infineon cryptographic library contains the same vulnerability.

Source: https://arstechnica.com/security/2024/09...e-channel/
Reply
#2
copy paste the key
[center]
PGP Key: https://pastebin.com/raw/BMbXaW3a
8692 8F47 E83E 6C5C
[/center]
Reply
#3
Just have to make sure that your hardware wallet doesn't use the same microcontroller.
Obviously limit physical access to it in any case.
Reply
#4
>The offline phase took us about 24 hours; with more engineering work in the attack development, it would take less than one hour
>CVSS 4.9


seems to me that it's just academics jerking off, again
Reply
#5
So a flaw in the crypto libe right, and not affecting RSA?
Reply
#6
(Sep 12, 2024, 05:13 PM)joepa Wrote: So a flaw in the crypto libe right, and not affecting RSA?

No it's not affecting RSA, it's in the Extended Euclidean Algorithm that's used for modular inversion in ECDSA
Reply
#7
This is bad but not too terrible. This attack requires physical access.
With normal usage, you're still safe from key stealing malware, and if you added a PIN you are still safe.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  NO LOGS VPN: Best VPN for clear and dark web Crockett 362 69,000 May 09, 2026, 01:58 PM
Last Post: vladimirPuk1ng
  ? Bill Gates Shares Microsoft’s Original Source Code Teko 9 825 Feb 05, 2026, 11:11 AM
Last Post: xeyro
  [LLM] Malware dev and Hacking is getting easier brianoconnor 5 398 Feb 02, 2026, 01:09 PM
Last Post: pam2s
  ShinyHunters claim hacks of Okta, Microsoft SSO accounts for data theft joepa 0 317 Jan 25, 2026, 11:48 AM
Last Post: joepa
  Microsoft Gave FBI Keys To Unlock Encrypted Data, Exposing Major Privacy Flaw joepa 0 271 Jan 24, 2026, 11:31 AM
Last Post: joepa

Forum Jump:


 Users browsing this forum: 1 Guest(s)