FacebookInstagramTwitterContact

 

School Twinning Programme           >>           Participate in ASEAN Conference           >>           Informative Society Programme           >>           Politeknik Brunei Orientation Week for the 15th Intake           >>           Excellent Student Certificate Presentation Ceremony           >>           Fishermen's Day           >>           Rhythmic Speech Competition           >>           Panel Discussion on Workplace Safety           >>           Workplace Safety and Health Conference           >>           3rd ASEAN Forum: The Future of Finance           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 04:34 AM

Subuh

: 04:44 AM

Syuruk

: 06:09 AM

Doha

: 06:33 AM

Zohor

: 12:22 PM

Asar

: 03:48 PM

Maghrib

: 06:34 PM

Isyak

: 07:49 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


Yubikey Vulnerability Will Let Attackers Clone The Authentication Device


YubiKey

 


 September 6th, 2024  |  01:51 AM  |   455 views

ENGADGET

 

It's a very difficult and very expensive process, however.

 

NinjaLab, a security research company, has discovered a vulnerability that would allow bad actors to clone YubiKeys. As the company has explained in a security advisory, NinjaLab found a vulnerability in the cryptographic library used in the YubiKey 5 Series. In particular, it found a cryptographic flaw in the microcontroller, which the security researchers described as something that "generates/stores secrets and then execute cryptographic operations" for security devices like bank cards and FIDO hardware tokens. YubiKeys are the most well-known FIDO authentication keys, and they're supposed to make accounts more secure, since users would have to plug it into their computers before they could log in.

 

The researchers explained how they discovered the vulnerability because they found an open platform based on Infineon's cryptographic library, which Yubico uses. They confirmed that all YubiKey 5 models can be cloned, and they also said that the vulnerability isn't limited to the brand though they've yet to try and clone other devices.

 

That vulnerability has apparently gone unnoticed for 14 years, but just because it has now come to light doesn't mean anybody can exploit it to clone YubiKeys. To start with, bad actors will need to have physical access to the token they want to copy. Then, they have to take it apart and use expensive equipment, including an oscilloscope, to "perform electromagnetic side-channel measurements" needed to analyze the token. In the researchers' paper, they said their setup cost them around $11,000 and that using more advanced oscilloscopes could raise the setup's cost to $33,000. In addition, attackers might still need their target's PINs, passwords or biometrics to be able to access specific accounts.

 

Bottom line is that users part of government agencies or anybody handling very, very sensitive documents that could make them espionage targets would have to be very careful with their keys. For ordinary users, as researchers wrote in their paper, "it is still safer to use YubiKey or other impacted products as FIDO hardware authentication token to sign in to applications rather than not using one."

 


 

Source:
courtesy of ENGADGET

by Mariella Moon

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

How Trump's Tariff Chaos Could Reshape Asia's Businesses

 2025-07-07 10:22:30

Crying At Work: A Sign Of Strength, Weakness Or Just Being Human?

 2025-07-06 01:39:58