Connect with us

Hi, what are you looking for?

Your Profit SpringYour Profit Spring

Tech News

YubiKeys have an unfixable security flaw

The flaw doesn’t impact newer YubiKey hardware that doesn’t use the Infineon cryptolibrary. | Image: Yubico

Security researchers have detected a vulnerability in YubiKey two-factor authentication tokens that enables attackers to clone the device according to a new security advisory. The vulnerability was discovered within the Infineon cryptographic library used by most YubiKey products, including the YubiKey 5, Yubikey Bio, Security Key, and YubiHSM 2 series devices.

YubiKey manufacturer Yubico says the severity of the side-channel vulnerability is “moderate” but is difficult to exploit, partly because two-factor systems rely upon something the user has and something only they should know.

“The attacker would need physical possession of the YubiKey, Security Key, or YubiHSM, knowledge of the accounts they want to target, and specialized…

Continue reading…

You May Also Like

Tech News

The new adaptive charging feature could help to save power and preserve the life of controller batteries. | Photo by Amelia Holowaty Krales /...

Tech News

The latest Netflix app update will require Apple devices to run iOS 17 or later. | Illustration by Alex Castro / The Verge The...

World News

In theory, the question should have been easy. Debate moderator Linsey Davis on Tuesday night pointed out to former president Donald Trump that he...

Tech News

Hi, friends! Welcome to Installer No. 32, your guide to the best and Verge-iest stuff in the world. (If you’re new here, welcome, happy...