Connect with us

Hi, what are you looking for?

Your Profit SpringYour Profit Spring

Tech News

YubiKeys have an unfixable security flaw

The flaw doesn’t impact newer YubiKey hardware that doesn’t use the Infineon cryptolibrary. | Image: Yubico

Security researchers have detected a vulnerability in YubiKey two-factor authentication tokens that enables attackers to clone the device according to a new security advisory. The vulnerability was discovered within the Infineon cryptographic library used by most YubiKey products, including the YubiKey 5, Yubikey Bio, Security Key, and YubiHSM 2 series devices.

YubiKey manufacturer Yubico says the severity of the side-channel vulnerability is “moderate” but is difficult to exploit, partly because two-factor systems rely upon something the user has and something only they should know.

“The attacker would need physical possession of the YubiKey, Security Key, or YubiHSM, knowledge of the accounts they want to target, and specialized…

Continue reading…

You May Also Like

Business

Chinese bargain retailer Temu changed its business model in the U.S. as the Trump administration’s new rules on low-value shipments took effect Friday. In recent days,...

Tech News

The latest Netflix app update will require Apple devices to run iOS 17 or later. | Illustration by Alex Castro / The Verge The...

Tech News

The new adaptive charging feature could help to save power and preserve the life of controller batteries. | Photo by Amelia Holowaty Krales /...

Business

U.S. pharmacy chain Rite Aid on Monday filed for bankruptcy protection for the second time in as many years, according to a court filing....