Not that this isn't justifiable... just the way it goes when most of the cash goes into development perhaps.
Not that this isn't justifiable... just the way it goes when most of the cash goes into development perhaps.
These are crypto hardened chips with obfuscated ASIC layouts and other details to prevent things like power line attacks and decapping. These aren't quite your run of the mill commodity chips.
Furthermore, Yubico stands behind their product. When someone hacked the key with a power line analysis attack, they released updated firmware [1]. When someone hacked the OpenPGP applet that I use for SSH, they replaced my Yubikey Neo in a hassle free manner [2].
> Not that this isn't justifiable... just the way it goes when most of the cash goes into development perhaps.
When you factor in the cost of pretending that security devices don't have issues and compare it to the cost of actually handling those issues, it may not be so bad.
[1] https://www.yubico.com/2014/04/improvements-physical-yubikey...
[2] https://www.yubico.com/2015/04/yubikey-neo-openpgp-security-...
[0] https://www.yubico.com/2015/02/big-debate-2048-4096-yubicos-...
[1] http://www.nxp.com/documents/short_data_sheet/A700X_FAM_SDS....