How to weaponize the Yubikey (2019)
blackhillsinfosec.com
blackhillsinfosec.com
Opening with that, this could've been a story about sending trojan YubiKeys to high-value targets.
(For example, trojan might do stealthy exfiltration of stored data via cellular, have cloned hardware IDs/secrets to aid other attack, be a sleeper that doesn't hack and risk detection until heuristics on stored data suggest high-value opportunity, etc. Things for which there's an advantage to it being in a YubiKey rather than USB Storage.)
"Hi, this is totally Yubico writing to you. Your YubiKey was affected by a security vulnerability. Please use the enclosed free replacement, which has corrected the problem. For all your most sensitive security needs."
Infineon is a company that makes “secure elements”.
In 2017, Infineon announced that the key-generation component of their chips was making RSA keys in a way that could be exploited[1]. Yubico had these secure elements in some of their Yubikey products. In the affected products, it affected key generation for PGP and PKCS#11 keys[2].
Affected customers could self-identify by checking their YubiKey model, firmware version, and how they were using it. If they were affected, they could apply for a free replacement. This was implemented by Yubico sending the affected customer a code to ‘buy’ a free Yubikey from the store.
I remember the vulnerability being widely-publicized at the time. The only communications I got from Yubico, if any, were an email asking me to do the check. They did not randomly send me a Yubikey.
1: https://www.infineon.com/cms/en/product/promopages/rsa-updat...
2: https://www.yubico.com/support/issue-rating-system/security-...
All the downvotes since you posted your comment suggest that maybe some people then thought I had been criticizing the writer's opsec. But I wasn't, I respect the article, and I should've been more clear.
There was a time, so so long ago when we needed them when creating keyboard utilities in assembly. Today, it seems, the mechanical keyboard community keeps a handy reference to them: https://deskthority.net/wiki/Scancode and also https://gist.github.com/MightyPork/6da26e382a7ad91b5496ee55f...
I am also surprised Yubikey calls USB HID Usage codes "scan codes" when scan codes is a completely different table, it is indeed in the order the XT scanned the keyboard you can see it https://kb.iu.edu/d/aanc here.
I’m also kicking myself for not making this connection back when I first inadvertently typed gibberish into my documents by accidentally touching my Yubikey.
Edit: the images appear in a desktop browser, they're just hidden on mobile.
I returned them.