If you already had both these things, any vulnerability in the key's firmware would be moot, surely? It's hardly a surprise that 2FA can be compromised by compromising both factors.
If you already had both these things, any vulnerability in the key's firmware would be moot, surely? It's hardly a surprise that 2FA can be compromised by compromising both factors.
I could give you my security key and you'll be able to login once. If you can extract the key, then you could login without the security key. In the context of a targeted attack, that could heavily change the impact.
Yubikey security advisory: "Due to software vulnerability, always store in pocket".
:)
Without that property, might as well use a < 1$ Arduino clone that's 100x cheaper.
https://github.com/token2/pin_plus_firmware https://github.com/BryanJacobs/FIDO2Applet
Probably will cost 5USD
In addition to FIDO2, you can add java applet for OpenPGP (also open source), TOTP (https://github.com/JavaCardOS/Oath-Applet) and PIV/smartcard (open source as well). I tell you more - there are tons of JavaCardOS compatible applets available on github etc.
This thread talks about sub-1$ Arduinos:
https://old.reddit.com/r/arduino/comments/dixa9x/awesome_sub...
I can't speak to the quality of those, but my friend got some sub-1$ Arduionos in the past (not sure which) and said they worked.
Also I returned my yubikey to my $work when my contract ended so I know at least Microsoft reuses these keys.
Or destroys them.
So having my private key on the Yubikey plugged into my computer is still safer than having the private key directly on the computer, right?
You wouldn't have to pay > 50$ for a Yubikey.
But you would need this ultra-cheap device plugged into your computer to be resistant to your computer being compromised. Do you know such an off-the-shelf device?
> or your phone
Well your phone has a very large attack surface as compared to a Yubikey.
> You wouldn't have to pay > 50$ for a Yubikey.
Are you sure about that? I have a Nitrokey 3C NFC that cost more than my Yubikey, and the Nitrokey can be flashed from my computer. Meaning that if my computer is compromised, then my Nitrokey is compromised.
It's not clear to me that 50$ is expensive for a product that is not used by half the world and doesn't collect the private data of its users. I understand the frustration with the security issue, but I find it unfair to say "I would do better for < 1$".
The keys are tamper-evident.
The attack is not impossible, and surely fits within the capabilities of nation state actors. For majority of other users it's a theoretical attack.
No. Attacker replaces the shell.
I'm discounting the need to conduct phishing. That comes for free. I'll also give you that the victim may be rather unlikely to spot that their YubiKey has been replaced with a freshly manufactured copy.
For those kinds of capabilities you're still looking at nation state actors or very motivated enterprises.
Not at all. Superglue is ample.
> For those kinds of capabilities you're still looking at nation state actors or very motivated enterprises.
And that's comfort?
Nation state actors have the resources to destroy me. Defending fully against them is cost prohibitive. I'll take basic actions to make it more expensive though.
My threat model is much less well resources actors who would happily sim-swap or password-stuff, etc, and there a ubikey is enough to foil those attacks. I have locks on my doors to prevent random teenagers and miscreants from walking in, not to prevent people motivated enough to pick the locks, break a window, or go through a wall.
...whereas many users trusting the "industry’s #1 security key" pitch were relying upon a lot more.
For the threat model of keeping out random online attackers with no physical access, it seems this vulnerability doesn't matter.