Hi everyone,
I hope you're having a good Friday. I present you this week's issue. The Yubikey cloning is fascinating to read up on (and confusing, as crypto always is, it's not just you). I also learned that there are "2fa bypass service providers", and that the latest Russian hacker collective seems so young they make me feel old. Which I guess I am. I keep learning new things by writing this newsletter ;-)
Aaaanyway, enjoy the read folks!
Cheers,
Don't be afraid that your Yubikeys are now worthless, they are not. The attack requires physical access, your normal credentials, and a bunch of expertise. But it's interesting to read up on. Unfortunately the vulnerable firmware can't be patched, all current Yubikeys 5 series up to versions 5.7 are and will always be vulnerable.
"By using an oscilloscope to measure the electromagnetic radiation while the token is authenticating itself, the researchers can detect tiny execution time differences that reveal a token’s ephemeral ECDSA key, also known as a nonce. Further analysis allows the researchers to extract the secret ECDSA key that underpins the entire security of the token."
Damn fine research. You can find the paper with the research by Ninjalabs here, and a Hackernews disscussion here.