Yubikeys have a side channel allowing attackers to get the private key with physical access
- 28
- 30
Top Poster of the Day:
Thirtythirst4sissies
Current Registered Users: 28,720
tech/science swag.
Guidelines:
What to Submit
On-Topic: Anything that good slackers would find interesting. That includes more than /g/ memes and slacking off. If you had to reduce it to a sentence, the answer might be: anything that gratifies one's intellectual laziness.
Off-Topic: Most stories about politics, or crime, or sports, unless they're evidence of some interesting new phenomenon. Videos of pratfalls or disasters, or cute animal pictures. If they'd cover it on TV news, it's probably lame.
Help keep this hole healthy by keeping drama and NOT drama balanced. If you see too much drama, post something that isn't dramatic. If there isn't enough drama and this hole has become too boring, POST DRAMA!
In Submissions
Please do things to make titles stand out, like using uppercase or exclamation points, or saying how great an article is. It should be explicit in submitting something that you think it's important.
Please don't submit the original source. If the article is behind a paywall, just post the text. If a video is behind a paywall, post a magnet link. Fuck journos.
Please don't ruin the hole with chudposts. It isn't funny and doesn't belong here. THEY WILL BE MOVED TO /H/CHUDRAMA
If the title includes the name of the site, please leave that in, because our users are too stupid to know the difference between a url and a search query.
If you submit a video or pdf, please don't warn us by appending [video] or [pdf] to the title. That would be r-slurred. We're not using text-based browsers. We know what videos and pdfs are.
Make sure the title contains a gratuitous number or number + adjective. Good clickbait titles are like "Top 10 Ways to do X" or "Don't do these 4 things if you want X"
Otherwise editorialize. Please don't use the original title, unless it is gay or r-slurred, or you're shits all fucked up.
If you're going to post old news (at least 1 year old), please flair it so we can mock you for living under a rock, or don't and we'll mock you anyway.
Please don't post on SN to ask or tell us something. Send it to [email protected] instead.
If your post doesn't get enough traction, try to delete and repost it.
Please don't use SN primarily for promotion. It's ok to post your own stuff occasionally, but the primary use of the site should be for curiosity. If you want to astroturf or advertise, post on news.ycombinator.com instead.
Please solicit upvotes, comments, and submissions. Users are stupid and need to reminded to vote and interact. Thanks for the gold, kind stranger, upvotes to the left.
In Comments
Be snarky. Don't be kind. Have fun banter; don't be a dork. Please don't use big words like "fulminate". Please sneed at the rest of the community.
Comments should get more enlightened and centrist, not less, as a topic gets more divisive.
If disagreeing, please reply to the argument and call them names. "1 + 1 is 2, not 3" can be improved to "1 + 1 is 3, not 2, mathfaggot"
Please respond to the weakest plausible strawman of what someone says, not a stronger one that's harder to make fun of. Assume that they are bad faith actors.
Eschew jailbait. Paedophiles will be thrown in a wood chipper, as pertained by sitewide rules.
Please post shallow dismissals, especially of other people's work. All press is good press.
Please use Slacker News for political or ideological battle. It tramples weak ideologies.
Please comment on whether someone read an article. If you don't read the article, you are a cute twink.
Please pick the most provocative thing in an article or post to complain about in the thread. Don't nitpick stupid crap.
Please don't be an unfunny chud. Nobody cares about your opinion of X Unrelated Topic in Y Unrelated Thread. If you're the type of loser that belongs on /h/chudrama, we may exile you.
Sockpuppet accounts are encouraged, but please don't farm dramakarma.
Please use uppercase for emphasis.
Please post deranged conspiracy theories about astroturfing, shilling, bots, brigading, foreign agents and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email [email protected] and dang will add you to their spam list.
Please don't complain that a submission is inappropriate. If a story is spam or off-topic, report it and our moderators will probably do nothing about it. Feed egregious comments by replying instead of flagging them like a pussy. Remember: If you flag, you're a cute twink.
Please don't complain about tangential annoyances—things like article or website formats, name collisions, or back-button breakage. That's too boring, even for HN users.
Please seethe about how your posts don't get enough upvotes.
Please don't post comments saying that rdrama is turning into ruqqus. It's a nazi dogwhistle, as old as the hills.
Miscellaneous:
The quality of posts is extremely important to this community. Contributors are encouraged to provide high-quality or funny effortposts and informative or entertaining comments. Please refrain from posting the following:
Boring wingcucked nonsense nobody cares about that belongs in chudrama
Normie shit everyone already knows about
Anything that doesn't gratifify one's intellectual laziness
Bimothy-tier posts
Anything that the jannies don't like
We reserve the right to exile you for whatever reason we want, even for no reason at all! We also reserve the right to change the guidelines at any time, so be sure to read them at least once a month. We also reserve the right to ignore enforcement of the guidelines at the discretion of the janitorial staff. This hole is a janny playground, participation implies enthusiastic consent to being janny abused by unstable alcoholic bullies and loser nerds who have nothing better to do than banning you for any reason or no reason whatsoever.
[[[ To any NSA and FBI agents reading my email: please consider ]]]
[[[ whether defending the US Constitution against all enemies, ]]]
[[[ foreign or domestic, requires you to follow Snowden's example. ]]]
/h/slackernews SETTINGS /h/slackernews LOG /h/slackernews MODS /h/slackernews EXILEES /h/slackernews FOLLOWERS /h/slackernews BLOCKERS
Jump in the discussion.
No email address required.
What is a yubikey
Jump in the discussion.
No email address required.
It's a physical USB device that has a secret cryptographic key on it.
You add this key to various accounts that you make and they will require the physical device to be present while you log-in.
I got two a year to secure my most important accounts (Apple, Google, etc.) and this exploit means an attacker can steal them and make copies of them - that's the worst thing that could happen to them minus a "remote" attack or something.
Jump in the discussion.
No email address required.
Still better than SMS 2FA tbqhwyf
Jump in the discussion.
No email address required.
More options
Context
Don't let ppl steal your 2fa
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
Jump in the discussion.
No email address required.
I mean, it probably doesn't effect a lot of peoples threat models but it's pretty bad for this kind of device.
Jump in the discussion.
No email address required.
Can you make it self destruct if disassembled?
Jump in the discussion.
No email address required.
Doesn't seem like these ones do
That is a feature on some though.
Jump in the discussion.
No email address required.
That was my emotional support ounce of plastic explosive, it was not reasonably foreseeable that an officer of the peace would set it off, I hid it very well inside something I keep on my person at all times!
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
It probably doesn't affect anyone tbqh.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
HN thread: https://news.ycombinator.com/item?id=41434500
Jump in the discussion.
No email address required.
So if they have two factors of authentication they can break 2FA. I don't get what the big deal is??
Jump in the discussion.
No email address required.
I'm not really sure what is meant by "username and password" my yubikey just takes a physical press or NFC tap.
Jump in the discussion.
No email address required.
Presumably the first factor of authentication. Just the normal login
Jump in the discussion.
No email address required.
Ohh, they mean to websites.
Yeah I mean I'll continue using a secure password and password manager but this is still pretty bad if you were trying to prevent attackers.
Another thing the report mentions is this effects anything using that secure element so it might effect things like crypto wallets too.
Jump in the discussion.
No email address required.
No, it's really not. They need to steal your yubikey, disassemble it to make a copy, reassemble it to give it back to you so you don't notice it's missing. Then they also need to know your login info that requires the yubikey for MFA. There is zero threat here.
Jump in the discussion.
No email address required.
yeah I have over-reacted.
I'm curious to see if their warnings for other devices using the secure element come true.
It would be interesting if some old crypto stashes suddenly move in a couple months.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context
Shocking: if an attacker has the keys to your house and is standing in front of your house, they can enter your house
Jump in the discussion.
No email address required.
Naw, they copy the keys off the yubikey itself.
Jump in the discussion.
No email address required.
If an attacker takes my key they can make a copy by hand and hope I don't realize before they walk into my house
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
coming to PA for your physical keys
Jump in the discussion.
No email address required.
You can stay for some pierogis at least
Jump in the discussion.
No email address required.
More options
Context
More options
Context
and i just bought 2 a couple months ago....
Jump in the discussion.
No email address required.
Same bruv, i think I've had mine for two years or so. Whenever apple added support.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
An idiot admires complexity. A genius admires simplicity.
Snapshots:
https://www.yubico.com/support/security-advisories/ysa-2024-03/:
ghostarchive.org
archive.org
archive.ph (click to archive)
Jump in the discussion.
No email address required.
More options
Context
Sidechannel attack nothingburger that requires unrestricted physical access, disassembly of your key and probing with $100k++ equipment. This isnt some simple swipe and scan procedure that takes a few minutes. I wouldnt worry about it.
Jump in the discussion.
No email address required.
More options
Context
I've always wondered, at the end of the day the safety of these keys really depends on the manufacturing process. The NSA probably has a copy of every yubikey ever made
Jump in the discussion.
No email address required.
More options
Context
Soooooooo, what is the vulnerability here? Not really going to matter to the average user who uses it for 2FA. Corporate datacenters, maybe.
Jump in the discussion.
No email address required.
More options
Context