YubiKey still selling old stock with vulnerable firmware
280 points by MaKey 2 days ago | 112 comments
FYI, YubiKey is apparently still selling old stock with firmware vulnerable to the EUCLEAK attack instead of disposing of them, as a reader of Fefe's Blog reported: https://blog.fefe.de/?ts=99ccc8dc
Modified3019 2 days ago | next |
I hadn’t noticed the announcement of the vulnerability, looks like it’s nothing I care about for my “thread model”.
https://www.theverge.com/2024/9/4/24235635/yubikey-unfixable...
>“The attacker would need physical possession of the YubiKey, Security Key, or YubiHSM, knowledge of the accounts they want to target, and specialized equipment to perform the necessary attack,” the company said in its security advisory. “Depending on the use case, the attacker may also require additional knowledge including username, PIN, account password, or authentication key.” But those aren’t necessarily deterrents to a highly motivated individual or state-sponsored attack.