Don’t worry, YubiKeys are not as vulnerable as they seem

Recently, a study conducted by NinjaLab has revealed a vulnerability in YubiKey 5, the popular hardware token for two-factor authentication based on the FIDO standard. Although the news may sound alarming, it is important to understand the context and limitations of this vulnerability. Let’s talk about it.

TikTok Download

A very technical and targeted attack that we shouldn’t be a target of

The discovered vulnerability, of the “side channel” type, affects a microcontroller used in numerous authentication devices, including YubiKey 5. As reported in Arstechnica, the error lies in the implementation of an algorithm used to perform certain mathematical calculations during authentication. NinjaLab researchers demonstrated that, by measuring the electromagnetic radiation emitted during these calculations, they could deduce tiny differences in execution time to discover a crucial component of token security.

To exploit this vulnerability, therefore, an attacker needs physical access to the YubiKey device. In addition, they must have detailed knowledge of the accounts they want to compromise and specialized equipment to carry out the attack. Even with this, the process is not trivial: it involves both a data collection phase and subsequent analysis that can take several hours. A targeted and highly technical type of attack is very unlikely to affect us.

Yubico has already responded to this threat. The firmware version 5.7 of the YubiKey, released in May, replaces the cryptographic library with a custom one that is not affected by this vulnerability. Therefore, although we cannot update the units, the ones that come with the firmware are no longer susceptible to this type of attack.

TikTok Download

The vulnerability is technically feasible, yes, but the conditions required to exploit it are so restrictive that the majority of YubiKey users should not be affected at all.

Author: David Bernal Raspall

{ "de-DE": "Architekt | Gründer von hanaringo.com | Trainer für Apple-Technologien | Autor bei Softonic und iDoo_tech, zuvor bei Applesfera", "en-US": "Architect | Founder of hanaringo.com | Apple Technologies Trainer | Writer at Softonic and iDoo_tech, formerly at Applesfera", "es-ES": "Arquitecto | Creador de hanaringo.com | Formador en tecnologías Apple | Redactor en Softonic y iDoo_tech y anteriormente en Applesfera", "fr-FR": "Architecte | Créateur de hanaringo.com | Formateur en technologies Apple | Rédacteur chez Softonic et iDoo_tech, précédemment chez Applesfera", "it-IT": "Architetto | Fondatore di hanaringo.com | Formatore in tecnologie Apple | Scrittore per Softonic e iDoo_tech, precedentemente su Applesfera", "ja-JP": "建築家 | hanaringo.comの創設者 | アップル技術のトレーナー | SoftonicおよびiDoo_techのライター、以前はApplesferaで", "nl-NL": "Architect | Oprichter van hanaringo.com | Trainer in Apple-technologieën | Schrijver bij Softonic en iDoo_tech, voorheen bij Applesfera", "pl-PL": "Architekt | Założyciel hanaringo.com | Trener technologii Apple | Pisarz w Softonic i iDoo_tech, wcześniej w Applesfera", "pt-BR": "Arquiteto | Fundador do hanaringo.com | Instrutor em tecnologias Apple | Escritor na Softonic e iDoo_tech, anteriormente na Applesfera", "social": { "email": "races_provost0x@icloud.com", "facebook": "", "twitter": "https://twitter.com/david_br8", "linkedin": "https://www.linkedin.com/in/davidbernalraspall/" } }