Recently, a study conducted by NinjaLab has revealed a vulnerability in YubiKey 5, the popular hardware token for two-factor authentication based on the FIDO standard. Although the news may sound alarming, it is important to understand the context and limitations of this vulnerability. Let’s talk about it.
A very technical and targeted attack that we shouldn’t be a target of
The discovered vulnerability, of the “side channel” type, affects a microcontroller used in numerous authentication devices, including YubiKey 5. As reported in Arstechnica, the error lies in the implementation of an algorithm used to perform certain mathematical calculations during authentication. NinjaLab researchers demonstrated that, by measuring the electromagnetic radiation emitted during these calculations, they could deduce tiny differences in execution time to discover a crucial component of token security.
To exploit this vulnerability, therefore, an attacker needs physical access to the YubiKey device. In addition, they must have detailed knowledge of the accounts they want to compromise and specialized equipment to carry out the attack. Even with this, the process is not trivial: it involves both a data collection phase and subsequent analysis that can take several hours. A targeted and highly technical type of attack is very unlikely to affect us.
Yubico has already responded to this threat. The firmware version 5.7 of the YubiKey, released in May, replaces the cryptographic library with a custom one that is not affected by this vulnerability. Therefore, although we cannot update the units, the ones that come with the firmware are no longer susceptible to this type of attack.
The vulnerability is technically feasible, yes, but the conditions required to exploit it are so restrictive that the majority of YubiKey users should not be affected at all.