{"id":287835,"date":"2024-09-04T11:08:50","date_gmt":"2024-09-04T09:08:50","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=339631"},"modified":"2025-07-01T16:00:22","modified_gmt":"2025-07-01T23:00:22","slug":"dont-worry-yubikeys-are-not-as-vulnerable-as-they-seem","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/dont-worry-yubikeys-are-not-as-vulnerable-as-they-seem\/","title":{"rendered":"Don&#8217;t worry, YubiKeys are not as vulnerable as they seem"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Recently, a study conducted by NinjaLab has revealed a vulnerability in YubiKey 5, the popular hardware token for two-factor authentication based on the FIDO standard. Although the news may sound alarming, it is important to <strong>understand the context and limitations of this vulnerability<\/strong>. Let&#8217;s talk about it.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"TikTok\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-m\/p\/59ae462d-6083-48f2-bee8-25798091f31d\/381293511\/tik-tok-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">TikTok<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/tik-tok.en.softonic.com\/iphone?ex=CS-987.2\" target=\"_self\" rel=\"noopener noreferrer\">Download<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/tik-tok.en.softonic.com\/iphone?ex=CS-987.2\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">A very technical and targeted attack that we shouldn&#8217;t be a target of<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The discovered vulnerability, of the &#8220;side channel&#8221; type, affects a microcontroller used in numerous authentication devices, including YubiKey 5. As reported in Arstechnica, the error lies in the implementation of an algorithm used to perform certain mathematical calculations during authentication. NinjaLab researchers demonstrated that, by measuring the electromagnetic radiation emitted during these calculations, they could deduce tiny differences in execution time to discover a crucial component of token security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To exploit this vulnerability, therefore, <strong>an attacker needs physical access to the YubiKey device<\/strong>. In addition, they must have detailed knowledge of the accounts they want to compromise and specialized equipment to carry out the attack. Even with this, the process is not trivial: it involves both a data collection phase and subsequent analysis that can take several hours. A targeted and highly technical type of attack is very unlikely to affect us.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Yubico has already responded to this threat. <strong>The firmware version 5.7 of the YubiKey<\/strong>, released in May, replaces the cryptographic library with a custom one that is not affected by this vulnerability. Therefore, although we cannot update the units, the ones that come with the firmware are no longer susceptible to this type of attack.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"TikTok\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-m\/p\/59ae462d-6083-48f2-bee8-25798091f31d\/381293511\/tik-tok-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">TikTok<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/tik-tok.en.softonic.com\/iphone?ex=CS-987.2\" target=\"_self\" rel=\"noopener noreferrer\">Download<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/tik-tok.en.softonic.com\/iphone?ex=CS-987.2\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability is technically feasible, yes, but the <strong>conditions required to exploit it are so restrictive<\/strong> that the majority of YubiKey users should not be affected at all.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently, a study conducted by NinjaLab has revealed a vulnerability in YubiKey 5, the popular hardware token for two-factor authentication based on the FIDO standard. Although the news may sound alarming, it is important to understand the context and limitations of this vulnerability. Let&#8217;s talk about it. A very technical and targeted attack that we &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/dont-worry-yubikeys-are-not-as-vulnerable-as-they-seem\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Don&#8217;t worry, YubiKeys are not as vulnerable as they seem&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9262,"featured_media":287837,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":2},"categories":[],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-287835","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/287835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9262"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=287835"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/287835\/revisions"}],"predecessor-version":[{"id":311673,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/287835\/revisions\/311673"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/287837"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=287835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=287835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=287835"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=287835"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=287835"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=287835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}