YubiKeys Are a Security Gold Standard—but They Can Be Cloned
ID: 388d6d28-230a-5ce4-b06d-81f027fd43aa
STIX ID: report--388d6d28-230a-5ce4-b06d-81f027fd43aa
Feed Name: WIRED Security
Researchers disclosed a side-channel cryptographic flaw in the Infineon cryptolibrary used by YubiKey 5 tokens (and potentially other devices using the same microcontroller), enabling cloning and extraction of ECDSA private keys via electromagnetic/timing analysis during modular inversion; devices running firmware prior to 5.7 are permanently vulnerable because firmware cannot be updated on affected tokens, and exploitation requires temporary physical possession and specialized equipment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
