• tkw8@lemm.ee
    link
    fedilink
    English
    arrow-up
    27
    ·
    16 days ago

    Is this because FIDO2 is flawed, the yubikey hardware design is flawed or both?

    • BrikoX@lemmy.zipOP
      link
      fedilink
      English
      arrow-up
      7
      ·
      edit-2
      16 days ago

      While the researchers have confirmed all YubiKey 5 series models can be cloned, they haven’t tested other devices using the microcontroller, such as the SLE78 made by Infineon and successor microcontrollers known as the Infineon Optiga Trust M and the Infineon Optiga TPM. The researchers suspect that any device using any of these three microcontrollers and the Infineon cryptographic library contains the same vulnerability.

      Both. The cryptographic library in question is also used in other cryptographic applications too, so it’s a huge mess.