I caught a number of headlines about a YubiKey flaw that added their own dramatic spin about the doom of these two-factor authentication devices. So, let’s clear the air. The flaw exists, but the bad guy has to get the key, disassemble it, connected it to a bunch of expensive equipment to extract the private encoded key. But there’s more… to gain access, the bad guy would have to have the username, account password, PIN codes, and any additional hardware used to secure the account. Oh yeah, they also have to avoid detection, so they have to somehow get the key back to you and keep you from discovering the hack or replacing it. It’s a nothing burger designed to scare us.
I’m a big fan of YubiKeys and the fact that some of them are vulnerable to being cloned doesn’t change that. Let me explain.
Found at www.zdnet.com
