the yubikey thing 

@clarfonthey @joepie91 That's going to depend.

I suspect a large portion of the infineon catalog is impacted, so it depends on the implementation. Yubikey does have the funding to do things like "we wrote our own, and have an extensive cryptographic test suite", where open source may not.

Yubikeys are tamper evident in the face of this attack. An open source one may or may not be.

I guess the real question is: can this kind of em attack be made to work through potting?

Follow

the yubikey thing 

@astraluma @clarfonthey Look, if you want to be weirdly defensive of Yubico without actually engaging with the points made, that's your prerogative, but please do it somewhere that isn't my mentions, thanks

· · Web · 0 · 0 · 2
Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.