Oddbean new post about | logout
 That’s a nope. 

https://www.theverge.com/2024/9/4/24235635/yubikey-unfixable-security-vulnerability-side-channel-explot 
 Doesn’t this require physical access? 
 I’m no expert. I just know they have a design flow that allows them to be hacked. 🤷‍♂️ 
 Seems low risk 

“The attacker would need physical possession of the YubiKey, Security Key, or YubiHSM, knowledge of the accounts they want to target, and specialized equipment to perform the necessary attack,” 
 Good to know. Yeah, i suppose that is low risk. 
 Requires physical access and latest series not affected

https://www.yubico.com/support/security-advisories/ysa-2024-03/ 
 Good to know. 
 Cool. Mine were affected so I ordered some new ones 🙌 

Thanks for the heads up!