Does it require physical access to the device?

Reply to this note

Please Login to reply.

Discussion

Yes, it is written:

"The attack requires physical access to the secure element"

Thanks, then I don’t see how this is newsworthy.

If you have physical access to the Yubikey, you can just tap it to get it to sign. No exfiltration necessary.

This allow the cloning of the key, with no trace