EUCLEAK - Extraction of the ECDSA #secret #key of #Yubikey 5 series FIDO devices

https://ninjalab.io/eucleak/

Reply to this note

Please Login to reply.

Discussion

Does it require physical access to the device?

Yes, it is written:

"The attack requires physical access to the secure element"

Thanks, then I don’t see how this is newsworthy.

If you have physical access to the Yubikey, you can just tap it to get it to sign. No exfiltration necessary.

This allow the cloning of the key, with no trace

Thank you for sharing.

resharing on twitter. i mean x