YubiKey Side-Channel Attack
Full article189 words · extracted from schneier.com · click to collapse
There is a side-channel attack against YubiKey access tokens that allows someone to clone a device. It’s a complicated attack, requiring the victim’s username and password, and physical access to their YubiKey—as well as some technical expertise and equipment.
Still, nice piece of security analysis.
Tags: academic papers, cloning, security analysis, security tokens, side-channel attacks
Comments
Somebody Anon • September 9, 2024 3:51 PM
Another side-channel attack:
New RAMBO Attack Uses RAM Radio Signals to Steal Data from Air-Gapped Networks
A novel side-channel attack has been found to leverage radio signals emanated by a device’s random access memory (RAM) as a data exfiltration mechanism, posing a threat to air-gapped networks.
The technique has been codenamed RAMBO by Dr. Mordechai Guri, the head of the Offensive Cyber Research Lab in the Department of Software and Information Systems Engineering at the Ben Gurion University of the Negev in Israel.
For more information: https://thehackernews.com/2024/09/new-rambo-attack-uses-ram-radio-signals.html
Subscribe to comments on this entry
Sidebar photo of Bruce Schneier by Joe MacInnis.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2024/09/yubikey-side-channel-attack.html