Some thoughts on the YubiKey EUCLEAK Vulnerability


Photo of electrical equipment placed very close to a circuit board.

It looks like everyone's favourite FIDO token provider might have an unpatchable vulnerability! Much Sturm und Drang from the usual sources. But how bad is it really? Not so bad - but it does expose some weaknesses in the very idea of having physical tokens. First up, as the research paper's abstract says: The attack […]

Continue reading →

How do I revoke a FIDO / WebAuthN token from every service?


YubiKey Neo - a thumb sized USB device - on cardboard backing

After my blog post about recovering my accounts after a disaster, I followed the most repeated advice: Get two YubiKeys Associate them both with your accounts Keep one off-site in a safe location OK, done! My wife and I spend a very boring evening going through every single account we have which supports FIDO tokens […]

Continue reading →

What's the risk from fake Yubikeys?


Meme in the style of "You Wouldn't Download A Car" saying "You wouldn't take a free USB stick.

I found this on a security-related Slack (shared with permission). It launched an entertaining discussion about the risks of taking a potentially fake FIDO token. We all know the risks of taking a free USB drive and shoving it in our computer, right? USB sticks can install software, act as a keylogger, transmit data over […]

Continue reading →

Where are the U2F Rings?


Photo of an NFC ring, taken by Rain Ashford.

The FIDO specification defines a form of Universal 2nd Factor (U2F) when users log in to a system. Rather than relying on one-time codes sent via SMS, or displayed on a phone screen, these are physical hardware tokens which are used to supplement passwords. When used with websites, this technology is also known as WebAuthn. […]

Continue reading →

That's not how 2FA works


List of tweeters advocating for 2FA.

Another day, another high-profile website cloned to phish credentials. Tess Rinearson@_tessrIs this a phishing attempt? Goes to "githubverification.com" and asks for username and pw (if so, it nearly got me!) /cc @github pic.x.com/jgt4onvjf2❤️ 2,322💬 115♻️ 016:12 - Sat 16 January 2021 In the replies, you’ll see lots of techbros saying “this is why you should […]

Continue reading →