YubiKey Cloning Attack

From Elvis Wiki
Revision as of 16:48, 18 December 2024 by LTrifunovic (talk | contribs)

Summary

A YubiKey is a hardware authentication device (Hardware-Token) produced by Yubico. It provides an additional Layer of security for logging into online accounts. It functions as a physical security token for 2-Factor-Authentication (2FA) or Multi-Factor-Authentication (MFA). The Hardware-Token uses the Elliptic Curve Digital Signature Algorithm (ECDSA) and stores the private-key locally on the device. Before being able to log in, the user has to input the YubiKey into the USB-port and prove the possession of the private-key. However, attackers have found a way to extract this private-key with a Side-Channel-Attack and clone the YubiKey, enabling unauthorized authentication. The affected device is the YubiKey 5-Series with a firmware version before 5.7.

General

Passwords

Passwords have been fundamental for authentication for decades and are still the most used authentication method. However, they come with a few weaknesses, which make them vulnerable to data leaks, phishing and identity theft. Users frequently reuse the same password across multiple accounts. That means, that one single data breach can compromise several accounts. Also, many create short or predictable passwords, like "123456" or "password". This makes it an easy target for brute-force attacks. Even long passwords with special characters lose their effectiveness if they are reused many times or remain unchanged for long periods.

Modern Authentication Methods

xxx

Courses

References