YubiKey FIDO authenticators could be abused via unrepairable cryptographic flaw

All physical multi-factor authentication (MFA) keys running on Infeneon’s SLE78 microcontroller are said to be vulnerable to a cryptographic flaw that allows threat actors to clone the device and gain unrestricted access to restricted accounts. This includes the YubiKey 5, considered the most widely used hardware token based on the FIDO standard.

In an in-depth technical analysis, NinjaLab researchers described how they discovered the flaw and what it means for those using the YubiKey 5. As explained, the SLE78 microcontroller implements the Elliptic Curve Digital Signature Algorithm (ECDSA) as its primary cryptographic primitive. In short, ECDSA is a cryptographic algorithm used to create digital signatures, and if a hacker can read this signature, they can undermine the security of the entire token.

scroll to top