COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Real-Time News Feed
  • Bitcoin
  • Altcoin
  • Ethereum
  • Technology News
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Users Secure Crypto Assets with YubiKey Despite Vulnerability
Share
Languages
  • TürkçeTürkçe
  • EspañolEspañol
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Real-Time News Feed
  • Bitcoin
  • Altcoin
  • Ethereum
  • Technology News
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 BLOCKCHAIN Information Technologies. >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency Security > Users Secure Crypto Assets with YubiKey Despite Vulnerability
Cryptocurrency Security

Users Secure Crypto Assets with YubiKey Despite Vulnerability

In Brief

  • YubiKey helps secure crypto assets but has a discovered vulnerability.

  • The vulnerability allows device cloning, affecting older YubiKey models.

  • Later YubiKey models are not affected by this vulnerability.

COINTURK NEWS
COINTURK NEWS 8 months ago
Share
SHARE

One way to keep your crypto assets secure is by using YubiKey, but there’s a problem. A vulnerability has been discovered that users who purchased a lifetime YubiKey must learn to live with. Let’s first discuss why YubiKey is important for crypto asset security and then talk about its lifelong vulnerability.

Contents
What is YubiKey?YubiKey Security Vulnerability

What is YubiKey?

FIDO Alliance developed this USB-sized device to assist with identity and password verifications. This authentication device, supporting 2-factor and FIDO2 authentication protocols, keeps your crypto wallets secure. You can think of it as a version designed to protect the passwords of cold wallets commonly used for cryptocurrencies.

It can work offline, allowing you to log in by simply touching the key instead of entering a password, without relying on a phone. This way, you don’t need to store your exchange passwords or other private keys on WhatsApp, email, or paper.

You can also use it by tapping it on your phone thanks to the NFC feature. You can even set this YubiKey as your key when you want to log into your computer. This way, physical access to your computer is not possible while the device is in your possession. This device, compatible with applications like Lastpass and Google Password Manager, can be used not only for your crypto accounts and wallets but for all your accounts.

For extra security, some users buy 2 YubiKeys, using one actively and keeping the other as a backup or recovery key.

YubiKey Security Vulnerability

Everything is perfect unless someone holds a gun to your head and takes your YubiKey. However, a significant security vulnerability that you need to get used to living with was recently discovered. Cybersecurity experts found a vulnerability in YubiKey two-factor authentication keys that allows the device to be cloned. This vulnerability was discovered in the Infineon crypto library used by almost all products, including the following series:

  • YubiKey 5
  • Yubikey Bio
  • Security Key
  • YubiHSM 2

Yubico stated that this security vulnerability is of moderate severity and difficult to exploit. Experts mentioned the following details in their comments on what to watch out for:

“An attacker would need to have physical possession of the YubiKey, Security Key, or YubiHSM, have knowledge about the accounts they want to target, and require special equipment to carry out the attack. Depending on the use case, the attacker might also need additional information such as username, PIN, account password, or authentication key.”

Although it seems difficult, attackers who believe they can access a significant amount of assets might overcome this challenge. In state-sponsored attacks, the success rate is higher because access to much information is easier. Additionally, knowing how extensively teams like Lazarus work and infiltrate companies, investors holding large amounts of assets need to be much more cautious.

Since YubiKey firmware cannot be updated, all YubiKey 5 devices before version 5.7 (or version 5.7.2 for the Bio series and version 2.4.0 for YubiHSM 2) will live with this vulnerability for a lifetime. However, later models are not affected by this vulnerability as they do not use the Infineon crypto library.

You can follow our news on Telegram, Facebook, Twitter & Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

The Shocking Story of How an X Account Hack Sent Bitcoin Prices Soaring

Protect Your Cryptocurrency: Strengthen Your Online Security with CZ’s Tips!

Lido Swiftly Secures Its Network After Critical Oracle Breach

Crypto Market Faces Severe Security Breaches in April

Catch Fraudsters with Revealing Identity and Background Lies

COINTURK NEWS 5 September, 2024 - 3:06 am 5 September, 2024 - 3:06 am
Share This Article
Facebook Twitter
Share
Previous Article Labor Market Data Influences Market Movements
Next Article Binance Futures Lists New BSWUSDT Perpetual Futures Contract
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

The Shocking Story of How an X Account Hack Sent Bitcoin Prices Soaring
Cryptocurrency Security
Crypto Assets Surge as Global Leaders Prepare for Crucial Talks
Technical Analysis
Industry Leaders Stress Banks’ Crucial Role in Stablecoin Success
Cryptocurrency News
US States Embrace Cryptocurrency Investments with New Legislations
Cryptocurrency News
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
© 2025 BLOCKCHAIN Information Technologies. >> COINTURK NEWS
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?