Even Google's toughest security tools can't protect from this flaw

Physical security keys from Google could be targeted by hackers looking to break into user devices and steal personal data, new research h...

Physical security keys from Google could be targeted by hackers looking to break into user devices and steal personal data, new research has found.

Security experts have discovered a vulnerability impacting the hardware included in Google Titan and YubiKey hardware security keys that have become popular with users looking for that extra level of protection.

The flaw looks to expose the encryption keys used to protect a device, leaving it unsecured and open to attack from outside sources.

Unlocked

The findings come from Victor Lomne and Thomas Roche, researchers with Montpellier-based NinjaLab, who examined all versions of Google's Titan Security Key, the Yubico Yubikey Neo, and several Feitian FIDO devices (Feitian FIDO NFC USB-A / K9, Feitian MultiPass FIDO / K13, Feitian ePass FIDO USB-C / K21, and Feitian FIDO NFC USB-C / K40)

The duo discovered a flaw that could allow hackers to recover the primary encryption key used by the key device to generate cryptographic tokens used in two-factor authentication (2FA) operations.

This could allow threat actors to clone specific Titan, YubiKey, and other keys, meaning hackers could bypass the 2FA procedures that are meant to offer users an extra level of protection.

However in order for the attack to work, the hacker would need to physically get hold of the security key device, as it will not work over the internet. This could mean that any lost or stolen devices could be temporarily used and cloned, before being returned to the victim.

Once completed, though, the attackers could clone the encryption keys used to protect Google or Yubico devices, allowing them access.

The researchers also noted that the keys themselves offered a robust protection against attacks, putting up a strong fight against heat and pressure to resist attempts to break in by hand.

This means that if an attackers was able to steal a key from say an office or factory, they would have a hard time returning it in the same condition it began in.

When contacted by ZDNet, Google highlighted this fact, noting that such an attack would be difficult to carry out in "normal circumstances".

Via ZDNet



from TechRadar - All the latest technology news https://ift.tt/3hVIgU8
via IFTTT

COMMENTS

BLOGGER
Name

Apps,3858,Business,151,Camera,1155,Earn $$$,3,Gadgets,1741,Games,926,GTA,1,Innovations,3,Mobile,1697,Paid Promotions,5,Promotions,5,Sports,1,Technology,8106,Trailers,796,Travel,37,Trending,4,Trendly News,25335,TrendlyNews,123,Video,5,XIAOMI,13,YouTube - 9to5Google,122,
ltr
item
Trendly News | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Reviews #TrendlyNews: Even Google's toughest security tools can't protect from this flaw
Even Google's toughest security tools can't protect from this flaw
Trendly News | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Reviews #TrendlyNews
http://www.trendlynews.in/2021/01/even-googles-toughest-security-tools.html
http://www.trendlynews.in/
http://www.trendlynews.in/
http://www.trendlynews.in/2021/01/even-googles-toughest-security-tools.html
true
3372890392287038985
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy