Yubikey Security Advisory YSA-2024-03 Infineon Ecdsa Private Key Recovery

  • Well since Yubikey's can't update their firmware everything with a firmware below 5.7 is e-waste I guess?

  • Discussion (51 points, 6 hours ago, 14 comments) https://news.ycombinator.com/item?id=41434500

  • I'm trying not to blow a gasket over this, but what the fuck? This makes the Yubikey a lost a couple months back a huge risk. This makes my primary and backup Yubikeys potential risks.

    They don't allow FW upgrades for dubious reasons, and they aren't issuing replacements? It's so sad that the OSS alternatives are so lacking.

    Maybe time to pickup a Precursor and start taking this all a bit more seriously.