Yubikey and NitroKey offer NFC and non-NFC versions of their flagship hardware security tokens (HSTs).

NFC is convenient, but can under some circumstances send e.g. challenge-response exchanges in clear text.

Smartcards using RFID, a similar though not identical protocol, can be queried from ~100cm away.

  • Are there other ways are NFC HSTs are known to be more risky than their non-NFC counterparts?
  • Should users store NFC HSTs in RFID-blocking pouches, like those used for wireless car keys or contactless bank cards?
  • modem_down@thebrainbin.orgOP
    link
    fedilink
    arrow-up
    4
    ·
    8 days ago

    Even if you can [exploit NFC] at 1m, thats close enough that it can just be stolen from you.

    Stealing the HST should not give the user a false sense of security. Not so dangerous.

    Silently exfiltrating the private key (or data for a replay attack), OTOH, would leave the user with a false sense of security. Dangerous.

    your link to rfidgate appears broken

    Wfm. Here’s an archive link.

    • CameronDev@programming.dev
      link
      fedilink
      English
      arrow-up
      3
      ·
      8 days ago

      The setup they have requires a pair of huge antennas, so pulling that off surreptitiously feels unlikely. They also had a controlled lab environment, so who knows how it would work in a less controlled RF space.

      Definitely cool research, but this isnt a viable attack vector IMO.