Skip to content

Security Advisory 2019-06-13 – Reduced initial randomness on FIPS keys

yubico.com
4 pointsdigitalnalogika2 comments
On HN

Comments

Rather worrying for a device whose entire purpose is to generate and store keys...

Also especially worrying considering a deliberately 'bad' random number generator is almost the perfect way to subvert a device, since true random is inprovable

meh this specifically pertains to the 2-factor feature, and if your 2nd factor is a secret you have gone very somewhere.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.