Yubico Replaces Security Keys Due to Hardware Flaws

Yubico Replaces FIPS Series Security Keys Due to Hardware Flaws

Yubico discovered a hardware flaw in YubiKey FIPS Series devices in mid-March and since then, has updated the firmware version to one that does not contain the bug, as well as replaced the majority of affected devices.

Yubico is replacing U.S. government-approved security keys due to hardware flaws. The recalled device is the YubiKey FIPS Series, which are not consumer devices, and only in versions 4.4.2 and 4.4.4.

Yubico released an advisory last week that stated that the main issue with the security keys was decreased randomness in the first set of values.

“Random values leveraged in some YubiKey FIBS applications contain reduced randomness for the first operations performed after YubiKey FIPS power-up,” Yubico said. “The buffer holding random values contains some predictable content left over from the FIPS power-up self-tests which could affect cryptographic operations which require random data until the predictable content is exhausted.”

Yubico originally discovered the flaw in mid-March 2019, and subsequently created YubiKey FIPS Series firmware version 4.4.5, which achieved FIPS certification on April 30, 2019.

The company has been replacing keys for affected FIPS devices since they discovered the issue, and said that at the time the advisory was released, they believed the majority of affected YubiKey FIPS Series devices had been replaced, or were in the process of being replaced.

The company is not aware of any security breaches due to the issue, but all users that haven’t yet been contacted by Yubico are advised to request a replacement.

About the Author

Kaitlyn DeHaven is the Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.