Post #3085262
2026-05-07 07:44 UTC
@g@irrelephant.co is there any way that getting enough randomized Yubikey outputs in quick succession would help the website provider reverse engineer the algorithm of your Yubikey ?
Replies (1)
-
@g@irrelephant.co 2026-05-07 08:06
@zed@mstdn.party each click creates a signature based on the server’s challenge and the private key never leaves the physical key’s enclave so no (if yes that would be a MASSIVE failure in implementation, so far physical access seems like the most likely way of doing this), but there are some minor privacy considerations, like it can identify the brand and model of key you’re using etc