Heiko · @hko
78 followers · 169 posts · Server fosstodon.org

While exploring use of PKCS #11 devices in contexts, I stumbled over a bug (and potential security issue) in the yubihsm_pkcs11.so driver for devices.

Long form text by Christian Reitter (who walked me through the coordinated disclosure process with , and did amazing work analyzing and writing up the issue):
blog.inhq.net/posts/yubico-yub

Yubico advisory: yubico.com/support/security-ad

: cve.mitre.org/cgi-bin/cvename.

(Thanks again to @sovtechfund for funding my work)

#openpgp #yubihsm #yubico #cve #pkcs11

Last updated 1 year ago