this post was submitted on 03 Sep 2024
5 points (100.0% liked)

Ars Technica - All Content

67 readers
67 users here now

All Ars Technica stories

founded 3 months ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 0 points 2 months ago* (last edited 2 months ago) (2 children)

There's a firmware update that fixes the vulnerability. Kinda moot as long as you do updates.

EDIT: Seems you have to buy a new key for that, but the difficulty of executing the vulnerability means it probably doesn't matter anyway.

[–] sprack 2 points 2 months ago

Also requires $11k in gear and physical access to the key.

[–] danski 2 points 2 months ago (1 children)

I thought these device's firmware were strictly read only and can't get updates.

[–] [email protected] 1 points 2 months ago* (last edited 2 months ago)

Apparently not.

EDIT: It seems they actually are? So I guess if you're at risk of having a national government try to break your security key, you should buy a new one.