• 0 Posts
  • 137 Comments
Joined 1 year ago
cake
Cake day: June 29th, 2023

help-circle
  • Godort@lemm.eetoLefty Memes@lemmy.dbzer0.comTell him?
    link
    fedilink
    English
    arrow-up
    21
    ·
    9 hours ago

    They are saying the same thing but mean something entirely different.

    This dude is saying something along the lines of “corporations wouldnt pander so much to the LGBTQ communites if they were run by regular folks like me” rather than “the C-suite of corporations are robbing us blind and we cant do anything because they have so much power that effectively organizing against them is impossible”










  • I’m not sure I necessarily agree. Your assessment is correct, but I don’t really think this situation is security by obscurity. Like most things in computer security, you have to weight the pros and cons to each approach.

    Yubico used components that all passed Common Criteria certification and built their product in a read-only configuration to prevent any potential shenanigans with vulnerable firmware updates. This approach almost entirely protects them from supply-chain attacks like what happened with ZX a few months back.

    To exploit this vulnerability you need physical access to the device, a ton of expensive equipment, and an incredibly deep knowledge in digital cryptography. This is effectively a non-issue for your average Yubikey user. The people this does affect will be retiring and replacing their Yubikeys with the newest models ASAP.











  • They very likely dont have read or write access to the files on your device.

    However, they probably do have the ability to remotely wipe the device. This feature is typically used in enterprise if a phone or laptop is lost or stolen to prevent bad actors from getting access to the data stored on the device.