home.social

#yubihsm — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #yubihsm, aggregated by home.social.

  1. While exploring use of PKCS #11 devices in contexts, I stumbled over a bug (and potential security issue) in the yubihsm_pkcs11.so driver for devices.

    Long form text by Christian Reitter (who walked me through the coordinated disclosure process with , and did amazing work analyzing and writing up the issue):
    blog.inhq.net/posts/yubico-yub

    Yubico advisory: yubico.com/support/security-ad

    : cve.mitre.org/cgi-bin/cvename.

    (Thanks again to @sovtechfund for funding my work)

  2. Today I spent a bit of time with the and its driver (the yubihsm_pkcs11.so driver had exhibited some confusing-to-me behavior, during occasional experiments over the past few weeks).

    After a closer look, I believe that "yubihsm_pkcs11.so" version 2.4.0 has introduced a number of rather confusing regressions around object IDs (see github.com/Yubico/yubihsm-shel ).

    This investigation was a side-quest of my @sovtechfund financed project "PKCS#11 support for @sequoiapgp".