Yubikey and NitroKey offer NFC and non-NFC versions of their flagship hardware security tokens (HSTs).

NFC is convenient, but can under some circumstances send e.g. challenge-response exchanges in clear text.

Smartcards using RFID, a similar though not identical protocol, can be queried from ~100cm away.

  • Are there other ways are NFC HSTs are known to be more risky than their non-NFC counterparts?
  • Should users store NFC HSTs in RFID-blocking pouches, like those used for wireless car keys or contactless bank cards?
  • y0kai [he/him]@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    2
    ·
    6 days ago

    not an expert on this but i would imagine a Faraday case for it, perhaps with a little flap for ease of access would work?

    I would also hope a security company making hardware keys would be aware of and avoid the sending in clear text, as it would be a major vulnerability. Then again, ive never trusted a company to do anything beyond what is absolutely necessary to stay afloat.