<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1979" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-08-24T20:08:33+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1979</id>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-08-20T10:35:01+01:00</updated>
<published>2015-08-20T10:35:01+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1979&amp;p=7716#p7716</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1979&amp;p=7716#p7716"/>
<title type="html"><![CDATA[Re: [QUESTION] Is there a way to recover the HMAC-SHA secret]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1979&amp;p=7716#p7716"><![CDATA[
No known methodology is known to extract data to this date 2015-08-20<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Thu Aug 20, 2015 10:35 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Ericy]]></name></author>
<updated>2015-08-18T02:14:42+01:00</updated>
<published>2015-08-18T02:14:42+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1979&amp;p=7700#p7700</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1979&amp;p=7700#p7700"/>
<title type="html"><![CDATA[Re: [QUESTION] Is there a way to recover the HMAC-SHA secret]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1979&amp;p=7700#p7700"><![CDATA[
<div class="quotetitle">h3lix wrote:</div><div class="quotecontent"><br />Back to the question... Is there any ability to extract the secret key for HMAC-SHA1 once it is programmed onto a yubikey? I want to make sure nobody else will be able to create additional yubikeys for obvious reasons. I understand CCID and PGP doesn't allow for extraction of keys once programmed, but want to verify the same for challenge-repsponse.<br />Thanks!<br /></div><br /><br />I don't know whether one can extract the secret key directly from the yubikey, but I will make the observation that if you use a Yubikey with pwsafe, that the secret key is visible from the pwsafe application .  Thus if you have one Yubikey that you have used to open the safe, you can do &quot;Manage-&gt;Yubikey&quot;.  When the Yubikey dialog comes up, click &quot;Show&quot; and it will display the secret key.<br /><br />Is the key stored in the pwsafe database, or is it able to download from the key itself?  I can't answer that question.  It seems like one of these two possibilities must be true.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3542">Ericy</a> — Tue Aug 18, 2015 2:14 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[h3lix]]></name></author>
<updated>2015-08-24T20:08:33+01:00</updated>
<published>2015-07-23T19:18:27+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1979&amp;p=7646#p7646</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1979&amp;p=7646#p7646"/>
<title type="html"><![CDATA[[SOLVED] Is there a way to recover the HMAC-SHA secret key]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1979&amp;p=7646#p7646"><![CDATA[
In an attempt to add a hardware component to make pwsafe a bit safer while sharing a database between users, I'm looking into a solution that uses yubikey and HMAC-SHA1.<br /><br />The plan is to use HMAC-SHA1 on slot 2 with the same secret on multiple yubikeys with hopes that it will make decrypting a pwsafe database difficult for anybody without a properly configured yubikey. I realize if someone actually logged the output from HMAC-SHA1 request and stored the response, it would circumvent the use of the yubikey. We could potentially change passwords frequently to avoid this type of attack, but we also want people to use the solution.<br /><br />Back to the question... Is there any ability to extract the secret key for HMAC-SHA1 once it is programmed onto a yubikey? I want to make sure nobody else will be able to create additional yubikeys for obvious reasons. I understand CCID and PGP doesn't allow for extraction of keys once programmed, but want to verify the same for challenge-repsponse.<br /><br />Thanks!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3842">h3lix</a> — Thu Jul 23, 2015 7:18 pm</p><hr />
]]></content>
</entry>
</feed>