I contacted support about this around 4 days ago, but have not received an answer, so I think I need to put this to the community just in case, and also to ease my mind on something that could be a perfectly mundane (but annoying, none-the-less) issue.
The problem I had was with an OTP I generated for a website I use. - I generated the key, saved the new key to one of the key configuration slots, and uploaded it (successfully) to the YubiKey servers. The test also worked, so I proceeded to use it on the website to be secured and all was good (logged-in, logged-out, closed the browser, opened the browser, logged-in again, etc.). Then, a few days later, I found that the OTP was no longer working and that my OTP had been changed - not on my key, but on the site itself. - How did this happen?
My thought is that someone guessed or knew the email address I used with the OTP, and that they generated and uploaded a key to the YubiKey server using that same email address, thereby effectively locking me out of the secured site. - Would this work? - If it would then it would explain what happened, but it would also be a major security concern because, whilst that would not immediately mean that someone could gain access to the secured site, it would still mean that they could, effectively, lock you out of a secured resource very quickly and very easily just by generating and uploading a YubiKey OTP with the same email address to the YubiKey server.
|