Yubico Forum
https://forum.yubico.com/

Since only a few bits of the token change from each...
https://forum.yubico.com/viewtopic.php?f=4&t=43
Page 1 of 1

Author:  hrag [ Wed May 14, 2008 7:56 pm ]
Post subject:  Since only a few bits of the token change from each...

Q: Since only a few bits of the token change from each authentication request - Could and an attacker could guess some of the plaintext if they knew the approximate current sequence number?

A: We have a 16-bit random number and and a 16-bit CRC together with the counter- and timer fields. So there is a bit more stocastic means than just the counters themseleves.

We have been thinking of increasing the random part to make the string less deterministic. It would be a very simple thing to do.

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/