There have been a few support mails lately showing concerns over static password emitted by the YubiKey having the key logger vulnerability. Here is some discussion about this topic.
Yubikey acts as a USB keyboard and will therefore be affected by a key-logger program when running in static mode. However, most online services with Yubikey support is running in OTP mode and are therefore not sensitive to key loggers.
Furthermore, in situations where Yubico will be used in static PW mode, it will likely be used for a service that is somewhat local to the user; either used locally on the user's computer itself to login to the computer or locally in the user's network thus making it less sensitive from key-logger attacks launched over the Internet.
|