• 0 Posts
  • 166 Comments
Joined 1 year ago
cake
Cake day: June 29th, 2023

help-circle




  • I’m not sure I necessarily agree. Your assessment is correct, but I don’t really think this situation is security by obscurity. Like most things in computer security, you have to weight the pros and cons to each approach.

    Yubico used components that all passed Common Criteria certification and built their product in a read-only configuration to prevent any potential shenanigans with vulnerable firmware updates. This approach almost entirely protects them from supply-chain attacks like what happened with ZX a few months back.

    To exploit this vulnerability you need physical access to the device, a ton of expensive equipment, and an incredibly deep knowledge in digital cryptography. This is effectively a non-issue for your average Yubikey user. The people this does affect will be retiring and replacing their Yubikeys with the newest models ASAP.












  • Godort@lemm.eetoPC Master Race@lemmy.worldPCIe bifurcation
    link
    fedilink
    English
    arrow-up
    18
    ·
    1 month ago

    I’m not sure what hardware you’re running, but with my motherboard, to get 4x4x4x4 out of a slot requires sacrificing GPU bandwidth from x16 to x8

    to get 4x NVMe drives out of a single PCIe slot without bifurcation you need a card that has it’s own RAID controller. These aren’t cheap (think ~$500) as they are specialty hardware, but it’s a hell of a lot cheaper than a whole professional workstation or server.