I noticed we do not yet recommend the always require user vector setting on Yubikeys. This partly mitigates the vulnerability discovered and generally seems good practice.
I had already configured this and I mostly use Yubikey Bio series. But just checked and saw it wasnât recommended as a default yet and we should really encourage using this.
Havenât looked yet, but we should also double-check whether this is possible on the Yubico Security Key series, and on Nitrokeys for the sake of completeness.
I just checked and I can confirm that this option is not supported even on yubico 5 series with firmware versions older than 5.7. Considering that they released yubikey 5 series with the updated firmware 5.7 on May 21, 2024, any yubikey 5 series that was purchased before that date comes with an older firmware version (like 5.4.x). So all yubikeys (except for BIO) that do not have the latest firmware are vulnerable to this.