Hi everybody,
Do Yubico (the seller) knows/keep the serial numbers of the YubiKey security keys they sale?
Are they able to link the YubiKeys to the user via serial number?
Are these serial numbers traceable?
Any insights appreciated.
Thank you
Hi everybody,
Do Yubico (the seller) knows/keep the serial numbers of the YubiKey security keys they sale?
Are they able to link the YubiKeys to the user via serial number?
Are these serial numbers traceable?
Any insights appreciated.
Thank you
Check what payment methods your local authorized reseller accepts.
The one near me accepts 5 different cryptocurrencies, or you can turn up in person and pay in cash
Obviously consider the privacy issues for shipping or CCTV in person as well
Unique identifiers cannot be detected by websites you use the YubiKey with, the FIDO2/U2F protocol is designed with this privacy in mind.
Just get an open source hardware wallet that also support U2F and FIDO2.
This also comes with the benefit that you can properly backup it.
These YubiKeys should be sold at brick-and-mortar Stores.
Identity correlation is possible if you use the same YubiKey for U2F authentication with different accounts.
The YubiKey has a single counter for all U2F sites (explicitly allowed by the standard), so the initial counter for a new registration might be 0, or it might be greater than zero.
Example of single-service identity correlation:
Example of cross-service identity correlation: