A Historical Look At Hardware Token Compromises

No ratings

Presented at Blackhat USA 2004 by

This talk examines the details behind successful hardware attacks of early authentication tokens: Two USB devices and one iButton device. We'll be looking at the methods used to compromise the devices and gain access to private data stored on them without having legitimate credentials. Our attacks were based on an approach of using only common, off-the-shelf tools, yet we still succeeded in defeating the security features. While learning from history is important to avoid repeating the same design mistakes, we'll also look at some of the newer authentication tokens and hypothesize about potential attacks.