Yubikeys are compromised due to the microcontroller used

The secure element of Nitrokey 3 is a SE050 from NXP. The main MCU is either a NRF52 or LPC55S6x type processor.

Nitrokey passkey is based on the Nitrokey 3 platform.

Basic MCU shared for multiple Nitrokey types (Pro, Start, HSM) that is used e.g. as card reader is the STM32F103R8T6 (for interacting with the secure element on a smartcard). The Nitrokey Start does not hold a separate smartcard.

The smartcard in the HSM were once based on A700x from NXP (around 2017) and are now most likely using similar successor chips that offer a JCOP Javacard runtime and are considered current by the vendor.

See here a previous statement that no Infinion chips are used.

Protecting against sidechannel attacks is very difficult.

2 Likes