Yubikey
NEO
Unplug and plug it back in and it should be usable as a smartcard.
NFC / HTTP Auth
This will hit the API with a URL like https://api.stelfox.net/session/yknfc?t=ccccccuddclhrkuvurcufviveulljleihvreukifegjh
.
The API can then return a token that for accessing additional functionality.
Resetting
This will wipe all keys, user, and admin pins on the card.
This requires scdaemon and gpg-agent to be working and able to connect to the smartcard. It needs to be plugged into the computer and requires GPG version 2.0.22 or later. On yubikeys prior to the YubiKey4 check the version and confirm it's version 1.0.6 or later using the following command:
Indicating version 1.0.6. To reset the applet you can use the following manual hex commands:
|
|
Using as a RNG source
Vulnerability
A vulnerability was published around YubiKey NEOs use as smartcards and Yubico's response is top notch. I recommend following the steps in checking on your key to see if you're affected.
fbd8ca38 @ 2024-07-15