• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

Yubico’s Transparent Approach to Security Vulnerabilities Sets Strong Example

June 13, 2018

“With the security flaw fixed, Google gave Yubico a “bug bounty” of $5,000, which the latter donated to Girls Who Code.”

Yubico's Transparent Approach to Security Vulnerabilities Sets Strong Example

Yubico is illustrating the benefits of transparency in a new blog post about a security bug recently found in the use of FIDO U2F authenticators with Google Chrome.

As Yubico’s Jesper Johansson and Venkat Venkataraju explains, the vulnerability first came to light in a news report this past March, prompting Yubico’s team to immediately investigate the issue, which revolved around the potential “to circumvent the FIDO U2F origin check using WebUSB functionality of Google Chrome.” But while the article only mentioned YubiKey NEO authenticator, the company’s team quickly found that the security flaw affected all USB key devices.

Yubico’s actions from there demonstrate the company’s community-minded approach to online security. The company brought its findings to Google and worked with the company to establish a patch, which was included in a Google Chrome update released at the end of May. With the security flaw fixed, Google gave Yubico a “bug bounty” of $5,000, which the latter donated to Girls Who Code. Then Google, in turn, matched that donation to the organization.

It’s a happy ending, and one that’s indicative of a corporate philosophy that puts end users’ security above defensive brand repair. Yubico wasn’t about to brush this issue under the rug, and the company wants to set an example for others; as its latest blog post argues, “The security ecosystem is only as strong as the weakest link and if we, as a community of vendors and security researchers effectively and respectfully work together, we can secure not only end users, but the entire ecosystem from continually evolving threats.”

And with the FIDO2 authentication standard poised to bring biometric authentication to Google Chrome and other browsers, it will be all the more important for the security community to heed that call and make sure that such technology is as effective as it can be, and that end users’ most sensitive data is protected.

Source: Yubico Blog

Filed Under: Industry News Tagged With: controversy, FIDO U2F, Google Chrome, mobile device, mobile identification, strong online authentication, Yubico

Related News & Articles

iProov Gets High Ranking in Deloitte UK Tech Startup List

US Mobile Carriers Unveil Password-Free ZenKey Authentication Platform

Reseller Agreement Points to Extensive Collaboration Between NTT Data, Nok Nok Labs

Primary Sidebar

Learn About Mobile ID and Aviation

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • NordPass, Yahoo! Japan, and Regula Keep Up Mobile Biometrics Momentum
  • NordPass Enables Biometric, TOTP-secured 2FA for Business Users
  • Mastercard Solution Certified Under UK’s Digital ID Framework
  • Transatlantic Digital Traveler Identity Project Gets High-Profile Tech Partner
  • Digital Identity Tech Demo Online Event

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld