NinjaLab

58 posts

NinjaLab banner
NinjaLab

NinjaLab

@NinjaLabFr

NinjaLab is a company specialized in the analysis and improvement of the security of cryptographic implementations - [email protected]

Montpellier, France 가입일 Ağustos 2017
44 팔로잉622 팔로워
NinjaLab
NinjaLab@NinjaLabFr·
Malek Sfaxi (aka @YoursSto), our new ninja currently intern at @NinjaLabFr , co-organizes the @N0PSctf , a 36 hours capture-the-flag challenge which will happen from 31 of May to 1 of June 2025. Feel free to participate ! nops.re
English
0
4
8
930
NinjaLab
NinjaLab@NinjaLabFr·
We are proud to announce that a conference paper about #EUCLEAK (SCA attack against Infineon secure elements affecting Yubikeys: ninjalab.io/eucleak/) has been accepted to @IEEESSP 2025. Thomas will be there next week to present his work, if you are in SF, come and say hi!
English
0
3
9
529
NinjaLab
NinjaLab@NinjaLabFr·
Today Camille Mutschler, the first @NinjaLabFr employee, successfully defended her PhD thesis about post-quantum cryptography and side-channel attacks, in front of a jury of world-renowned cryptography researchers ! Congratulations to her 👩‍💻👩‍🎓🥳
NinjaLab tweet media
English
2
2
12
571
NinjaLab 리트윗함
Victor LOMNE
Victor LOMNE@victorlomne·
For people attending @EUCyberWeek this week in Rennes, do not miss today the presentation of my associate Thomas Roche about his last research work #EUCLEAK, a side-channel vulnerability impacting the ECDSA implementation of all secure elements of @Infineon
European Cyber Week@EUCyberWeek

📝✨ On today's European Cyber Week program: CAID by AMIAD, Job Dating, Hazard Generation, European Day/EU Guardian, CTF Challenge, Crypto post-quantum, C&ESAR by DGA... And much more here 👉european-cyber-week.eu/programme

English
1
3
4
688
NinjaLab
NinjaLab@NinjaLabFr·
We are very excited to share our last research work: 𝐄𝐔𝐂𝐋𝐄𝐀𝐊, authored by Thomas Roche. An electromagnetic Side-Channel Vulnerability in the ECDSA implementation of all Infineon security microcontrollers, notably impacting all YubiKey 5 Series. ninjalab.io/eucleak/
English
12
115
274
84K
NinjaLab 리트윗함
hardwear.io
hardwear.io@hardwear_io·
⚠️ Unearthing a Side-Channel Vulnerability Undetected for 14 Years! 🚨 Join Thomas Roche at #hw_ioNL2024 to dive deep into a critical side-channel flaw in Infineon Technologies' secure elements—missed in 80+ high-level Common Criteria assessments More: hardwear.io/netherlands-20…
hardwear.io tweet media
English
0
4
9
933
NinjaLab
NinjaLab@NinjaLabFr·
@fabian_bader We checked on a vulnerable YubiKey 5C: on the acquired traces the ECDSA signature with the attestation key is easily identifiable and then EUCLEAK must apply. In fact this was already covered by Yubico advisory (see section "Attestation"): yubico.com/support/securi…
English
1
0
1
182
Fabian Bader
Fabian Bader@fabian_bader·
@NinjaLabFr Oh that's definitely problematic since then the attestation of all of those keys is invaluable. Don't know if you are able to check this in more depth but if yes it would be very much appreciated
English
1
0
0
153
NinjaLab
NinjaLab@NinjaLabFr·
@fabian_bader We didn't try but it should be possible on vulnerable FIDO devices
English
1
0
2
383
Fabian Bader
Fabian Bader@fabian_bader·
@NinjaLabFr Hi @NinjaLabFr were you also able to extract the private key that is used by those security keys for attestation of e.g. FIDO credentials?
English
1
0
1
597
NinjaLab
NinjaLab@NinjaLabFr·
@jasperrrry A PIN is not necessarily enforced on FIDO devices
English
0
0
0
181
NinjaLab
NinjaLab@NinjaLabFr·
@RenaudDUBOIS10 This attack is very specific to Infineon implementation. It is not running inside a phone secure enclave (AFAIK).
English
0
0
1
345
Reno ⚫️⚪️
Reno ⚫️⚪️@RenaudDUBOIS10·
@NinjaLabFr Amazing. Do you think this exploit could be used by a malware processus spying the execution time required by the secure enclave of a phone to perform Webauthn authentications ?
English
1
0
0
423
NinjaLab
NinjaLab@NinjaLabFr·
@shitestfan EdDSA is not impacted as it does not need to compute a modular inverse.
English
0
0
3
537
NinjaLab
NinjaLab@NinjaLabFr·
We are happy to share our last research work 𝐈𝐧𝐬𝐩𝐞𝐜𝐭𝐨𝐫 𝐆𝐚𝐝𝐠𝐞𝐭, co-authored by Camille Mutschler, Laurent Imbert and Thomas Roche, published in the international Journal IACR Communications in Cryptology. More info here: #InspectorGadget" target="_blank" rel="nofollow noopener">ninjalab.io/news/#Inspecto
English
1
3
13
552