Multi-factor authentication (MFA) is one of the easiest ways to combat spear phishing and account take over, but it’s not perfect. In a report published this week, security researchers from NinjaLab successfully cloned a Google Titan security key and exposed a vulnerability affecting the NXP P5x cryptographic chipset used by numerous other security keys.

Launched in 2018, Google’s Titan security key is a MFA hardware device used to physically verify the identity of the user. The keys are commonly used in place of less secure MFA methods such as confirmation codes sent to the users phone via text message or email.

From the time its launch, NinjaLab researchers had suspected the keys may be vulnerable certain kinds of side-channel attacks. For those that aren’t familiar, side-channel measurements and attacks take advantage of the electromagnetic radiation coming off electronic devices during normal operation to identify patterns and glean useful information.

By observing the electromagnetic radiations during ECDSA signatures, NinjaLab was able to successfully execute a side-channel attack on the key’s secure element, an NXP A700X chip, enabling researchers to clone the key.

NinjaLab notes that this chipset is used in a wide variety of MFA security keys are likely affected, with NXP Product Security Response Teams on the record as confirming that all “NXP ECC Crypto Library up to version 2.9 on P5 and A7x products” are vulnerable to the attack.

How the Attack Works

While it is possible to clone a Google Titan Security or similar key using the NXP P5x chipset, that doesn’t mean it’s easy or even practical. In fact, the process detailed in NinjaLab’s report reads like something out of a Mission Impossible movie.

The attack would begin with a simple social engineering attack — likely a phishing email — to obtain the target’s username and password. But that’s the easy bit, from here on things get a lot more difficult.

The target’s credentials aren’t all that useful without the physical security key. This means the attacker must obtain the target’s security key during a limited window in which it won’t be missed. From there, the attacker can use the target’s credentials in conjunction with the key to take side-channel measurements.

Once the measurements are taken, the attacker must then return they key to the target without them knowing it was ever missing. This is critical as if the target realizes that the key was out of their possession they may be required to revoke the key and register a new one, rendering the attack mute.

With the key returned and the target none the wiser, the attacker can perform a side-channel attack on the measurements to extract the elliptic curve digital signature algorithm (ECDSA) private key linked the target’s account. Using this key in conjunction with the user’s credentials the attacker can now access the target’s account without their knowledge.

NinjaLab notes these last two steps pose the greatest challenge as successfully cloning a key requires time, opportunity, and expensive equipment to accomplish. NinjaLab used a Langer near-field electromagnetic probe, a Thorlabs three-axis manual micro-manipuator, and a Pico Technology PicoScope oscilloscope to execute the side channel measurements. Researchers estimate the costs of this equipment at nearly $13,000.

What This Means For Security Keys

While Ninja labs has proven cloning a Google Titan key or similar is possible given sufficient motivation and resources, the authors argue that physical MFA keys are still far more effective than the alternative.

“The adversary could make a clone allowing her to sign in to the targeted application, assuming she previously had stolen the login and password on the victim’s application account with out the victim noticing,” the authors write. “However, this requires that the adversary steals during several hours the device of the victim noticing, open or thing the IC package, access to expensive side-channel set-up equipment,  and custom attack software.”

In other words, this isn’t an indiscriminate vulnerability likely to impact large numbers of people. For this reason NinjaLab isn’t discouraging the use of the Google Titan security key or devices like it.

“It is still clearly far safer to use your Google Titan security key — or other impacted products — as FIDO U2F two-factor authentication token to sign into applications like your Google account rather than not using one,” the authors write.

Ninja Labs adds that adequate security measures can help to limit the potential damage caused by a cloned security key. Suggested measures include implementing a MFA system that can detect a cloned key and lock down the affected account.

With that said, the researchers do encourage users likely to be targeted by an attack, like the one detailed in the report, to switch to an MFA hardware security key with no know vulnerabilities.