Post
Topic
Board Bitcoin Discussion
Re: Blockchain.info acount hacked while using yubikey....
by
matthewh3
on 27/10/2012, 14:56:16 UTC
I tried out my MtGox YubiKey on the blockchain wallet service, and I noticed the OTP's that it generates are REUSABLE. It seems Blockchain.info is only looking at the first few letters of the OTP, as they are static, you can actually change the end of the OTP and the website will still accept it.

Doesn't sound secure at all to me.

You are absolutely correct

https://bitcointalk.org/index.php?topic=64300.0

What about if you don't use the MtGox Yubikey but the standard version.  Also can you use the standard version of the Yubikey on more than wallet/site and be safe?