<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>security tokens &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/security-tokens/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Fri, 06 Sep 2024 15:16:21 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>YubiKey Side-Channel Attack</title>
		<link>https://noise.getoto.net/2024/09/06/yubikey-side-channel-attack/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 06 Sep 2024 15:16:21 +0000</pubDate>
				<category><![CDATA[academic papers]]></category>
		<category><![CDATA[cloning]]></category>
		<category><![CDATA[security analysis]]></category>
		<category><![CDATA[security tokens]]></category>
		<category><![CDATA[side-channel attacks]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69329</guid>

					<description><![CDATA[There is a side-channel attack against YubiKey access tokens that allows someone to clone a device. It&#8217;s a complicated attack, requiring the victim&#8217;s username and password, and physical access to their YubiKey&#8212;as well as some technica...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Smart Contract Bug Results in $31 Million Loss</title>
		<link>https://noise.getoto.net/2021/12/02/smart-contract-bug-results-in-31-million-loss/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 02 Dec 2021 14:32:36 +0000</pubDate>
				<category><![CDATA[blockchain]]></category>
		<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[security tokens]]></category>
		<category><![CDATA[theft]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=64598</guid>

					<description><![CDATA[<p>A hacker stole $31 million from the blockchain company MonoX Finance , by <a href="https://arstechnica.com/information-technology/2021/12/hackers-drain-31-million-from-cryptocurrency-service-monox-finance/">exploiting a bug</a> in software the service uses to draft smart contracts.</p>
<blockquote><p>Specifically, the hack used the same token as both the tokenIn and tokenOut, which are methods for exchanging the value of one token for another. MonoX updates prices after each swap by calculating new prices for both tokens. When the swap is completed, the price of tokenIn­that is, the token sent by the user­decreases and the price of tokenOut­or the token received by the user­increases.</p>
<p>By using the same token for both tokenIn and tokenOut, the hacker greatly inflated the price of the MONO token because the updating of the tokenOut overwrote the price update of the tokenIn. The hacker then exchanged the token for $31 million worth of tokens on the Ethereum and Polygon blockchains...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 29/67 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-10 04:57:42 by W3 Total Cache
-->