@nuntius @thomas That's something I would expect. As their "secure hardware"™/proprietary (and thus unaudited) stuff[1] failed to be secure… well… that's the minimum they should do. [1] https://www.yubico.com/2016/05/secure-hardware-vs-open-source/