Yubikey and NitroKey offer NFC and non-NFC versions of their flagship hardware security tokens (HSTs).
NFC is convenient, but can under some circumstances send e.g. challenge-response exchanges in clear text.
Smartcards using RFID, a similar though not identical protocol, can be queried from ~100cm away.
- Are there other ways are NFC HSTs are known to be more risky than their non-NFC counterparts?
- Should users store NFC HSTs in RFID-blocking pouches, like those used for wireless car keys or contactless bank cards?


The setup they have requires a pair of huge antennas, so pulling that off surreptitiously feels unlikely. They also had a controlled lab environment, so who knows how it would work in a less controlled RF space.
Definitely cool research, but this isnt a viable attack vector IMO.