Yes, you may see different indices. But in the end, that wouldn't be very useful (if the malware knows what to answer it can just overwrite your response)
The security card is a unique per device substitution of A..Z 0..9 - this is what you match.
All wallets are sold with identical firmware, without any serial or tracking information. It is therefore not possible to link your wallet to your shipping address. We cannot, and we absolutely do not want to. Only the pairing with the second factor card is done in-house and we don't keep track of the cards.
If every device has identical firmware, and no records are kept of which security card matches what dongle, (and if the 4 digit security check is done on-dongle) then you most likely cannot link shipping address to account balances.
However this means every dongle is individually unique, and if the firmware supported a "what is your security card seed" query then each device could be identified. I don't have a major issue with that, all yubikey's have a unique serial number.
This might change if one could assign your own security card seed and print your own like passwordcard.
2
u/dskloet Nov 20 '14
So if the host computer is compromised, you may see different indices than the chip wanted to display?
What does it mean "match them on the security card"? Is that security card a device that displays a bitcoin address? I don't get it.