Live data from Hacker News

Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

github.com

41–50 of 94 posts

Re: Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

#41

I didn't know github also supports 3d models with visualization

For those confused, see https://github.com/conorpp/u2f-zero/commit/dd71758a

Is that green because it supports difs?!

Re: Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

#42
post #10

This project is awesome, but I'd be worried about my hand brushing up against all that lead every day for years. Or am I being too paranoid? In any case, easily solved with some casting epoxy.

The tiny amount of lead involved is very unlikely to be harmful. You could probably safely eat the amount of solder used to assemble that board.

I do think think a case is necessary though, as those SOIC packages will not last long in pocket with keys before they are ripped off the PCB.

Re: Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

#43
post #24

I'm curious about the following statement in the README: > The token is durable enough to survive on a key chain for years, even after going through the wash. On the other hand, the token is shown as "naked electronics", without a husk. Is that really sufficient for such a device? Does it really withstand (mineral) water, mechanical stress (key chain), let alone the combination of both (washing)?

I'd be very skeptical about that claim without substantial evidence of it surviving in the field. Especially if you use ROHS solder, which is more brittle than leaded solder.

There is an ESD diode in the design but it only protects certain pathways -- a zap could come from anywhere if the thing is bare.

Re: Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

#44
post #30
post #8

My barrier to entry with a lot of DIY hardware projects was an incorrect assumption that it was difficult/expensive to get PCBs made. Looking into this, I found the blog of the guy running this project and he had some experience with various cheap PCB vendors, with stencils going as low as $18. [1] [1]: https://conorpp.com/2016/03/13/my-experience-with-dirtypcbsc...

A lot of amateur radio HF range projects use what is known as the "manhattan style" construction where, a copper clad board is used as a ground plane, so to speak and then tiny round pads are glued to it, which act as islands. The pads can be made using paper punch of appropriate grade. I have used cheap punch used for cutting paper and have made pads in the past. The parts are then soldered directly to these island…

Modern SMD microcontrollers tend to have pretty fine pin pitches, often in the 1mm ballpark. You really want a proper PCB for those.

Re: Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

#45

Earlier quoted context omitted.

Cast in epoxy. Cheap and quite durable.

Do you have any information on what you need to buy and how it works? Do you need a hot air station?

It's just a base + a hardener, mix and cast. Make sure you protect switches and connectors before casting. The reaction is exothermal, if you cast larger volumes you may need to cool the whole thing to avoid trouble (such as fire).

Re: Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

#46
post #12

The author, Connor Patrick's personal site has a "looking for work" page[1]. It reads: I want to work on projects that do good. I don’t want to work on projects regarding surveilance or the weaking of existing cryptosystems. Way to go Connor! [1]: https://conorpp.com/work/

>>> I’m currently looking for work in the U.S. government.

A crypto work in the goverment not related with surveilance - directly or not- seems difficult to find.

Or am I missing something ?

Re: Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

#47
post #37
post #12

The author, Connor Patrick's personal site has a "looking for work" page[1]. It reads: I want to work on projects that do good. I don’t want to work on projects regarding surveilance or the weaking of existing cryptosystems. Way to go Connor! [1]: https://conorpp.com/work/

It's "weakening".

Way to go, Connor.

Re: Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

#48
post #8

My barrier to entry with a lot of DIY hardware projects was an incorrect assumption that it was difficult/expensive to get PCBs made. Looking into this, I found the blog of the guy running this project and he had some experience with various cheap PCB vendors, with stencils going as low as $18. [1] [1]: https://conorpp.com/2016/03/13/my-experience-with-dirtypcbsc...

My father made a simple PCB himself a few years ago. He designed the PCB with http://www.geda-project.org/ (I think?), printed out a negative of the PCB on a (printer-safe!) transparent page, and used an old overhead projector as the light source for the etching.

That being said, I suspect that methodology doesn't scale down to such small features, multiple layers etc. that you see in the link you posted, so at some point you have to give up on DIY etching.

Re: Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

#49

Earlier quoted context omitted.

Cast in epoxy. Cheap and quite durable.

Do you have any information on what you need to buy and how it works? Do you need a hot air station?

Similar to this -> http://makezine.com/2012/04/12/the-most-beautiful-homemade-d...

Re: Show HN: A secure, open source U2F token you can make with $4.5 worth of parts

#50

Earlier quoted context omitted.

Do you have any information on what you need to buy and how it works? Do you need a hot air station?

It's just a base + a hardener, mix and cast. Make sure you protect switches and connectors before casting. The reaction is exothermal, if you cast larger volumes you may need to cool the whole thing to avoid trouble (such as fire).

That sounds easy enough, thanks!
Post reply on HN