Live data from Hacker News

Solo – Open-source FIDO2 security key

kickstarter.com

31–40 of 47 posts

Re: Solo – Open-source FIDO2 security key

#31
Looks good, but the form factor of the Yubikey Nano is much nicer for laptops. Once it's in, you just leave it in there, and you don't need to worry about knocking/bending/snapping it.

I could see one of these living in my desktop, but then I'd choose a Yubikey over it again for the OpenPGP support.

I'm already using a separate Yubikey with my phone over NFC. I'm pretty sure that wont work when I get my librem 5 though. I don't even think that's coming with NFC. But my new option for Librem will probably end up being another Yubikey instead of this. Specifically the 4C Nano, as I will hopefully be able to stick it in the phones USB-C port and let it live there whilst it's not charging.

So, looks good, but not for me. Hopefully you're a success and are able to bring out some different form factors at some point in the future.

Re: Solo – Open-source FIDO2 security key

#32
post #25

If any FIDO experts are reading this, two technical questions: 1. Is there anything in the standard about proving to the server that you have a genuine FIDO device that meets certain standards, and not say a piece of software that is merely pretending to be a hardware security module? If so, I presume the Solo will come with whatever certification / digital signature is required? 2. My understanding of FIDO (v1) is t…

1. Yes, it's called attestation, and you can read more here [1]. For example recently Amazon launched support for U2F only allowing some yubikeys. 1b. Solo will have its own attestation certificate, so you'd be able to say I wan't/don't want to accept Solo. I believe this will be more valuable to enterprise/closed environments that publicly available services, but of course an option. 2. FIDO2 and "1" (U2F) work pret…

Makes sense, thanks - and congratulations on how the kickstarter is going so far!

Is Solo going to support the HMAC extension that @agl talked about below?

Re: Solo – Open-source FIDO2 security key

#33

Why would I choose this over the Yubikey, or even Google's offering? And I didn't see on the kickstarter (I may have missed it), where are these being produced? I know people were not interested in Google's because they were being made in China.

Openness? Price? Colors? NFC+USB-C? I guess it depends, we're just offering more choice.

For the production. The ST processor is fabricated in Europe. The PCBs are assembled in China. The programming and testing is done in the US.

Re: Solo – Open-source FIDO2 security key

#35

Looks good, but the form factor of the Yubikey Nano is much nicer for laptops. Once it's in, you just leave it in there, and you don't need to worry about knocking/bending/snapping it. I could see one of these living in my desktop, but then I'd choose a Yubikey over it again for the OpenPGP support. I'm already using a separate Yubikey with my phone over NFC. I'm pretty sure that wont work when I get my librem 5 thou…

You only have to leave the key in by choice. For example, I use my Solo to authenticate login for google. But, I only need it on login....which really doesn't happen very often from my laptop. So, I am not leaving my key embedded in my laptop, which presents a problem if you actually have your laptop lifted at Starbucks!

Re: Solo – Open-source FIDO2 security key

#36
post #34

We've removed “Show HN” on account of a previous one: https://news.ycombinator.com/item?id=18035079 also discussed here: https://news.ycombinator.com/item?id=17778262

I’ve originally put Show because this is the product, the previous was the firmware, but ok.

Did you also apply a penalty? We jumped from #4 to #50, and we have more votes, comments, and are newer than nyt currently in fp.

Re: Solo – Open-source FIDO2 security key

#38
post #23

Earlier quoted context omitted.

> Is there anything in the standard about proving to the server that you have a genuine FIDO device Yes. When registering a credential you can request[1] attestation information. Generally this will come in the form of an X.509 certificate[2] per batch of 100,000 devices which is signed by the manufacturer and which signs the generated key. FIDO is planning on running a central registry[3] of devices which should inc…

First of all, thank you for the high quality response! A FIDO2 device with fingerprint reader was supposedly launched at RSA 2018 [1][2]. [1] https://mobileidworld.com/fido2-compliant-usb-key-fingerprin... [2] https://www.slideshare.net/FIDOAlliance/fido-kwg-tech-semina...

I think it's this one: http://www.e-wbm.com/fido_usb.jsp

But I couldn't find where to buy it.

Re: Solo – Open-source FIDO2 security key

#40
post #35

Looks good, but the form factor of the Yubikey Nano is much nicer for laptops. Once it's in, you just leave it in there, and you don't need to worry about knocking/bending/snapping it. I could see one of these living in my desktop, but then I'd choose a Yubikey over it again for the OpenPGP support. I'm already using a separate Yubikey with my phone over NFC. I'm pretty sure that wont work when I get my librem 5 thou…

You only have to leave the key in by choice. For example, I use my Solo to authenticate login for google. But, I only need it on login....which really doesn't happen very often from my laptop. So, I am not leaving my key embedded in my laptop, which presents a problem if you actually have your laptop lifted at Starbucks!

Yeah, I choose to leave it in there, so I don't have to think about it. For me, that's the thing that finally switched using 2FA from being a burden, to neutral.

I have multiple Yubikeys, and fall back to TOTP on my phone and watch, so if my laptop is lifted, I will care about the financial/inconvenience loss of the laptop, but not the Yubikey.

Post reply on HN