Live data from Hacker News

OnlyKey: Open-Source Alternative to YubiKey

onlykey.io

11–20 of 215 posts

Re: OnlyKey: Open-Source Alternative to YubiKey

#13
post #4

I couldn't find any open source links on the site (reading from phone), is it open hardware or open config app/firmware?

There is a link to https://github.com/trustcrypto from within what seems to be the footer of (at least) the FAQ page.

Huh. So they have the firmware up, and a forked project that gets FIDO2 working on an Audrino .. I don't see and CAD files or any repos that seem to contain circuit diagrams. Is the hardware something standard they load firmware on, or is only he firmware open and the hardware designs closed?

Re: OnlyKey: Open-Source Alternative to YubiKey

#14
post #11

This seems to predate FIDO2. https://solokeys.com/ would be a better option if you prefer separate keys for each site (via FIDO2) and open source hardware.

Given that only key appears to support FIDO2 it seems unlikely that it pre-dates FIDO2.

>"Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubikey OTP, TOTP, Challenge-response."

Re: OnlyKey: Open-Source Alternative to YubiKey

#15
Security keys are the heart of security and we desperately need open-source solutions on this. Kudos for doing it.

Now, I must point out a few things:

1. Please don't call your solution "Open-source", when you do not have not even the schematics uploaded to github.

2. (this item is an open problem without a solution yet) how do I make sure the source code and the (still missing) hardware information actually corresponds to the hardware I'm buying?

If we do take item 2 seriously, one may say that buying Yubico is actually "safer" than your open-source solution, mainly due to company reputation and credibility.

Again, sorry the harsh words, but I take my keys seriously.

Re: OnlyKey: Open-Source Alternative to YubiKey

#16

Security keys are the heart of security and we desperately need open-source solutions on this. Kudos for doing it. Now, I must point out a few things: 1. Please don't call your solution "Open-source", when you do not have not even the schematics uploaded to github. 2. (this item is an open problem without a solution yet) how do I make sure the source code and the (still missing) hardware information actually correspo…

Also, you guys should definitely do some research about side-channel attacks. I quickly inspect the source code and did not find any counter-measure.

Re: OnlyKey: Open-Source Alternative to YubiKey

#19

Security keys are the heart of security and we desperately need open-source solutions on this. Kudos for doing it. Now, I must point out a few things: 1. Please don't call your solution "Open-source", when you do not have not even the schematics uploaded to github. 2. (this item is an open problem without a solution yet) how do I make sure the source code and the (still missing) hardware information actually correspo…

I'm having a rough time even finding the "open source" embedded software running on the onlykey. This site definitely needs an "open source" section linking to the relevant github/gitlab repos, or at least cross links/references to source within their documentation. I see tons of claims, but no way to validate them.

Re: OnlyKey: Open-Source Alternative to YubiKey

#20
Can this device function as an SSD, holding, for example, a Keepass2Android APK file and a KeePass database -- as well as being able to open said datanbase via one of the stored profiles? It doesn't need to have a lot of storage... 640 MB ought to be enough for anyone's KeePass databases.
Post reply on HN