Live data from Hacker News

Yubico is merging with ACQ Bure and intends to go public

yubico.com

21–30 of 222 posts

Re: Yubico is merging with ACQ Bure and intends to go public

#21
post #14

I have an irrational concern about using security products from a company post-merger or acquisition. It has never ended well for me as an anecdotal user. Going public is taking that worry even further. Make keys, sell keys. The end. What's there to raise funding for? Build yet another password vault?

This is not really a merger because the other company is a “blank check” holding company (a.k.a. SPAC). It has no operations, it just holds a bunch of money put in by investors who want to find a private company that wants to go public.

The fact this is not only legal, but common practice baffles me ...

Re: Yubico is merging with ACQ Bure and intends to go public

#22
post #5
post #2

Anyone has insights into how trustworthy is Yubico? Their firmware is opaque, not shared outside the company, so is their hardware (important for RNGs etc).

Very. They are a tiny Swedish company that pay for top talent, are quite active and hands-on in the netsec community. It's not a faceless corporation with a Chinese PO Box.

> It's not a faceless corporation with a Chinese PO Box.

On this note, are Feitian still the OEM for the Google Titan keys?

Re: Yubico is merging with ACQ Bure and intends to go public

#23

I have an irrational concern about using security products from a company post-merger or acquisition. It has never ended well for me as an anecdotal user. Going public is taking that worry even further. Make keys, sell keys. The end. What's there to raise funding for? Build yet another password vault?

For personal use, I just tried to buy a few pre-SPAC units, just in case. But they seem to no longer sell any plain non-NFC USB-A keychain models.

Re: Yubico is merging with ACQ Bure and intends to go public

#24
post #9
post #4

(ACQ Bure is a SPAC.)

> A special purpose acquisition company (SPAC; /spæk/), also known as a "blank check company", is a shell corporation listed on a stock exchange with the purpose of acquiring a private company, thus making it public without going through the traditional initial public offering process and the associated regulations thereof. https://en.wikipedia.org/wiki/Special-purpose_acquisition_co...

Why is that even legal?

Re: Yubico is merging with ACQ Bure and intends to go public

#25
post #11

Earlier quoted context omitted.

US government had a nice little swedish cryptography company there for a bit too...

Do you mean Swiss (classic!) or was there another one? https://en.wikipedia.org/wiki/Crypto_AG

Though started by the Swede Boris Hagelin.

https://en.wikipedia.org/wiki/Boris_Hagelin

Re: Yubico is merging with ACQ Bure and intends to go public

#26
I really hope this does not affect their current mode of operation. The reason I bought my Yubikeys in the first place were the one off purchase cost and the promise that the keys would do their job without me having to interact with Yubico from that point onwards. This has worked great so far!

Now with shareholders in the mix I fear they will try to find recurring income models to increase profits. I guess we'll just have to see.

Re: Yubico is merging with ACQ Bure and intends to go public

#27
post #5
post #2

Anyone has insights into how trustworthy is Yubico? Their firmware is opaque, not shared outside the company, so is their hardware (important for RNGs etc).

Very. They are a tiny Swedish company that pay for top talent, are quite active and hands-on in the netsec community. It's not a faceless corporation with a Chinese PO Box.

Tiny is a bit misleading. The turnover is about 100 MUSD. The company has about 300 employees, with offices in all regions of the world and a lot of R&D in the USA.

Re: Yubico is merging with ACQ Bure and intends to go public

#28
post #8

Time for an open source u2f token.

Well an interesting new approach to security tokens just launched: the tillitis tkey[1]. It has open source hardware and software. Unlike other security tokens that are based around storing your key where it can't be read, the tillitis tkey doesn't have any persistent storage and instead calculates your private key by hashing the program you've loaded onto the key, a user-supplied secret, and a per-device random secr…

>Currently we ship to EU/EEA countries, Norway, Switzerland, UK, USA and Canada

Re: Yubico is merging with ACQ Bure and intends to go public

#29
post #21
post #14

Earlier quoted context omitted.

This is not really a merger because the other company is a “blank check” holding company (a.k.a. SPAC). It has no operations, it just holds a bunch of money put in by investors who want to find a private company that wants to go public.

The fact this is not only legal, but common practice baffles me ...

It’s a more transparent and less predatory than venture capital.

Re: Yubico is merging with ACQ Bure and intends to go public

#30
post #5
post #2

Anyone has insights into how trustworthy is Yubico? Their firmware is opaque, not shared outside the company, so is their hardware (important for RNGs etc).

Very. They are a tiny Swedish company that pay for top talent, are quite active and hands-on in the netsec community. It's not a faceless corporation with a Chinese PO Box.

If you are looking for a tiny, Swedish company working in a similar area as Yubico, there is Tillits AB. Tillitis is a spin off from the Swedish VPN provider Mullvad. In contrast to Yubikeys, The Tillitis TKey as well as tools, device verification etc is 100% open source.

https://tillitis.se/

https://github.com/tillitis

https://mullvad.net/en

(Full disclosure: I work for Tillitis.)

Post reply on HN