Live data from Hacker News

OnlyKey: Open-Source Alternative to YubiKey

onlykey.io

211–215 of 215 posts

Re: OnlyKey: Open-Source Alternative to YubiKey

#211
post #11

This seems to predate FIDO2. https://solokeys.com/ would be a better option if you prefer separate keys for each site (via FIDO2) and open source hardware.

I've got a few SoloKey. This project seems like a joke comparatively as solo is actually open source hardware[0] and this is not. You can look above to see how OnlyKey might be more trouble on the software side than it's worth and potentially is just a liability. [0] https://github.com/solokeys/solo-hw

I've got a few SoloKeys too. The USB C one broke in half and looking on Amazon reviews this is an issue for lots of people. Meanwhile my OnlyKey has been running strong 3 years in and has been on my keychain the whole time. Also SoloKey doesn't manage passwords at all, while OnlyKey does.

Re: OnlyKey: Open-Source Alternative to YubiKey

#212
post #123

Solo was the first open source alternative to YubiKey. I'm using one of their products and have been happy with it so far: https://solokeys.com/

FYI, this is fake news OnlyKey has been around since 2016 and has been open source the whole time. Solo was launched in 2018 and claimed to be the first FIDO2 open source security key, this was only true because at the time OnlyKey wasn't FIDO2. OnlyKey was the first open source security key. Also Solo isn't even a viable alternative to YubiKey as it doesn't support challenge-response, static passwords, or OpenPGP. OnlyKey does support all of those things.

Re: OnlyKey: Open-Source Alternative to YubiKey

#213

I honestly don't understand how a YubiKey is supposed to help me secure my accounts if I get locked out of my accounts when I lose it. I an trivially copy a keepass database anywhere and have dozens of backups. If I want to do the same with a YubiKey I first have to buy multiple YubiKeys and then I have to register each one on each site. This means they cannot be used as a primary authentication method because they a…

Well, if you have multiple yubikeys on each site, then it can be used as a primary authentication method - because if you lose yubikey A, then the emergency fallback is yubikey B which you can use to revoke the access of yubikey A and add yubikey C instead. Or, you have a set of one-time codes for recovery. I have accounts with a lot of sites, and all the sites that support proper U2F did have one-time recovery code…

I used to a pile of yubikeys like this (yubikey A, B, C) then I replaced them all with one OnlyKey. Each Yubikey only has 2 slots, each OnlyKey has 24 and it has a secure backup feature.

Re: OnlyKey: Open-Source Alternative to YubiKey

#214

Earlier quoted context omitted.

I've got a few SoloKey. This project seems like a joke comparatively as solo is actually open source hardware[0] and this is not. You can look above to see how OnlyKey might be more trouble on the software side than it's worth and potentially is just a liability. [0] https://github.com/solokeys/solo-hw

I've got a few SoloKeys too. The USB C one broke in half and looking on Amazon reviews this is an issue for lots of people. Meanwhile my OnlyKey has been running strong 3 years in and has been on my keychain the whole time. Also SoloKey doesn't manage passwords at all, while OnlyKey does.

But it's not open source. Why even bother to call it open source if it's not? Since the Solo is open source hardware if you don't like it, you can change the design and get your own boards cut on OSH Park.

Re: OnlyKey: Open-Source Alternative to YubiKey

#215
post #177
post #97

Earlier quoted context omitted.

Feitian advertises one here https://www.ftsafe.com/Products/FIDO/NFC and they say you can request a dev version so you can install your own applets, but I can't vouch for it yet personally.

Looks interesting, thanks for the link!

Apparently K9 Dev version is basically like eJavaToken, without applets installed, so no U2F, only CCID. Unless you specifically want that don't order.
Post reply on HN