Woohoo! My urge-zero key stopped working mysteriously and I wasn’t happy about that but I’ll give them another chance.
Solo – Open-source FIDO2 security key
51–60 of 65 posts
Re: Solo – Open-source FIDO2 security key
#52From the image it doesn't look like it'll be easily hand solderable. I love that about the U2F zero (though I'm still torn on if I should build it or buy it).
I'm thinking about making a short video showing how to solder one reliably for folks interesting in making their own. Unfortunately newer MCUs these days often don't come in easy-to-solder packages.
Re: Solo – Open-source FIDO2 security key
#53Solo describes itself as "An upgrade to U2F Zero." What does it do better than U2F Zero?
Also planning to have case, USB-C option, NFC option
Re: Solo – Open-source FIDO2 security key
#54> It protects against phishing Not so much. U2F proves only that the user tapped the device when asked to do so. You still have to trust your browser and your entire desktop that the tap will be used to log in to the service you are browsing instead of e.g. quietly logging to your home banking. To prevent "tap hijacking" we need a display on the U2F key to show the URL/service you are really authenticating to.
Re: Solo – Open-source FIDO2 security key
#55I wonder where are they going to manufacture it, and what control and visibility will they have into their supply chains, both upstream and downstream? Absent some very serious issue with the crypto implementation, that would be my greatest concern -- how easy would it be for a state-level actor to introduce some sort of backdoor or other vulnerability (even a subtle one, e.g. modification to EM radiation pattern) to…
Right now, we plan to do the programming ourselves to at least verify that goes okay. Since we are bootstrapping, we are outsourcing the PCB-A, but hopefully since this is pretty expensive threat for an adversary to invest in, I don't think it would be an issue unless we show to have a large market. By then, we can move more supply chain in house :)
Re: Solo – Open-source FIDO2 security key
#56What processor parts will this be using? A major benefit of the Yubikey U2F parts is that they're almost indestructible. I've heard over and over again about how flimsy the Feitian parts are, and from people who have run over their Yubikeys with cars and still had them work. How resilient (in particular: waterproof) will these be?
Re: Solo – Open-source FIDO2 security key
#57Earlier quoted context omitted.
That's a better MCU, but aren't they using a secure element to store keys?
Right. Why not add a ATECC608A?
Given this, I think having a 1 chip solution really simplifies the design and allows more flexibility.
Re: Solo – Open-source FIDO2 security key
#58Earlier quoted context omitted.
Yubikey 4C is very fragile. Mine has quite severe cracks on its plastic casing after 4 months of casual use (nothing extreme!), and I expect it to break in some months. YK4 (non-C) is quite robust, though.
My experience has been the same, I've had a 4 for years and it is still going strong but my 4C died in less than 12 months; the USB-C connector is too flimsy.
Re: Solo – Open-source FIDO2 security key
#59Re: Solo – Open-source FIDO2 security key
#60Bit of a tangent, but out of interest, why KickStarter as opposed to CrowdSupply?