Live data from Hacker News

Yubico is merging with ACQ Bure and intends to go public

yubico.com

51–60 of 222 posts

Re: Yubico is merging with ACQ Bure and intends to go public

#51
post #9

Earlier quoted context omitted.

> A special purpose acquisition company (SPAC; /spæk/), also known as a "blank check company", is a shell corporation listed on a stock exchange with the purpose of acquiring a private company, thus making it public without going through the traditional initial public offering process and the associated regulations thereof. https://en.wikipedia.org/wiki/Special-purpose_acquisition_co...

Why is that even legal?

Why should it not be legal? Exactly what is wrong with it and how would legislation that forbids it but allows other M&A activities look like? I don't see a problem.

Re: Yubico is merging with ACQ Bure and intends to go public

#52
post #35

Earlier quoted context omitted.

Is it? VCs don’t raise money from “mom and pop and Reddit” retail investors, but SPACs have enabled insiders to sell stock at $10 that often ends up being worth less than $1 or even bankrupt just a year or two later. These often included a social media pump like the SPACs promoted by “SPAC king” Chamath Palihapitiya. However the companies that go public via SPAC are mostly VC-funded, so in that sense you’re right tha…

Not this SPAC, https://www.avanza.se/aktier/om-aktien.html/1206860/acq-bure... It's mostly owned by Swedish Pension funds.

Yubico is originally Swedish, this makes sense.

Re: Yubico is merging with ACQ Bure and intends to go public

#53
post #5

Earlier quoted context omitted.

Very. They are a tiny Swedish company that pay for top talent, are quite active and hands-on in the netsec community. It's not a faceless corporation with a Chinese PO Box.

If you are looking for a tiny, Swedish company working in a similar area as Yubico, there is Tillits AB. Tillitis is a spin off from the Swedish VPN provider Mullvad. In contrast to Yubikeys, The Tillitis TKey as well as tools, device verification etc is 100% open source. https://tillitis.se/ https://github.com/tillitis https://mullvad.net/en (Full disclosure: I work for Tillitis.)

Is the TKey tamper-proof?

Re: Yubico is merging with ACQ Bure and intends to go public

#54

Earlier quoted context omitted.

If you are looking for a tiny, Swedish company working in a similar area as Yubico, there is Tillits AB. Tillitis is a spin off from the Swedish VPN provider Mullvad. In contrast to Yubikeys, The Tillitis TKey as well as tools, device verification etc is 100% open source. https://tillitis.se/ https://github.com/tillitis https://mullvad.net/en (Full disclosure: I work for Tillitis.)

Is the TKey tamper-proof?

No, not yet. Physical attacks are out of scope for the TKey1, even if we have some mechanisms in play which try to extend the time and effort required to perform a successful evil maid-attack extracting the Unique Device Secret (UDS). See the threat model for the release:

https://github.com/tillitis/tillitis-key1/blob/main/doc/thre...

The current casing is fairly tamper evident (it will break), but we do not yet use real, tamper evident sealing. We are looking at tamper sealing for future versions. And ways to further protect against physical attacks.

Re: Yubico is merging with ACQ Bure and intends to go public

#55
post #5

Earlier quoted context omitted.

Very. They are a tiny Swedish company that pay for top talent, are quite active and hands-on in the netsec community. It's not a faceless corporation with a Chinese PO Box.

If you are looking for a tiny, Swedish company working in a similar area as Yubico, there is Tillits AB. Tillitis is a spin off from the Swedish VPN provider Mullvad. In contrast to Yubikeys, The Tillitis TKey as well as tools, device verification etc is 100% open source. https://tillitis.se/ https://github.com/tillitis https://mullvad.net/en (Full disclosure: I work for Tillitis.)

The key costs 880 SEK. That's about 78 euros or 85 dollars. It's designed to be future proof, with applications being uploaded to the device by the host.

The website feels a bit cramped with all the large text on desktop, like it was only tested on phones

Re: Yubico is merging with ACQ Bure and intends to go public

#56

I really hope this does not affect their current mode of operation. The reason I bought my Yubikeys in the first place were the one off purchase cost and the promise that the keys would do their job without me having to interact with Yubico from that point onwards. This has worked great so far! Now with shareholders in the mix I fear they will try to find recurring income models to increase profits. I guess we'll jus…

As somebody who just bought some keys last week for the same exact reasons, I share the same exact concerns. Why this need to always make more and more money?

Do one thing, do it right, keep your customers happy, get your money, enjoy your life...

Re: Yubico is merging with ACQ Bure and intends to go public

#57
post #36
post #15

Earlier quoted context omitted.

Like SoloKeys? The Solo 2 has a firmware written in Rust: https://solokeys.com

Anybody have a solokey, or have some feedback? I wanted to buy some, but the comments about bent connectors put me off, as well as the supply issues for usb-c

I backed their crowdfunding campaign back in the day. Due to $REASON I didn't test all of them when I got them, but when I got around to it two out of four were broken (the broken ones had USB-C). Their support didn't help at all (why should they? but they could have offered me keys for a better price...)

With that said, I had a Yubikey Neo die for me as well (NFC still worked, USB totally dead) - Yubikey offered me a new key for a discount.

Re: Yubico is merging with ACQ Bure and intends to go public

#58
post #17
post #8

Time for an open source u2f token.

The idea of authenticator hardware is inherently hostile to DIY and open source because you cannot produce or extract a keypair to generate valid attestation statements. Unless you are part of the cartel of course. https://w3c.github.io/webauthn/#attestation-statement

> The idea of authenticator hardware is inherently hostile to DIY and open source

Isn't this the same with all hardware?

Re: Yubico is merging with ACQ Bure and intends to go public

#59

I have an irrational concern about using security products from a company post-merger or acquisition. It has never ended well for me as an anecdotal user. Going public is taking that worry even further. Make keys, sell keys. The end. What's there to raise funding for? Build yet another password vault?

I agree with this as well. Capitalist influence creates a powerful conflict of interest.

When it cuts down to it, which master will yubico serve? The customers or their shareholders?

Now Yubico has a fiduciary responsibility to their shareholders.

I frankly can't think of very many companies that are able to resist this core capitalist corruption. Even Costco is implementing shareholder over customer policies. 1Password? Google's "do no evil." Are there good examples of companies that stay customer first after going public?

Re: Yubico is merging with ACQ Bure and intends to go public

#60
post #5

Earlier quoted context omitted.

Very. They are a tiny Swedish company that pay for top talent, are quite active and hands-on in the netsec community. It's not a faceless corporation with a Chinese PO Box.

If you are looking for a tiny, Swedish company working in a similar area as Yubico, there is Tillits AB. Tillitis is a spin off from the Swedish VPN provider Mullvad. In contrast to Yubikeys, The Tillitis TKey as well as tools, device verification etc is 100% open source. https://tillitis.se/ https://github.com/tillitis https://mullvad.net/en (Full disclosure: I work for Tillitis.)

Good grief, the text on tillitis.se is obnoxiously large and the information density extremely low.
Post reply on HN