Is there any way to validate it?
Edit: It seems Yubico is a trusted brand so I guess you are safe when you buy keys from them.
Here is a list of FIDO certified products: https://fidoalliance.org/certification/fido-certified-produc...
Is there any way to validate it?
Edit: It seems Yubico is a trusted brand so I guess you are safe when you buy keys from them.
Here is a list of FIDO certified products: https://fidoalliance.org/certification/fido-certified-produc...
1. Sell you a key whose secret key they already know. This is hard to defend against. But if you just buy a generic key from a reputable manufacturer and aren't a major target this seems pretty safe in practice.
2. Hide something malevolent inside the security key's case, e.g. it's secretly a GPS tracker or it's a tiny USB disk plus keyboard that hacks your PC after detecting inactivity.
You may be able to make more of the hardware yourself, depending on how capable you are with electronics.
(Much) more expensive devices can implement FIDO while actually using arbitrary new keys for each registration and you could arrange to hand-pick the keys and then verify it behaves as intended and uses your chosen keys.
You can at least verify when a cheaply-designed device has changed its secret key, because the public key it offers for github.com is different from before, but yeah, that 'new' secret key could still just be derived from a manufacturer-known seed/secret serial number, too, same as the first one was, but with an incremented counter.
This obviously only applies to products that are being shipped with "Fulfilled by Amazon".
Sources:
https://www.engadget.com/2018/05/31/fulfilled-by-amazon-coun...
https://www.theguardian.com/technology/2018/apr/27/amazon-si...
https://www.cnbc.com/2016/07/08/amazons-chinese-counterfeit-...
They list Google as one of their customers.
Also if you're a Linux kernel developer you get one for free: https://www.nitrokey.com/news/2018/nitrokey-partners-linux-f...