Solo – Open-source FIDO2 security key
solokeys.com
solokeys.com
A major benefit of the Yubikey U2F parts is that they're almost indestructible. I've heard over and over again about how flimsy the Feitian parts are, and from people who have run over their Yubikeys with cars and still had them work. How resilient (in particular: waterproof) will these be?
(I have them alongside my keys; one is a NEO - still working - the other is (was) U2F only)
[1] https://www.silabs.com/products/mcu/32-bit/efm32-pearl-gecko
Given this, I think having a 1 chip solution really simplifies the design and allows more flexibility.
YK4 (non-C) is quite robust, though.
I don't setup hardware 2FA on personal accounts with less than 3 enrolled devices (and from 2 different vendors).
I just finished building my first USB-C (for standard USB) board board, it's surprisingly easy, 2 extra resistors - pad tolerances are tight, but it's not hard
However, perhaps you're referring to the OpenPGP Smart Card spec, which does indeed lack support for Curve 25519 and EdDSA.
I wish the spec would be updated to include them...
Not so much. U2F proves only that the user tapped the device when asked to do so.
You still have to trust your browser and your entire desktop that the tap will be used to log in to the service you are browsing instead of e.g. quietly logging to your home banking.
To prevent "tap hijacking" we need a display on the U2F key to show the URL/service you are really authenticating to.
If the phishing page is then able to compromise the browser the security is breached.
For example it could trick the browser into presenting the legitimate URL to the U2F token, or wait for the user to log on the home banking site for real and then perform transaction, or many other attacks.
Absent some very serious issue with the crypto implementation, that would be my greatest concern -- how easy would it be for a state-level actor to introduce some sort of backdoor or other vulnerability (even a subtle one, e.g. modification to EM radiation pattern) to either all or just a select subset of devices, either into components "upstream" in the supply chain, in manufacturing itself, or downstream in transit to the retailer/customer.
Right now, we plan to do the programming ourselves to at least verify that goes okay. Since we are bootstrapping, we are outsourcing the PCB-A, but hopefully since this is pretty expensive threat for an adversary to invest in, I don't think it would be an issue unless we show to have a large market. By then, we can move more supply chain in house :)
We'll just have to verify which features are copiable vs proprietary for yubikeys. To be honest I don't know at this point, I mostly use my keys for auth, rarely otp, but no gpg/ssh/etc.
Do you have any primary use case that you're interested in?
If it did that then it would potentially replace my YubiKey(s).
My first and primary use of my key is that I use HMAC hashing on the Yubikey to unlock my KeepPassCX database. This solution works very well for me because it works seamlessly on multiple platforms (Linux and Windows) and is also compatible with Keepass2Android for my phone. I've looked into GPG only solutions and the ones I looked at didn't offer either the cross-platform compatibility and or browser integration, which is nice. The strong advantage of the Neo (vs the other hardware keys) is the use of NFC, which means less plugging things into my phone. In an ideal world, I'd love to get NFC working with my computers too.
I also use the PGP/SSH smartcard capabilities of my Yubikey on Linux (Ubuntu) and that's been flawless. I don't use SSH on Windows, but I hear the integration there is fairly solid as well.
I've not yet begun to use U2F for authentication, yet. My focus is on my most important services first, which is my passwords and logins. I'll be moving to U2F soon though.
If there was a way to store my passwords easily using PGP instead of HMAC, I'd be interested in that. The issue isn't the storage, but the interface to that storage being easy to use and cross platform (which is not the domain of the hardware, obviously). If I had that, I could consider not needing the HMAC.
I've heard that there is a way to use U2F offline for SSH, but I haven't looked into it. I'm still using SSH keys for things like SSH and Git. Perhaps if there was a solution to that, I might drop the GPG requirement, but I'd need either HMAC or GPG for decryption of my password database, so in any case, FIDO alone isn't enough.
Also planning to have case, USB-C option, NFC option
FIDO2, according to https://fidoalliance.org/fido2/ , is the overall project that includes both WebAuthn and CTAP — the latter being the new protocol for talking to the keys.
I'm thinking about making a short video showing how to solder one reliably for folks interesting in making their own. Unfortunately newer MCUs these days often don't come in easy-to-solder packages.
Just sayin'.
(My recommendation would be to not make this a background image, but simply an image in the markup after the headline.)
(followed the recommendation -- only for large screens though, it's late and I don't want to make mistakes ehehe)