A new open security key: Solo v2
solokeys.com
solokeys.com
There’s a reason Yubikeys can’t be updated, and it’s not to sell more Yubikeys.
We do support firmware upgrade, unlike other security keys. For example in 2020 we patched a couple security issues, while Yubico, Google Titan and Feitian all recalled keys. Specs and thus firmware are getting bigger and more complex, so we believe that updates are the only way to maintain security in the long run.
We do not use a secure element, unlike other keys. This is not a statement, it’s just a fact. If you want an open product, there’s no “secure element” available that doesn’t require an nda. We hope that our work (we’re not alone in this) will motivate manufacturer to release secure elements with less obscurity around them.
My biggest problem is not the key.
My biggest problem is the fact that I can't easily roll keys out in a startup with 5 people and not become the customer service IT person handling security problems every day.
Solve THAT problem and I'll pay a monthly fee for your service.
That threat is so far off the typical path that it can't even see civilization anymore.
However, simply encasing the key in acrylic would solve your use case.
These keys are meant to solve the typical remote attacks like phishing--and they do that extremely well.
They also are quite good at stopping the: "Someone stole my laptop and now has access to everything." If the key is on your keychain, that scenario is stopped cold.
These keys are not really meant to solve one-to-one attacks by determined adversaries. And, to be fair, such an adversary is going to compromise your OpSec LONG before he tries to compromise your key.
The only things I see are 10x faster NFC, and "reversible", whatever that means.
Does reversible mean you can plug it in without looking, because there is no upside-down?
It is far from clear what the NFC feature actually does. Does it mean it doesn't need to be plugged into the USB port to work? Uses passive components, or draws enough power from NFC to operate?
I know that v1 (or, anyway, Somu) supported only ECDSA keys, not ED25519, and only one key per physical device. Is that changed?
- More secure microcontroller supporting secure boot, PUF, flash encryption, etc.
- Firmware rewritten in rust.
- Much more robust and durable construction.
- Touch buttons, reversible USB-A, USB-C
NFC is passively operated similar to other authenticators and is more reliable.
ED255 is supported in V2!
Does it support installing more than one key?
There’s no constrain on the number of keys. You can use 1 device with unlimited sites, both v1 and v2, because keys are generated on-the-fly and not stored.
(There’s a limit on number of resident keys, and we supported 50 in v1, while for example yubikeys support 25. So far these are rarely used, if ever.)
Somu can store 50 resident keys exactly like Solo v1, as it has exactly the same MCU. In both there's a single master secret that's used to derive the (non-resident) keys. That's the only thing that's unique.
Personally, I would prefer flush mount and/or tactile buttons, but NBD.
Hope they will be available on other than kickstarter, as I never got it to work, with all their tracking and what-not.
54726637-0-gif-9.gif
(happy owner of solo1)