From the website:
>The TKey™ is a new kind of USB security key inspired by measured boot and DICE.
>TKey™s design encourages developers to experiment with new security key applications and models in a way that makes adoption easier and less risky forend-users.
>TKey™ is and always will be open source hardware and software. Schematics, PCB design and FPGA design source as well as all software source code can be found on GitHub.
[1]: https://www.tillitis.se/ -- also "tillit" is Swedish for "trust" and "mullvad" is Swedish for "mole" (the animal).
they also support ed25519 FIDO SSH keys, whereas all the cheapo FIDO keys I've tested only support ecdsa-nistp256, but that's a relatively minor difference.
Nitrokey 3 claims that GPG smart card support is planned in an upcoming firmware update. once that's released I may bite the bullet on shipping costs and order one. 55€ shipping to the US for a 49€ key is cost-prohibitive for the most part.
A Yubikey is just a proprietary smartcard with a bunch of apps installed and some HID emulation (pretending to be a keyboard, which you likely do not want).
They have been claiming many things. I pre-ordered a Nitrokey 1.5 years ago, still haven't received it, and apparently during this time they have not implemented much.
https://www.nitrokey.com/blog/2023/nitrokey-3-status-update-...
Cryptocurrency wallets are horrible for normal security features that do not involve blockchains.
There are so many UX reasons why you would never want to conflate a login token with a key that can mathematically and instantaneously eviscerate your life savings. But to put it simply; there’s no way anyone’s grandma can use this system, wherein with something like browser Passkeys she has a chance.
The backup functionality (which requires encryption password entry on a computer, i.e. not the device itself) looks especially concerning.
[0] https://developer.mozilla.org/en-US/docs/Web/API/Web_Authent...
WebAuthN specifices the browser API, CTAP2 specifies the interface between an authenticator device/software implementation and a browser or other client, and FIDO specifies the behavior of the authenticator itself (including certification of attestation-capable authenticators).
For AWS, I use Firefox and a FIDO key, and have a backup MFA as Safari using U2F.
You can't use Safari's option on anything other than that particular Mac or iPhone. It's my understanding that you can't extract the secret key from the secure enclave.
Hell, even software based implementations which force domain checking would solve 99% of the problem…
But there are indeed alternatives to yubikey. Anyone have experience with https://www.token2.com/shop/product/token2-t2f2-fido2-and-u2... ? 128 resident keys is much better than 25/50
The Solo team believes that other functionality such as PIV overlaps with GnuPG use cases, so that OpenPGP isn't a priority, and their work on that functionality appears to have stopped in 2021. That's too bad, because OpenPGP's network effects far outweigh its pure functionality, which means a technical substitute isn't a substitute.
In August 2022 they released a major firmware update. Maybe that addressed the iCloud incompatibility and reliability issues?