That was under the previous leadership when Stina Ehrensvärd was CEO.
Now they've taken VC money[1], and more recently merged with a listed SPAC[2] I suspect replacement devices will never happen because, you know, shareholders come first.
I wish Yubico had some serious competition, but sadly they don't. NitroHSM is not the same thing (plus has flashable firmware, which leads to potential security risks). Tilitis looks interesting, but its far from maturity.
[1] https://www.yubico.com/blog/yubico-adds-new-round-of-investm... [2] https://www.yubico.com/blog/yubico-is-merging-with-acq-bure/
This likely wouldn’t qualify as “serious competition” but I have a few solokeys and they work fine for my use.
Despite being a bit careless with my keys (e.g. leaving them in a pocket and washing said clothing), they still work just fine. I highly recommend SoloKeys to anyone who wants to support open source hardware and firmware.
Looking at the list of FIDO certified hardware authenticators alone, they definitely do.
My country's eID scheme even requires FIDO Level 2 certification, which Yubico hasn't had for a while, so they practically supported only non-Yubico authenticators until recently.
What's not the same thing as what? There's no NitroHSM (Nitrokey has 2 different HSM-related products that are different kinds of things from each other, and neither is called that), and most Yubikeys aren't their special HSM devices.
Also mentioning OnlyKey <https://onlykey.io>. You don’t need to be some big corpo to be considered ‘serious’.
That's not what I meant and I suspect you know that. :)
I meant everything from the Yubico hardware (more compact and less bulky than anything else out there) to the Yubico software (extensive featureset with more controllability than most other products out there).
Also as I said already, Yubico is one of the few (only ?) one that does not permit firmware flashing. Most competitor keys have firmware flashing capability, which to me is a big no-no as its an attack surface just waiting for an exploit.
That's what I meant by 'serious'.
I would be feeling a bit miffed if I bought one recently, though.
One ? How about corporates who recently bought a batch ? ;)
Previously when their Yubikey 4's were found to be suceptible to the ROCA vulnerability [0], they issued replacements [1] for any customers who had affected devices. I had a few of those devices and they were replaced for free.
I guess that's a disadvantage of having a non-upgradable firmware. They can't fix these devices that are already out in the field.
[0] https://en.wikipedia.org/wiki/ROCA_vulnerability
[1] https://support.yubico.com/hc/en-us/articles/360021803580-In...
This vulnerability, meanwhile, appears to be in the class of "if someone has physical access to your hardware token, and has access to some specialized (expensive) hardware to do side-channel analysis, they might be able to do side-channel on your hardware token." But if someone has physical access to the hardware token... I mean, at that point, most people would consider it compromised anyways and wouldn't expect security guarantees from that point.
Not being able to flash the firmware is a feature, not a bug. :)
Its the fundamental reason I won't buy NitroHSM because of the Rumsfelt unkown-unknowns about use of the firmware flash feature on NitroHSMs as a future exploit route.
It is a feature only if they ship replacement devices in case of issues like this. If they don't and you're left with a broken device then I'd rather count it as a "bug".
Indeed, but I didn't say otherwise :)