HNHacker News
TopNewBestAskShowJobs

conorpp

752 karma · joined September 10, 2013

conorpp.com

[ my public key: https://keybase.io/conor1; my proof: https://keybase.io/conor1/sigs/wdyXzcj8bXBHa4Xz0Gu_Q7rhBOsKqHC_zqQtTDEj-ss ]

submissionscomments
conorpp··on Designing and Producing 2FA tokens to Sell on Amazon
I'm naive and didn't realize Amazon wouldn't ship internationally by default. I just updated the listing to enable international shipping which should take effect in a couple days. Thanks!
conorpp··on Designing and Producing 2FA tokens to Sell on Amazon
Thank you!
conorpp··on Designing and Producing 2FA tokens to Sell on Amazon
Thanks! I didn't know about Security Dynamics.

I think there's a lot of neat improvements you can make on 2FA products for different markets. But it's kind of at the point where if I wanted to continue working on a better 2FA token, I would have to get funding and do it full time. Although it's always tempting, I'm not sure I want to "cash out" of school and regular life just yet.

Also if I don't work in government I'd be in a lot of debt to pay back school. So that's an additional hurdle.

conorpp··on Designing and Producing 2FA tokens to Sell on Amazon
I agree. The problem is trying to do this at scale. I don't want to do it myself as it would be too time consuming and messy.

Without having the funds for injection/pressure molding, I haven't been able to find a good solution. Maybe there are cost effective services that would work like PCB potting or overmolding.

One service that I found that looks promising is Cavist:

http://cavist.com/

But I haven't gone down this route or found someone that has. I might do this later on.

conorpp··on Designing and Producing 2FA tokens to Sell on Amazon
Haha good question.

Yubico has a good explanation:

https://www.yubico.com/products/yubikey-hardware/fido-u2f-se...

It's the same as any other U2F token. You register it with a service that supports U2F (Google, Github, Duo, etc.) and then present the token and press the button upon logging in later.

No software or drivers needed. It's an HID device so all normal operating systems will support it.

conorpp··on Designing and Producing 2FA tokens to Sell on Amazon
Yeah I'm not sure about the legals and just figured it would be fine. I did get a VID/PID from SiLabs which has already done USB certification for the chip.

FIDO U2F also has a $10k certification process to allow you to use the FIDO logo. I don't think it's worth pursuing for me.

conorpp··on Designing and Producing 2FA tokens to Sell on Amazon
Thank you!

Assembly depends on the service you end up using. For PCBCart, I think I just ended up filling out their template BOM manually. Not much of a hassle since I only have 8 parts. I just had to match the component references on the PCB to the BOM, count the number of pins, provide part number, etc. They figured everything else out, just a question or two on part polarities.

Yeah getting boards assembled for small volumes will likely not be cost effective. You can mess around with online quote tools to get an ideal if it'd be worth it or not. Using parts with pins that extend out from the package (rather than underneath) will always be more cost effective. Less pins is cheaper too.

conorpp··on Felony – An open-source PGP keychain
Yes you're right.

It's hard to say that most mistakes are avoided from two audits. Especially in a browser; there's a lot of attack vectors.

conorpp··on Felony – An open-source PGP keychain
Have you heard of or used signal?

https://whispersystems.org/

Same idea -- strong crypto that's usable for anyone. It uses the OTR Ratchet protocol which uses perfect forward secrecy. The app also provides a way to verify keys through an OOB channel.

I would recommend considering OTR Ratchet integration just like WhatsApp did recently.

PGP is not a good design choice for a messaging app as you're always using asymmetric crypto operations which are computationally intense -- not terrible on modern computers but will be dreadful on mobile devices. Also can you provide some more documentation on how the app leverages PGP? Hopefully conversation is not using the same private keys to encrypt. That is vulnerable to data or side channel leakage. The modern approach is to generate and exchange an ephemeral key. Also please provide information on key storage.

Rather than making vague security claims like "first-rate" and " Security++ to the greatest extreme" you should rather provide a threat model and explain why one can remain confidential and have authenticity against particular types of adversaries. No security tool is perfect and it's only a matter of time before an adversary breaks it. Developers are doing a disservice by claiming anything more.

Before you can claim a first-rate security tool you will need to face a lot of scrutiny first.

conorpp··on Show HN: A secure, open source U2F token you can make with $4.5 worth of parts
Thanks for the comments! I never thought of trying to do a reversible USB connection. And it's actually quite easy!

The button you point out looks like a better choice. It's about 10 cents cheaper than my current one. Currently sold out with 13 week lead time at Mouser! Must be popular.

conorpp··on Show HN: A secure, open source U2F token you can make with $4.5 worth of parts
The keys used for the picture are not used. But yes it is not a good practice to post pictures of door keys.
conorpp··on Show HN: A secure, open source U2F token you can make with $4.5 worth of parts
It's a good question. It's definitely not been through years of testing yet but in the past few months me and some friends have had no problems.

All of the parts have a low center of mass with respect to the PCB and are unlikely to catch on anything. Water and/or sweat won't hurt it as long as it's dry when you use it. I've tested it works fine after putting it through a washer and dryer.

However, making your own casing or 3D printing something like this [1] is always best

[1]: https://github.com/conorpp/u2f-zero/blob/master/hardware/cas...

conorpp··on Show HN: A secure, open source U2F token you can make with $4.5 worth of parts
As the ATECC508A is just an I2C peripheral you still have a broad choice for microcontrollers (as you still need a U2F program and U2F).

I choose to use a EFMUB1 from silicon labs.

conorpp··on Show HN: A secure, open source U2F token you can make with $4.5 worth of parts
Yes. There is [1] which is on Yubikey OTP specifically.

And on a lot more that focus on general embedded platforms running common cryptographic algorithms. U2F uses elliptic curve cryptography (ECC) internally -- check out this source for DPA on ECC [2].

[1] http://link.springer.com/chapter/10.1007/978-3-642-41284-4_1...

[2] http://saluc.engr.uconn.edu/refs/sidechannel/

conorpp··on Show HN: A secure, open source U2F token you can make with $4.5 worth of parts
No it is purely a hardware peripheral that just has configuration options.

http://www.atmel.com/Images/Atmel-8923S-CryptoAuth-ATECC508A...

conorpp··on How to accelerate a program using hardware
What would be the difference between writing to shared hardware pixels over a shared memory performance wise?

I mean, pixels are just like a memory except that they glow. They hold their value and can be writen a new value in sync with a clock (which is normally 60 Hz for most monitors which is MUCH slower then on chip memory). There could be no performance benefit.

conorpp··on Trying out Let's Encrypt (beta)
I used a Jekyll theme and have made incremental changes over the past few months to make it my own. You can see the source on my github account
conorpp··on Trying out Let's Encrypt (beta)
You can technically use TLS with anything. All the certificates give you is a trusted 3rd party that authenticates that a domain is what it claims to be. So if you want that authentication for your NAS domain name, then of course.
conorpp··on As sites move to SHA2 encryption, millions face HTTPS lock-out
No, it's not SHA2 encryption. SHA2 is a hashing function, meaning it's one way. Encryption is two way or else it wouldn't work. People often confuse the two but they are quite different.
conorpp··on A close look at an operating botnet
I was running the basic web server detailed in the post, but I didn't really have to do anything else. It's a public IP, notably a Digital Ocean IP. Internet scanners will pick it up.
conorpp··on Ask HN: Idea Sunday
Idea: A TENS Machine you can control with your phone

http://hackaday.com/2015/03/02/building-a-transcutaneous-ele...

TENS are currently kind of expensive and hard to use. People typically only use them when prescribed by a doctor and the devices are actually quite useful.

Many people get pain somehow or could use some sort of recreational relaxation, and a intuitive TENS machine for a smart phone could have a good market.

conorpp··on How I got featured on the AppStore
"How I got featured on the AppStore"

I was expecting an explaination.

conorpp··on We're going to send out invitations to YC interviews close to midnight
Fingers crossed
← PreviousPage 2 of 2