752 karma · joined September 10, 2013
[ my public key: https://keybase.io/conor1; my proof: https://keybase.io/conor1/sigs/wdyXzcj8bXBHa4Xz0Gu_Q7rhBOsKqHC_zqQtTDEj-ss ]
I think there's a lot of neat improvements you can make on 2FA products for different markets. But it's kind of at the point where if I wanted to continue working on a better 2FA token, I would have to get funding and do it full time. Although it's always tempting, I'm not sure I want to "cash out" of school and regular life just yet.
Also if I don't work in government I'd be in a lot of debt to pay back school. So that's an additional hurdle.
Without having the funds for injection/pressure molding, I haven't been able to find a good solution. Maybe there are cost effective services that would work like PCB potting or overmolding.
One service that I found that looks promising is Cavist:
But I haven't gone down this route or found someone that has. I might do this later on.
Yubico has a good explanation:
https://www.yubico.com/products/yubikey-hardware/fido-u2f-se...
It's the same as any other U2F token. You register it with a service that supports U2F (Google, Github, Duo, etc.) and then present the token and press the button upon logging in later.
No software or drivers needed. It's an HID device so all normal operating systems will support it.
FIDO U2F also has a $10k certification process to allow you to use the FIDO logo. I don't think it's worth pursuing for me.
Assembly depends on the service you end up using. For PCBCart, I think I just ended up filling out their template BOM manually. Not much of a hassle since I only have 8 parts. I just had to match the component references on the PCB to the BOM, count the number of pins, provide part number, etc. They figured everything else out, just a question or two on part polarities.
Yeah getting boards assembled for small volumes will likely not be cost effective. You can mess around with online quote tools to get an ideal if it'd be worth it or not. Using parts with pins that extend out from the package (rather than underneath) will always be more cost effective. Less pins is cheaper too.
It's hard to say that most mistakes are avoided from two audits. Especially in a browser; there's a lot of attack vectors.
Same idea -- strong crypto that's usable for anyone. It uses the OTR Ratchet protocol which uses perfect forward secrecy. The app also provides a way to verify keys through an OOB channel.
I would recommend considering OTR Ratchet integration just like WhatsApp did recently.
PGP is not a good design choice for a messaging app as you're always using asymmetric crypto operations which are computationally intense -- not terrible on modern computers but will be dreadful on mobile devices. Also can you provide some more documentation on how the app leverages PGP? Hopefully conversation is not using the same private keys to encrypt. That is vulnerable to data or side channel leakage. The modern approach is to generate and exchange an ephemeral key. Also please provide information on key storage.
Rather than making vague security claims like "first-rate" and " Security++ to the greatest extreme" you should rather provide a threat model and explain why one can remain confidential and have authenticity against particular types of adversaries. No security tool is perfect and it's only a matter of time before an adversary breaks it. Developers are doing a disservice by claiming anything more.
Before you can claim a first-rate security tool you will need to face a lot of scrutiny first.
The button you point out looks like a better choice. It's about 10 cents cheaper than my current one. Currently sold out with 13 week lead time at Mouser! Must be popular.
All of the parts have a low center of mass with respect to the PCB and are unlikely to catch on anything. Water and/or sweat won't hurt it as long as it's dry when you use it. I've tested it works fine after putting it through a washer and dryer.
However, making your own casing or 3D printing something like this [1] is always best
[1]: https://github.com/conorpp/u2f-zero/blob/master/hardware/cas...
I choose to use a EFMUB1 from silicon labs.
And on a lot more that focus on general embedded platforms running common cryptographic algorithms. U2F uses elliptic curve cryptography (ECC) internally -- check out this source for DPA on ECC [2].
[1] http://link.springer.com/chapter/10.1007/978-3-642-41284-4_1...
http://www.atmel.com/Images/Atmel-8923S-CryptoAuth-ATECC508A...
I mean, pixels are just like a memory except that they glow. They hold their value and can be writen a new value in sync with a clock (which is normally 60 Hz for most monitors which is MUCH slower then on chip memory). There could be no performance benefit.
http://hackaday.com/2015/03/02/building-a-transcutaneous-ele...
TENS are currently kind of expensive and hard to use. People typically only use them when prescribed by a doctor and the devices are actually quite useful.
Many people get pain somehow or could use some sort of recreational relaxation, and a intuitive TENS machine for a smart phone could have a good market.
I was expecting an explaination.