752 karma · joined September 10, 2013
[ my public key: https://keybase.io/conor1; my proof: https://keybase.io/conor1/sigs/wdyXzcj8bXBHa4Xz0Gu_Q7rhBOsKqHC_zqQtTDEj-ss ]
- Sending money across borders.
- Decentralized exchanges that actually charge fair fees, unlike the centralized exchanges of today.
- Allowing more people to purchase goods online that previously had to no way to.
- Providing stable rates of return for your crypto based savings account (e.g. via staking).
- Lowering interest rates on loans by cutting out the middlemen.
TOTP and any sort of one time code authentication are just as phishable as passwords. Perhaps the biggest benefit for most people using U2F or FIDO2, is the large resistance to phishing.
This is because of how the whole ecosystem has adopted FIDO2. When a FIDO2 key signs an assertion for a website, it includes the domain in the signature base, e.g. "example.com". The browser enforces that the request to the FIDO2 key always uses the correct name of the domain you're on.
If you accidentally go to a fake website, "exaample.com", then the key will make a signature for "exaample.com", which is invalid for "example.com". Nothing can be phished to get around that, unlike OTP codes.
Even if you have other 2FA options linked to your account, as long as you're using your FIDO2 key, you gain this benefit. Very strong benefit for both individuals and enterprises.
The epoxy can be chemically dissolved, but would deteriorate the outside of the device as well. It the epoxy isn't completely cleaned out, then refilling it with new epoxy would look messy. With great care and skill, it could be done with little damage, but would be time consuming.
- More secure microcontroller supporting secure boot, PUF, flash encryption, etc.
- Firmware rewritten in rust.
- Much more robust and durable construction.
- Touch buttons, reversible USB-A, USB-C
NFC is passively operated similar to other authenticators and is more reliable.
ED255 is supported in V2!
I'm part of an open source based startup and we'd love to get some help with our web design.
We sell physical FIDO2/U2F security keys, for strong authentication on the web. Soon to replace passwords! All firmware and hardware is open source.
Would you be interested in helping out?
https://github.com/SoloKeysSec/solo/blob/master/targets/efm3...
https://github.com/SoloKeysSec/solo/blob/master/targets/efm3...
Like what others mention, it really depends on documentation from the vendor for the chipset you're working with. I mainly copied and pasted code from a form post by the vendor.
And of course link to the security key product :)
1. you can set the width of the jig to match your pogo pin spring "active region" easily.
2. You can make cutouts for the board and other features (USB-C + USB-C connectors in my case).
I admit, a Form 2 is an expensive perk. But there are much more affordable routes: https://dirtypcbs.com/store/print3d https://dirtypcbs.com/store/lasercut
I.e. when you order PCBs, you can order a $5 SLA jig :)
Maybe one "affordable" idea could be to stack 2 two-layer PCBs XD.
Right now it'd be a bit tough, because to fit our chipset [1] in that tight space, it would likely involve making a custom IC package [2] or placing silicon die's directly on the circuit. I think it'd be really cool to do that, and if we get enough sales/interesting, we'll definitely go that route.
Using something like the Tomu seems promising as well. It doesn't have the same security features and is just an M0 core, so it's not the best fit.
[1] https://i.imgur.com/sVQ34em.pnghttps://i.imgur.com/sVQ34em.p...
Our code is designed to be small and portable, so I think it could easily be run on the Tomu. Just need some work to change the USB drivers stuff.
After considering many MCUs with USB interfaces, it seems to always be more cost effective to get the non-USB MCU and use the EFM8UB1 (from a BOM perspective anyways). The lesser chance of having a backdoor is a plus!
Here's our schematic: https://i.imgur.com/sVQ34em.pnghttps://i.imgur.com/sVQ34em.p...
Still have to document this better on Github :)
I'm not sure of any methods to bypass the read protection on normal MCUs in a 10s "drive by" attack. AFAIK, the special companies that provide flash readout (http://www.break-ic.com/), do so by decapping the chip and using involved imaging techniques. I suspect they get good at identifying various flash technologies, many of which are common to many chips. But don't think it's feasible for a drive by.
The I2C eavesdropping shouldn't be an issue because the ATECC508A does apply a mask.
http://ww1.microchip.com/downloads/en/DeviceDoc/20005927A.pd...
https://www.amazon.com/gp/product/B01L9DUPK6 https://conorpp.com/designing-and-producing-2fa-tokens-to-se...
Brings in around $500-$1000 per month of revenue (when in stock haha). I started just to learn how to lay out a circuit board and make my own embedded device, just kind of took off.
Using the U2F protocol is nice, since it's a standard and the PC side infrastructure is all there for the users to use it. I just have to do the hardware development :)
Also, I'm working on a new U2F token. It supports FIDO2 (password replacement protocol, upgrade to U2F), NFC, USB-C, and will have a nice case. If you're interested, sign up here, we'll be releasing more news soon :)
Given this, I think having a 1 chip solution really simplifies the design and allows more flexibility.
Right now, we plan to do the programming ourselves to at least verify that goes okay. Since we are bootstrapping, we are outsourcing the PCB-A, but hopefully since this is pretty expensive threat for an adversary to invest in, I don't think it would be an issue unless we show to have a large market. By then, we can move more supply chain in house :)
Also planning to have case, USB-C option, NFC option
I'm thinking about making a short video showing how to solder one reliably for folks interesting in making their own. Unfortunately newer MCUs these days often don't come in easy-to-solder packages.