HNHacker News
TopNewBestAskShowJobs

snakeye

84 karma · joined February 9, 2020

[ my public key: https://keybase.io/snakeye; my proof: https://keybase.io/snakeye/sigs/zIv2-DiZ3oQeXSWBmk3Q43VqJBp0tyRZ7pb9z8EAjs8 ]
submissionscomments
snakeye··on Arduino FIDO2 Authenticator
Thank you! I will definitely take a look at your CTAP implementation!
snakeye··on Arduino FIDO2 Authenticator
Oh, in fact it's much simpler than MicroUSB. There is special type of USB Type C used for charging - https://en.ovcharov.me/uploads/2020/04/06/20200404_092055.jp...

It has only six huge pads and can be soldered either with hot air or normal soldering iron as a charm.

snakeye··on Arduino FIDO2 Authenticator
Nothing can stop us from making the same PCB but with USB Type C connector for charging.

Actually I'm using it in my other device according to the exactly same thoughts.

snakeye··on Arduino FIDO2 Authenticator
You are probably right. However, the BLE transport was not removed from the 2.1 specification and supported by Microsoft Hello. And, anyways, for Arduino based DIY project existing security is more than enough.
snakeye··on Arduino FIDO2 Authenticator
You can not extract private key from ATECC508A while it can be an issue with custom key storage built on Arduino. The chip itself costs around one dollar so why not?
snakeye··on Arduino FIDO2 Authenticator
It is encrypted with MITM protection. That's why I do not believe in severe security issues in BLE. There can be problems with particular implementations, but in general it should not be less secure that typing password on a keyboard.
snakeye··on Arduino FIDO2 Authenticator
From my experience - most people say "Arduino is ok" but struggle working with plain C.

As well keep in mind number of ready-made libraries for Arduino that can be reused here almost out of the box.

snakeye··on Arduino FIDO2 Authenticator
I'm using a bluetooth keyboard and I type my passwords in plain text. I don't think that public key sent over bluetooth is less secure. So it's a very tricky topic and I think it's more about corporate insterests that actual security.
snakeye··on Arduino FIDO2 Authenticator
Thank you! :)
snakeye··on Arduino FIDO2 Authenticator
This project is a spin-off from my wireless biometric authenticator. I was asked to make it open source many times.

Other than that - I've got one on my keyring as well. But buying one is not as fun as making :)

snakeye··on Arduino FIDO2 Authenticator
Yes, I have seen this recently. Google is so unsatisfied with BLE in FIDO2 so they removed support for it from the Chrome browser.
snakeye··on Arduino FIDO2 Authenticator
Oh, right, need some documentation there as well.

In general you can try the project with ESP32 development board and upload the firmware using `pio run -t upload -t monitor`

Then you need to pair the Bluetooth device. Afterwards you should be able to see connection requests in the serial monitor when you start authentication.

The actual authentication commands are not implemented yet, so it will not go further. Sorry :(

snakeye··on Arduino FIDO2 Authenticator
Thank you! I'm looking for a simple and convenient solution as well.
snakeye··on Arduino FIDO2 Authenticator
There is small UART biometric module https://www.digikey.com/products/en?keywords=2304-100018754-...

The biggest downside - it's more that 3 times more expensive than the device I have now.

snakeye··on URU Key – ESP32 FIDO2 Authenticator with Biometrics
I have a small hobby project - FIDO2 Authenticator built on ESP32 chip. For cryptography, I'm using ATECC508A co-processor. I want to use biometric authentication so I connected fingerprint scanner.

So far the device can be used both for user registration and authentication. However, fingerprint recognition is not implemented yet.