TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Solo – Open-source FIDO2 security key

174 pointsby fabiofedericialmost 7 years ago

16 comments

tptacekalmost 7 years ago
What processor parts will this be using?<p>A major benefit of the Yubikey U2F parts is that they&#x27;re almost indestructible. I&#x27;ve heard over and over again about how flimsy the Feitian parts are, and from people who have run over their Yubikeys with cars and still had them work. How resilient (in particular: waterproof) will these be?
评论 #17778685 未加载
评论 #17778594 未加载
评论 #17786378 未加载
评论 #17782750 未加载
评论 #17781450 未加载
评论 #17780216 未加载
Taniwhaalmost 7 years ago
I&#x27;ve spent some time building small open source USB devices, I went through a &quot;let&#x27;s just use the PCB to make the USB plug&quot; phase but frankly they&#x27;re not wonderfully reliable, I&#x27;m not a fan, and actual USB plugs are cheap and reliable (you do need to use one that has thru-hole lugs to be robust, not just surface mount which is an extra manufacturing step).<p>I just finished building my first USB-C (for standard USB) board board, it&#x27;s surprisingly easy, 2 extra resistors - pad tolerances are tight, but it&#x27;s not hard
angry_octetalmost 7 years ago
If you could manage to modify Signal so it&#x27;s keys were stored on the security key, and the user had to tap each time they log in, that would be far more valuable than GPG.
评论 #17779632 未加载
eeZah7Uxalmost 7 years ago
&gt; It protects against phishing<p>Not so much. U2F proves only that the user tapped the device when asked to do so.<p>You still have to trust your browser and your entire desktop that the tap will be used to log in to the service you are browsing instead of e.g. quietly logging to your home banking.<p>To prevent &quot;tap hijacking&quot; we need a display on the U2F key to show the URL&#x2F;service you are really authenticating to.
评论 #17782690 未加载
评论 #17782661 未加载
Kadinalmost 7 years ago
I wonder where are they going to manufacture it, and what control and visibility will they have into their supply chains, both upstream and downstream?<p>Absent some very serious issue with the crypto implementation, that would be my greatest concern -- how easy would it be for a state-level actor to introduce some sort of backdoor or other vulnerability (even a subtle one, e.g. modification to EM radiation pattern) to either all or just a select subset of devices, either into components &quot;upstream&quot; in the supply chain, in manufacturing itself, or downstream in transit to the retailer&#x2F;customer.
评论 #17782730 未加载
评论 #17780785 未加载
m-p-3almost 7 years ago
Is it U2F only or can it also do some of Yubikey stuff like storing GPG keys, etc?
评论 #17778495 未加载
评论 #17778514 未加载
armanini_ioalmost 7 years ago
See also the all in one OnlyKey - <a href="https:&#x2F;&#x2F;crp.to&#x2F;" rel="nofollow">https:&#x2F;&#x2F;crp.to&#x2F;</a>
advisedwangalmost 7 years ago
Solo describes itself as &quot;An upgrade to U2F Zero.&quot; What does it do better than U2F Zero?
评论 #17779353 未加载
评论 #17782688 未加载
confoundedalmost 7 years ago
Bit of a tangent, but out of interest, why KickStarter as opposed to CrowdSupply?
评论 #17783523 未加载
bubblethinkalmost 7 years ago
What&#x27;s nitrokey&#x27;s status regarding fido2 ? I know that their current open source products don&#x27;t support it, but they were planning to add it.
评论 #17801702 未加载
Freak_NLalmost 7 years ago
Does FIDO2 imply WebAuthn? How do the two relate to each other, other than WebAuthn being an &#x27;outgrowth of&#x27; FIDO2?
评论 #17781728 未加载
zxcvbn4038almost 7 years ago
Woohoo! My urge-zero key stopped working mysteriously and I wasn’t happy about that but I’ll give them another chance.
评论 #17782667 未加载
zaarnalmost 7 years ago
From the image it doesn&#x27;t look like it&#x27;ll be easily hand solderable. I love that about the U2F zero (though I&#x27;m still torn on if I should build it or buy it).
评论 #17782681 未加载
ohiovralmost 7 years ago
Any chance someone might make this work with Nextcloud?
评论 #17779928 未加载
评论 #17780940 未加载
ncmncmalmost 7 years ago
I think I like my tomu.im gadget better.<p>Just sayin&#x27;.
评论 #17781290 未加载
fibrahimalmost 7 years ago
Looks awesome, just one thing about the website if anybody knows them personally. The motto under the Product, &quot;Secure login, open, easy.&quot; is mostly hidden by the photo.
评论 #17779915 未加载