TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OnlyKey: Open-Source Alternative to YubiKey

448 pointsby mconeover 5 years ago

29 comments

dehugewe1209over 5 years ago
Security keys are the heart of security and we desperately need open-source solutions on this. Kudos for doing it.<p>Now, I must point out a few things:<p>1. Please don&#x27;t call your solution &quot;Open-source&quot;, when you do not have not even the schematics uploaded to github.<p>2. (this item is an open problem without a solution yet) how do I make sure the source code and the (still missing) hardware information actually corresponds to the hardware I&#x27;m buying?<p>If we do take item 2 seriously, one may say that buying Yubico is actually &quot;safer&quot; than your open-source solution, mainly due to company reputation and credibility.<p>Again, sorry the harsh words, but I take my keys seriously.
评论 #21885017 未加载
评论 #21888210 未加载
评论 #21886030 未加载
评论 #21884633 未加载
评论 #21884974 未加载
评论 #21884813 未加载
cr7pt0over 5 years ago
Thanks for all of the interest in OnlyKey! Full disclosure, I work for CryptoTrust and am on the team that makes OnlyKey. I wanted to try to address the questions&#x2F;concerns in this thread in one place and provide some useful links for more information. OnlyKey started from a successful kickstarter launch in 2016 and has grown to become a popular product for businesses and individuals.<p>- OPEN SOURCE - If you are looking for OnlyKey source you will find it here <a href="https:&#x2F;&#x2F;github.com&#x2F;trustcrypto" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;trustcrypto</a> all of our apps and firmware is open source. OnlyKey is not open hardware, however the hardware design is very transparent, literally. The device has a clear protective coating on the hardware which in addition to adding durability allows visually verifying everything.<p>- ABOUT SECURITY - Security documentation is here <a href="https:&#x2F;&#x2F;docs.crp.to&#x2F;security.html" rel="nofollow">https:&#x2F;&#x2F;docs.crp.to&#x2F;security.html</a> and provides information on how OnlyKey random number generator works, supply chain, side-channel attacks etc. One thing that you will notice about OnlyKey that differentiates it from other security keys is the on key PIN entry. While no device is immune to hacking, this feature mitigates many traditional threat models. We are always open to discussing specific threat models openly on our support forum.<p>- WHERE TO GO FOR MORE INFO Get started - <a href="https:&#x2F;&#x2F;onlykey.io&#x2F;start" rel="nofollow">https:&#x2F;&#x2F;onlykey.io&#x2F;start</a> General documentation - <a href="https:&#x2F;&#x2F;docs.crp.to&#x2F;" rel="nofollow">https:&#x2F;&#x2F;docs.crp.to&#x2F;</a> FAQs - <a href="https:&#x2F;&#x2F;docs.crp.to&#x2F;faq.html" rel="nofollow">https:&#x2F;&#x2F;docs.crp.to&#x2F;faq.html</a> Compare to Yubikey - <a href="https:&#x2F;&#x2F;crp.to&#x2F;p&#x2F;" rel="nofollow">https:&#x2F;&#x2F;crp.to&#x2F;p&#x2F;</a> Setup and User&#x27;s Guide - <a href="https:&#x2F;&#x2F;docs.crp.to&#x2F;usersguide.html" rel="nofollow">https:&#x2F;&#x2F;docs.crp.to&#x2F;usersguide.html</a> Features - <a href="https:&#x2F;&#x2F;docs.crp.to&#x2F;features.html" rel="nofollow">https:&#x2F;&#x2F;docs.crp.to&#x2F;features.html</a> Support - <a href="https:&#x2F;&#x2F;forum.onlykey.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;forum.onlykey.io&#x2F;</a> List of supported services - <a href="https:&#x2F;&#x2F;onlykey.io&#x2F;pages&#x2F;works-with-onlykey" rel="nofollow">https:&#x2F;&#x2F;onlykey.io&#x2F;pages&#x2F;works-with-onlykey</a>
评论 #21885846 未加载
ComodoHackerover 5 years ago
Setting aside problems with this particular device, the whole &quot;trust the open-source hardware&quot; model is inherently flawed. Every useful security hardware will be commoditized, then faked and&#x2F;or trojaned. We can&#x27;t take the open-source software approach and rely on many volunteer eyes catching vulnerabilities and backdoors. First, there just aren&#x27;t enough skilled professionals capable of proper hardware review. And second, how can you be sure the device in your hand strictly meets its specs? there&#x27;s no such things as digital signatures and reproducible builds for hardware. Vendor reputation is all we have for now.<p>Can we do something about this?
评论 #21889897 未加载
评论 #21886880 未加载
funkasterover 5 years ago
I really like the concept. I bought 4 of them a while ago (maybe a couple of years?) mostly to support them. I used one onlykey as my daily driver, I tried to integrate it with pass (my password manager at that time) without much luck. The software itself was very rough, the key was not meant to be used in your keychain: clear signs of usage after about a month, the usb port started to &quot;fade&quot;, it was hard to use the touch buttons, it factory resetted at some point (out of nowhere). Overall: I&#x27;m going to keep an eye, try them again in the future, but I fee the product needs one or two more iterations before I can depend on them as my daily security driver. Oh, and LED lights stopped working after a few weeks.<p>one huge disadvantage (which is the same for yubikey) is that I use programmers dvorak as my keyboard layout: had to change it every time to English to input the passwords&#x2F;token.
评论 #21884317 未加载
评论 #21887992 未加载
devinlover 5 years ago
This seems to predate FIDO2. <a href="https:&#x2F;&#x2F;solokeys.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;solokeys.com&#x2F;</a> would be a better option if you prefer separate keys for each site (via FIDO2) and open source hardware.
评论 #21884586 未加载
评论 #21884444 未加载
评论 #21884968 未加载
评论 #21890772 未加载
评论 #21891209 未加载
jandeboevrieover 5 years ago
The only true open hardware and open source key is the Nitrokey Start, running Gnuk firmware. Other nitrokeys are open hardware but run a smartcard (hsm or pgpcard) and those firmwares are not fully open. Yubikey is closed source and this posts bugger is closed as well. Go for a Nitrokey if you value true openness.
评论 #21885379 未加载
评论 #21890141 未加载
young_bloodover 5 years ago
I&#x27;ve owned and used an OnlyKey for around a year and a half now and have had a really positive experience using mine. There is one issue, unfortunately the LED lights do not work when the key is plugged into a USB 3 port. The key itself works, but you do not get any LED feedback which can make unlocking and using it a little difficult. Be sure to keep this in mind if you&#x27;re thinking about purchasing one.
评论 #21891352 未加载
评论 #21888464 未加载
abetuskover 5 years ago
Are the schematic files and PCB&#x2F;Gerber files available? I understand that they only claim to be Open-Source and not Open Source Hardware but it would still be nice to see and have the hardware schematics.
评论 #21890780 未加载
randallover 5 years ago
In concept I like it, but one of the biggest yubikey advantages is how unobtrusive it is. I realize the tradeoff they&#x27;re going for: Absolute security in the event that it&#x27;s stolen... but I think that&#x27;s actually bad for me since I&#x27;d rather have a tiny button to press as a second factor, than absolute security with a big dongle.<p>It&#x27;d be great if they just released a direct yubikey style clone.
评论 #21889303 未加载
qertoipover 5 years ago
Trezor T is vastly superior solution for U2F &#x2F; WebAuthn and also fully open source. The main advantage is super mature backup (Shamir&#x27;s secret sharing) and PIN-locking with exponential escape. Being a Bitcoin hardware wallet, security is very well tested.
评论 #21885900 未加载
评论 #21889384 未加载
sedatkover 5 years ago
Solo was the first open source alternative to YubiKey. I&#x27;m using one of their products and have been happy with it so far: <a href="https:&#x2F;&#x2F;solokeys.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;solokeys.com&#x2F;</a>
评论 #21916287 未加载
评论 #21889319 未加载
grogenautover 5 years ago
I couldn&#x27;t find any open source links on the site (reading from phone), is it open hardware or open config app&#x2F;firmware?
评论 #21884286 未加载
评论 #21884277 未加载
imtringuedover 5 years ago
I honestly don&#x27;t understand how a YubiKey is supposed to help me secure my accounts if I get locked out of my accounts when I lose it. I an trivially copy a keepass database anywhere and have dozens of backups. If I want to do the same with a YubiKey I first have to buy multiple YubiKeys and then I have to register each one on each site. This means they cannot be used as a primary authentication method because they always require a fallback option in case you want to reset your credentials because you lost your YubiKey. If I can&#x27;t use the YubiKey to secure my E-Mail account then what&#x27;s the point? I&#x27;ll still need to use password based login and store that E-Mail password in a conventional password manager that I then backup a dozen times.<p>YubiKeys only seem to make sense in a corporate environment where you can always request a new YubiKey and reregister it based on your ID.
评论 #21887176 未加载
评论 #21886186 未加载
评论 #21886233 未加载
评论 #21890052 未加载
评论 #21886293 未加载
评论 #21886461 未加载
评论 #21886493 未加载
评论 #21887007 未加载
blintzingover 5 years ago
If the device doesn&#x27;t have a secure element, how can anyone take it seriously as a strong root of trust? The page lists several recent attacks on secure element, but that&#x27;s not really enough to convince me that no secure element is needed.
评论 #21889444 未加载
aexover 5 years ago
OnlyKey&#x27;s ability to type passwords differentiates it for my use cases.<p>I can use OnlyKey to type long BIOS, disc, user and root passwords without worrying about people around or security cameras.
评论 #21885509 未加载
评论 #21885560 未加载
dima_medvedevover 5 years ago
Bought two of those last March. Mostly positive experience so far.<p>Previous firmware didn&#x27;t restore U2F key from backup, but current one does. It also didn&#x27;t have any kind of lockdown, so I did it via UDEV rules, luckily current firmware has a lock button, which even sends &quot;Super-l&quot;.<p>I would also love onlykey-cli be ported to Python3.<p>Somebody mentioned here that onlykey isn&#x27;t fit for keychain use, yet mine is totally fine and USB port shows virtually no signs of wear.
lisperover 5 years ago
Another open source security key: <a href="https:&#x2F;&#x2F;sc4.us&#x2F;hsm" rel="nofollow">https:&#x2F;&#x2F;sc4.us&#x2F;hsm</a>
mikeceover 5 years ago
Can this device function as an SSD, holding, for example, a Keepass2Android APK file and a KeePass database -- as well as being able to open said datanbase via one of the stored profiles? It doesn&#x27;t need to have a lot of storage... 640 MB ought to be enough for anyone&#x27;s KeePass databases.
评论 #21884932 未加载
评论 #21885406 未加载
xaduhaover 5 years ago
This thing seems fishy to me. If you want something that is mostly under your control to which you can install open source stuff into then buy some smart cards and card readers e.g. from <a href="https:&#x2F;&#x2F;www.javacardsdk.com" rel="nofollow">https:&#x2F;&#x2F;www.javacardsdk.com</a>
评论 #21891228 未加载
nine_kover 5 years ago
Something way more solid apparently does exist: USB Armory.<p><a href="https:&#x2F;&#x2F;inversepath.com&#x2F;usbarmory.html" rel="nofollow">https:&#x2F;&#x2F;inversepath.com&#x2F;usbarmory.html</a><p>The hardware is open, the software is mentioned without much detail; I suppose it&#x27;s not shipping yet.
评论 #21889294 未加载
wfdctrlover 5 years ago
Why does the code look like a copy-pasted mess? Kudos for making it open, though...
评论 #21889403 未加载
Tomdarknessover 5 years ago
One thing I immediately noticed is that apparently it supports exporting full backups of the device? Surely this is a terrible idea? I&#x27;m far from a security expert but I&#x27;d have thought you&#x27;d want to make it so that it is extremely difficult to extract key material from a security key, not offer it as a feature?
评论 #21887398 未加载
guenthertover 5 years ago
I was interested until I saw the price tag: $46. Seriously, WTH?
评论 #21886301 未加载
annolirover 5 years ago
ykpass (<a href="https:&#x2F;&#x2F;github.com&#x2F;noliran&#x2F;ykpass" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;noliran&#x2F;ykpass</a>) takes another approach at this. It generates unique strong passwords for every website, which are fully restorable without needing constant backups, thus providing a solution for non-U2F websites, which is - honestly - most of the internet at the moment
foobarbazetcover 5 years ago
Unless you have a provable chain of trust that the code compiled is the code running on this thing then... Nah.<p>I trust Google’s Titan keys. <i>shrug</i>.
评论 #21913730 未加载
WhyNotHugoover 5 years ago
The price seems ridiculous though. $2700?! Exactly what kind of audience is this geared towards?
评论 #21888387 未加载
评论 #21888378 未加载
classics2over 5 years ago
Where are the cad files, bom and other data needed to manufacture the device?
woliveirajrover 5 years ago
&gt; &quot; promote us and earn&quot;<p>this doesn&#x27;t send a good message
ciesover 5 years ago
Open source is the only way to security in most cases.
评论 #21886229 未加载
评论 #21886086 未加载
评论 #21886432 未加载
评论 #21884800 未加载