[HN Gopher] A new open security key: Solo v2
___________________________________________________________________
A new open security key: Solo v2
Author : ecesena
Score : 15 points
Date : 2021-01-03 15:39 UTC (7 hours ago)
(HTM) web link (solokeys.com)
(TXT) w3m dump (solokeys.com)
| amluto wrote:
| I see it supports firmware updates, and I see nothing about
| whether it uses an actual hardened secure element chip. I'm not
| convinced I would trust this device.
|
| There's a reason Yubikeys can't be updated, and it's not to sell
| more Yubikeys.
| ecesena wrote:
| Yes to both.
|
| We do support firmware upgrade, unlike other security keys. For
| example in 2020 we patched a couple security issues, while
| Yubico, Google Titan and Feitian all recalled keys. Specs and
| thus firmware are getting bigger and more complex, so we
| believe that updates are the only way to maintain security in
| the long run.
|
| We do not use a secure element, unlike other keys. This is not
| a statement, it's just a fact. If you want an open product,
| there's no "secure element" available that doesn't require an
| nda. We hope that our work (we're not alone in this) will
| motivate manufacturer to release secure elements with less
| obscurity around them.
| bsder wrote:
| Define "trust". Or more appropriately "threat model".
|
| My biggest problem is not the _key_.
|
| My biggest problem is the fact that I can't easily roll keys
| out in a startup with 5 people and not become the customer
| service IT person handling security problems every day.
|
| Solve _THAT_ problem and I 'll pay a monthly fee for your
| service.
___________________________________________________________________
(page generated 2021-01-03 23:02 UTC)