19 ms·
OnlyKey: Open-Source Alternative to YubiKey
- foobarbazetc 7y agoUnless you have a provable chain of trust that the code compiled is the code running on this thing then... Nah. I trust Google’s Titan keys. shrug.
- 0x0359463 7y agoSo Google Titan keys have a pretty bad track record when it comes to security: https://www.engadget.com/2019/05/15/google-recalls-some-titan-bluetooth-security-keys/ https://www.engadget.com/2019/05/15/google-recalls-some-tita... It's not possible to have a provable chain of trust on hardware as others have mentioned in the thread, even in the device you mentioned there is no proof that the code the manufacturer intended to run on device is the same code running on the device. Also its closed source so you wouldn't even know what code they intended to run. In fact with Google Titan you have lots of other issues like that it's actually just a rebranded Feitian key, a China based company with unknown supply chain or possibly even China govt mandated backdoor. More on that here https://www.securitynewspaper.com/2018/09/06/experts-ask-google-for-clarifications-about-backdoor-in-titan-security-key/ https://www.securitynewspaper.com/2018/09/06/experts-ask-goo... You can check out the hardware of your key here, there is no tamperproofing at all. http://hexview.com/~scl/titan/ http://hexview.com/~scl/titan/
- grogenaut 7y agoI couldn't find any open source links on the site (reading from phone), is it open hardware or open config app/firmware?
- thenewnewguy 7y agoThe desktop site has a link to https://github.com/trustcrypto https://github.com/trustcrypto in the footer.
- g_p 7y agoThere is a link to https://github.com/trustcrypto https://github.com/trustcrypto from within what seems to be the footer of (at least) the FAQ page.
- djsumdog 7y agoHuh. So they have the firmware up, and a forked project that gets FIDO2 working on an Audrino .. I don't see and CAD files or any repos that seem to contain circuit diagrams. Is the hardware something standard they load firmware on, or is only he firmware open and the hardware designs closed?
- g_p 7y agoLooks it. Seems like it might be open firmware and user-space interfacing software. Didn't see any CAD/EDA repos.
- young_blood 7y agoI've owned and used an OnlyKey for around a year and a half now and have had a really positive experience using mine. There is one issue, unfortunately the LED lights do not work when the key is plugged into a USB 3 port. The key itself works, but you do not get any LED feedback which can make unlocking and using it a little difficult. Be sure to keep this in mind if you're thinking about purchasing one.
- sedatk 7y agoWhy does it have LEDs if they don't work?
- cr7pt0 7y agoSorry to hear that you had issues with the LED. We did receive reports of some user's having issue with LEDs on some computers years back. With the latest OnlyKey hardware there have been no issues reported, you can check out the reviews on Amazon as if there is any issue at all there will usually be negative reviews on Amazon - https://www.amazon.com/OnlyKey-Stealth-Black-Case-Communication/dp/B06Y1CSRZX https://www.amazon.com/OnlyKey-Stealth-Black-Case-Communicat...
- funkaster 7y agoI really like the concept. I bought 4 of them a while ago (maybe a couple of years?) mostly to support them. I used one onlykey as my daily driver, I tried to integrate it with pass (my password manager at that time) without much luck. The software itself was very rough, the key was not meant to be used in your keychain: clear signs of usage after about a month, the usb port started to "fade", it was hard to use the touch buttons, it factory resetted at some point (out of nowhere). Overall: I'm going to keep an eye, try them again in the future, but I fee the product needs one or two more iterations before I can depend on them as my daily security driver. Oh, and LED lights stopped working after a few weeks. one huge disadvantage (which is the same for yubikey) is that I use programmers dvorak as my keyboard layout: had to change it every time to English to input the passwords/token.
- young_blood 7y agoThere's currently an issue (and an open PR) in to add dvorak support, though, I'm not sure if/when it'll be merged. https://github.com/trustcrypto/OnlyKey-Firmware/issues/85 https://github.com/trustcrypto/OnlyKey-Firmware/issues/85
- Tharkun 7y agoThere are many, many keyboard layouts out there. Maybe it's time for an input standard that acknowledges this fact, instead of endlessly putting the onus on OS developers and users. Maybe keyboards should output UTF8 instead of messy keycodes.
- samatman 7y agoThis would require new hardware. If one is already going to be purchasing new hardware, one may as well get a QMK keyboard. This way you can program it with any keyboard layout you would like, and it will work on any computer without having to change the system defaults. Clearly this doesn't help with built-in keyboards such as found on laptops; the clear workaround for this specific product is to allow it to import keyboard layouts in the various OS-specific forms they exist in.
- randall 7y agoIn concept I like it, but one of the biggest yubikey advantages is how unobtrusive it is. I realize the tradeoff they're going for: Absolute security in the event that it's stolen... but I think that's actually bad for me since I'd rather have a tiny button to press as a second factor, than absolute security with a big dongle. It'd be great if they just released a direct yubikey style clone.
- cr7pt0 7y agoThis is the plan, an OnlyKey pro and a small form factor key similar to the Yubikey nano is in development.
- cies 7y agoOpen source is the only way to security in most cases.
- Whatarethese 7y agoIf its auditable by anyone.
- samatman 7y agoFor one meaning of 'auditable by anyone', this is definitional for open-source systems. Perhaps you mean 'if there's anyone with the domain-specific knowledge to audit the software successfully', well, the first kind of audit should determine that. If there isn't anyone who can evaluate the security claims, that's a pretty strong signal not to use it, no?
- reaLg_move_in_3 7y agoSadly much of the implementation is still missing to be audited, things like schematics and hardware design need to be more robust before we can really call this open source hardware.
- imtringued 7y agoMost of the security benefits come from giving the vendor an incentive to update their software quickly. I've often seen proprietary companies delay security critical patches until the next release or sue well meaning people who are reporting vulnerabilities (to the companies) as hackers to hide evidence of vulnerabilities. There is a reason why so many vulnerabilities are found and reported in Linux compared to e.g. Windows. There is no censorship that tries to make the world look prettier than it is.
- cies 7y agoEveryone who cared to comment seems to agree that open source is a prerequisite for proper security in software. Interestingly I got down voted :) Good point that the security of FLOSS stems from the culture surrounding FLOSS...
- abetusk 7y agoAre the schematic files and PCB/Gerber files available? I understand that they only claim to be Open-Source and not Open Source Hardware but it would still be nice to see and have the hardware schematics.
- stuntkite 7y agoNo. There isn't because it's not actually open source and this is bullshit.
- devinl 7y agoThis seems to predate FIDO2. https://solokeys.com/ https://solokeys.com/ would be a better option if you prefer separate keys for each site (via FIDO2) and open source hardware.
- captn3m0 7y agoSoloKey doesn't support everything this does. It is primarily a U2F key, and OpenPGP support is still WIP[0] [0]: https://github.com/solokeys/openpgp https://github.com/solokeys/openpgp
- prophesi 7y agoYeah, I've been happy with my SoloKey, but OnlyKey's integration with a software password manager + OpenPGP + SSH keys is really enticing. I'm on the same boat as a lot of others here, however, that the lack of open hardware is a deal breaker.
- cr7pt0 7y agoJust wondering, what additional security would you expect from open hardware vs. open software with transparently designed hardware? From a threat modeling perspective it seems that if the device is just using one chip onboard there are no clear security advantages of open hardware. Open hardware would only be provide a security benefit if you are planning to make your own security key, which most people won't be doing. And by being open hardware there is an additional threat model created where it is now easy for adversary to create identical clones of security key that can be used maliciously.
- prophesi 7y agoUltimately, it's just a personal belief that all knowledge should be free as in freedom. SoloKey Hacker Edition in particular lets you run custom firmware, so you can at least be confident in the software side of things, and build upon it. Open hardware has the benefit of being able to build it yourself, which is the only completely secure option. The downside is, indeed, the ability to easily create malicious clones, and the fact that you simply won't be able to build it yourself for any remotely modern hardware. So yeah, there's really no security benefit to it in terms of hardware. Proprietary hardware has the upside of needing reverse-engineering to create a malicious clone / part, and the transparent design helps you make sure that they can't do a sloppy job at it. It's a shame that tradeoffs have to be made once technology reaches a certain level of complexity, but alas.
- klhugo 7y agoSecurity keys are the heart of security and we desperately need open-source solutions on this. Kudos for doing it. Now, I must point out a few things: 1. Please don't call your solution "Open-source", when you do not have not even the schematics uploaded to github. 2. (this item is an open problem without a solution yet) how do I make sure the source code and the (still missing) hardware information actually corresponds to the hardware I'm buying? If we do take item 2 seriously, one may say that buying Yubico is actually "safer" than your open-source solution, mainly due to company reputation and credibility. Again, sorry the harsh words, but I take my keys seriously.
- cr7pt0 7y agoIt is open source, not to be confused with open hardware which it is not. The hardware is transparent, literally, it has a clear protective coating on the hardware which allows visually verifying everything. For security things check out https://docs.crp.to/security.html https://docs.crp.to/security.html - TL;DR Before you enter the PIN its not doing any crypto which means lots of side-channel attacks don't apply, you would have to know the PIN to even attempt many types of side-channel attacks.
- random3 7y agoWhen you say open-source it's rather general. I.e. not open-source software or hardware, so it does imply it's open-source both (e.g. https://en.wikipedia.org/wiki/Open-source_hardware https://en.wikipedia.org/wiki/Open-source_hardware not "open hardware")
- delfinom 7y ago> The hardware is transparent, literally, it has a clear protective coating on the hardware which allows visually verifying everything Right and that's bullshit. How do I know you aren't embedding a advanced joule thiefing silicon die disguised as a pull-up resistor to manipulate usb communication or even interface with the micro in a backdoor?
- stinos 7y ago
- aex 7y agoOnlyKey's ability to type passwords differentiates it for my use cases. I can use OnlyKey to type long BIOS, disc, user and root passwords without worrying about people around or security cameras.
- contactlight11 7y agoYubiKey can also do this: https://www.engineerbetter.com/blog/yubikey-static-secret/ https://www.engineerbetter.com/blog/yubikey-static-secret/
- cr7pt0 7y agoIt can only store up to 2 passwords, OnlyKey stores 24. For full comparison see https://crp.to/p https://crp.to/p
- andoriyu 7y agoYubiKey does it too. I use it to unlock GELI.
- mikece 7y agoCan this device function as an SSD, holding, for example, a Keepass2Android APK file and a KeePass database -- as well as being able to open said datanbase via one of the stored profiles? It doesn't need to have a lot of storage... 640 MB ought to be enough for anyone's KeePass databases.
- cr7pt0 7y agoNo it doesn't store files directly, but if you are looking for KeePass support it is now supported directly by KeePassXC - https://keepassxc.org/blog/2019-10-26-2.5.0-released/ https://keepassxc.org/blog/2019-10-26-2.5.0-released/
- mikece 7y agoI use KeePassXC on macOS, Windows, and Linux and copying the database to the machines in question is easy enough. I was specifically thinking for iOS and Android without going through iCloud.
- h4waii 7y agoThis [0] may or may not be of interest to you. 0. https://github.com/whs/K2AUSBKeyboard https://github.com/whs/K2AUSBKeyboard
- jandeboevrie 7y agoThe only true open hardware and open source key is the Nitrokey Start, running Gnuk firmware. Other nitrokeys are open hardware but run a smartcard (hsm or pgpcard) and those firmwares are not fully open. Yubikey is closed source and this posts bugger is closed as well. Go for a Nitrokey if you value true openness.
- omgbear 7y agoI've had a great experience with my NitroKey Starts. I'm just bummed that opensc doesn't yet support ed25519 since it seems gnuk does.
- cr7pt0 7y agoFYI OnlyKey already supports ed25519 with their SSH agent https://docs.crp.to/onlykey-agent.html#supported-curves https://docs.crp.to/onlykey-agent.html#supported-curves
- danieldk 7y agoI am not sure I follow? I have been using NitroKey Starts with ed25519 and GnuPG for two years without problems? The NitroKey Start is great! I have switched to YubiKeys, since they are more durable and also support U2F/Fido2 and PIV on the same token. But NitroKey's software being open source and upgradable are great features. Note that gnuk also works on Blue Pills. So, if a NitroKey is too expensive for you, you can pick up a couple of Blue Pills for a few dollars and flash gnuk on them. [1] [1] https://blog.dan.drown.org/gnuk-open-source-gpg-ssh-hardware-key-storage/ https://blog.dan.drown.org/gnuk-open-source-gpg-ssh-hardware...
- stinos 7y agoIt's indeed rather 'open'.. https://old.reddit.com/r/crypto/comments/bis3pf/extract_pgp_secret_keys_from_gnuk_nitrokey_start/ https://old.reddit.com/r/crypto/comments/bis3pf/extract_pgp_... Kidding aside: I'm sure there are many more prodcuts having problems like this. Just goes to show there's no such thing as 100% secure I guess. At least this is open so can be fixed with some effort.
- cr7pt0 7y agoThanks for all of the interest in OnlyKey! Full disclosure, I work for CryptoTrust and am on the team that makes OnlyKey. I wanted to try to address the questions/concerns in this thread in one place and provide some useful links for more information. OnlyKey started from a successful kickstarter launch in 2016 and has grown to become a popular product for businesses and individuals. - OPEN SOURCE - If you are looking for OnlyKey source you will find it here https://github.com/trustcrypto https://github.com/trustcrypto all of our apps and firmware is open source. OnlyKey is not open hardware, however the hardware design is very transparent, literally. The device has a clear protective coating on the hardware which in addition to adding durability allows visually verifying everything. - ABOUT SECURITY - Security documentation is here https://docs.crp.to/security.html https://docs.crp.to/security.html and provides information on how OnlyKey random number generator works, supply chain, side-channel attacks etc. One thing that you will notice about OnlyKey that differentiates it from other security keys is the on key PIN entry. While no device is immune to hacking, this feature mitigates many traditional threat models. We are always open to discussing specific threat models openly on our support forum. - WHERE TO GO FOR MORE INFO Get started - https://onlykey.io/start https://onlykey.io/start General documentation - https://docs.crp.to/ https://docs.crp.to/ FAQs - https://docs.crp.to/faq.html https://docs.crp.to/faq.html Compare to Yubikey - https://crp.to/p/ https://crp.to/p/ Setup and User's Guide - https://docs.crp.to/usersguide.html https://docs.crp.to/usersguide.html Features - https://docs.crp.to/features.html https://docs.crp.to/features.html Support - https://forum.onlykey.io/ https://forum.onlykey.io/ List of supported services - https://onlykey.io/pages/works-with-onlykey https://onlykey.io/pages/works-with-onlykey
- bpfrh 7y agoAny chance that key can be used for windows login? I'm searching for a key that also works as a smartcard for winows on prem active directory authentication, as well as FIDO2 support. Or a key that has software which allows this. edit: changes should be chance
- xaduha 7y agoFeitian advertises one here https://www.ftsafe.com/Products/FIDO/NFC https://www.ftsafe.com/Products/FIDO/NFC and they say you can request a dev version so you can install your own applets, but I can't vouch for it yet personally.
- dima_medvedev 7y agoBought two of those last March. Mostly positive experience so far. Previous firmware didn't restore U2F key from backup, but current one does. It also didn't have any kind of lockdown, so I did it via UDEV rules, luckily current firmware has a lock button, which even sends "Super-l". I would also love onlykey-cli be ported to Python3. Somebody mentioned here that onlykey isn't fit for keychain use, yet mine is totally fine and USB port shows virtually no signs of wear.
- qertoip 7y agoTrezor T is vastly superior solution for U2F / WebAuthn and also fully open source. The main advantage is super mature backup (Shamir's secret sharing) and PIN-locking with exponential escape. Being a Bitcoin hardware wallet, security is very well tested.
- groby_b 7y ago> Being a Bitcoin hardware wallet, security is very well tested Given the history of the cryptocurrency field, A is very far from implying B. And there's at the very least the Ledger analysis[1], which reveals several vulnerabilities. (The core issue for me is the order->backdoor->return issue - it doesn't seem there's a way to verify integrity of device or supply chain) [1] https://www.ledger.com/our-shared-security-responsibly-disclosing-competitor-vulnerabilities/ https://www.ledger.com/our-shared-security-responsibly-discl...
- qertoip 7y agoGiven the history of reputable Bitcoin hardware wallets, A actually does imply B. Hardware wallets are the only viable way to store cryptocurrency securely, with great track record since inception in 2014. Regarding the supply chain, there is very little that can be done, and yubikey-like solutions certainly do not excel here. Trezor T at least comes with no firmware (to be installed by the user) and holographic sticker. Basic, but better than Yubikey et al.
- cr7pt0 7y agoIt's interesting that Trezor and Solo are mentioned here. We specifically with OnlyKey decided not to go with an STM chip like the ones used in these devices due to the vulnerability that affects these devices described here -https://medium.com/@Zero404Cool/trezor-security-glitches-reveal-your-private-keys-761eeab03ff8 https://medium.com/@Zero404Cool/trezor-security-glitches-rev...
- guenthert 7y agoI was interested until I saw the price tag: $46. Seriously, WTH?
- fierarul 7y agoSeems reasonable. The cheap YubiKey is $20 (over $30 with tax and shipping) while the series 5 YubiKey is $50-$70. And I assume Yubico is capable of making much bigger (aka cheaper per unit) orders.
- blintzing 7y agoIf the device doesn't have a secure element, how can anyone take it seriously as a strong root of trust? The page lists several recent attacks on secure element, but that's not really enough to convince me that no secure element is needed.
- cr7pt0 7y agoThis is an interesting question. I would like to see more discussion like this in the security community. Of course this question should be proceeded by the question of what actually qualifies as a secure element? Who decides it's secure? If it's just an MCU with some basic security features you have to sign an N DA to even test is that a secure element? Is it possible to create an open source secure element without an NDA required?
- imtringued 7y agoI honestly don't understand how a YubiKey is supposed to help me secure my accounts if I get locked out of my accounts when I lose it. I an trivially copy a keepass database anywhere and have dozens of backups. If I want to do the same with a YubiKey I first have to buy multiple YubiKeys and then I have to register each one on each site. This means they cannot be used as a primary authentication method because they always require a fallback option in case you want to reset your credentials because you lost your YubiKey. If I can't use the YubiKey to secure my E-Mail account then what's the point? I'll still need to use password based login and store that E-Mail password in a conventional password manager that I then backup a dozen times. YubiKeys only seem to make sense in a corporate environment where you can always request a new YubiKey and reregister it based on your ID.
- cal5k 7y agoA lot of services, like GSuite and LastPass, allow you to register multiple hardware keys. The best bet is to register several of them with these sites, then put one or two offsite (e.g. in a safety deposit box) just in case. Then, use GSuite to sign into other services (like Slack) wherever supported to minimize how often you need to do this.
- idlewords 7y agoUse TOTP (like Google Authenticator) as a backup method as well. It's helpful for scenarios like having to log in on a phone.
- 91iejrj20310 7y agoIs Google Authenticator tied to your smartphone, to your account, or a combination of both? Can you transfer it to another smartphone? Is it being backupped automatically? We're amongst a very technologically educated part of the population here, and honestly, I'm not sure about the scope of Google Authenticator. Quite sure that many aren't.
- 7y ago
- wfdctrl 7y agoWhy does the code look like a copy-pasted mess? Kudos for making it open, though...
- cr7pt0 7y agoThanks I guess... We always review PRs
- ComodoHacker 7y agoSetting aside problems with this particular device, the whole "trust the open-source hardware" model is inherently flawed. Every useful security hardware will be commoditized, then faked and/or trojaned. We can't take the open-source software approach and rely on many volunteer eyes catching vulnerabilities and backdoors. First, there just aren't enough skilled professionals capable of proper hardware review. And second, how can you be sure the device in your hand strictly meets its specs? there's no such things as digital signatures and reproducible builds for hardware. Vendor reputation is all we have for now. Can we do something about this?
- scumbert 7y agoTo do something about this requires supply chain security that you won't find outside governments that are able to realize economies of scale.
- abdullahkhalids 7y agoIf someone sells you a quantum computer, there exists protocols that allow you to check if the QC is working as intended without inspecting the internals [1]. You merely have to pass some special (randomized) inputs and check the outputs. Does anybody know what sort of verification protocols exist for classical security devices, where you can verify that the device is working as intended without inspecting the hardware? [1] https://arxiv.org/abs/1911.08101 https://arxiv.org/abs/1911.08101
- arthurwilliams 7y agoPlaya Del Carmen real estate listings by BuyPlaya Realty Advisors-- your one-stop location for finding incredible beachfront properties in the Riviera Maya. We are a family-owned and operated company with more than 13 years experience in this Mexico realty sector. Our specialty is providing professional and expert brokerage services to both investors and getaway property buyers from Canada, the United States, the United Kingdom and worldwide. We are dedicated to helping with the trading of exclusive properties in Playa del Carmen and the Riviera Maya area in Mexico that will never be advertised anywhere except online. Delivering an unmatched level of professionalism and customer service is our supreme goal. Visit https://www.buyplaya.com https://www.buyplaya.com
- lisper 7y agoAnother open source security key: https://sc4.us/hsm https://sc4.us/hsm
- Tomdarkness 7y agoOne thing I immediately noticed is that apparently it supports exporting full backups of the device? Surely this is a terrible idea? I'm far from a security expert but I'd have thought you'd want to make it so that it is extremely difficult to extract key material from a security key, not offer it as a feature?
- rodgolpe 7y agoThe backups are automatically encrypted with a private key you save onto the device (obviously the key is not part of the backup). To restore a backup onto the same device or a new OnlyKey, you first have to load the same private key that encrypted your backup.
- xaduha 7y agoThis thing seems fishy to me. If you want something that is mostly under your control to which you can install open source stuff into then buy some smart cards and card readers e.g. from https://www.javacardsdk.com https://www.javacardsdk.com
- cr7pt0 7y agoCarrying your own smart cards and smart card reader may work for some use cases but I'm sure you can see why a small key attached to your key chain is a better solution in most cases.
- xaduha 7y agoThere are readers the size of a thumb drive, cards themselves are the standard credit card size or even SIM card size if not contactless. It's not the real issue here, there are a few more important ones such as lack of desktop browser support for U2F NFC use case. U2F applet works fine for me on Android though.
- WhyNotHugo 7y agoThe price seems ridiculous though. $2700?! Exactly what kind of audience is this geared towards?
- cryptobeard 7y agoWhere did you get $2700, OnlyKey is $46 USD
- cambalache 7y agoThe prices are localized. So $2700...ARS
- cambalache 7y agoLet me guess, you are Argentinian, jajajaja.
- annolir 7y agoykpass (https://github.com/noliran/ykpass https://github.com/noliran/ykpass) takes another approach at this. It generates unique strong passwords for every website, which are fully restorable without needing constant backups, thus providing a solution for non-U2F websites, which is - honestly - most of the internet at the moment
- classics2 7y agoWhere are the cad files, bom and other data needed to manufacture the device?
- sedatk 7y agoSolo was the first open source alternative to YubiKey. I'm using one of their products and have been happy with it so far: https://solokeys.com/ https://solokeys.com/
- 0x0359463 7y agoFYI, this is fake news OnlyKey has been around since 2016 and has been open source the whole time. Solo was launched in 2018 and claimed to be the first FIDO2 open source security key, this was only true because at the time OnlyKey wasn't FIDO2. OnlyKey was the first open source security key. Also Solo isn't even a viable alternative to YubiKey as it doesn't support challenge-response, static passwords, or OpenPGP. OnlyKey does support all of those things.
- cr7pt0 7y agoSolo is great, I would personally recommend this key if what you need is a 2nd factor. If you are looking for more features like password management and additional 2FA options then OnlyKey is a good choice.
- wclannen83 7y agoBest product of the year! A must buy!
- wclannen83 7y agoBest product of the year! A must buy.
- woliveirajr 7y ago> " promote us and earn" this doesn't send a good message
- nine_k 7y agoSomething way more solid apparently does exist: USB Armory. https://inversepath.com/usbarmory.html https://inversepath.com/usbarmory.html The hardware is open, the software is mentioned without much detail; I suppose it's not shipping yet.
- cr7pt0 7y agoThis product does not meet the same use cases as Onlykey, USB armory not being portable, waterproof, and durable is not something that will fit most users needs.