14 ms·
Arduino FIDO2 Authenticator
- indeyets 6y agoNot Arduino, but there is an open-source fingerprints reader for RPI: https://www.raspberrypi.org/blog/raspireader-fingerprint-scanner/ https://www.raspberrypi.org/blog/raspireader-fingerprint-sca... Is it that much worse in smaller form-factor? NDA only?
- snakeye 6y agoThere is small UART biometric module https://www.digikey.com/products/en?keywords=2304-100018754-ND https://www.digikey.com/products/en?keywords=2304-100018754-... The biggest downside - it's more that 3 times more expensive than the device I have now.
- StavrosK 6y agoThis is pretty cool, and being able to make a FIDO2 device that I can just keep at home next to the PC is pretty appealing. I already have a Yubikey in my keychain for carrying with me, but the keychain isn't at my desk, so having a second one would be pretty great. It would be amazing if this supported FIDO2 resident mode, it could store thousands of credentials (Yubikeys can only do 25 non-thousand credentials).
- snakeye 6y agoThank you! I'm looking for a simple and convenient solution as well.
- StavrosK 6y agoI have opened a few issues in your repo, I want to try this out but there's very little documentation. I know I can probably just `pio build -t upload`, but I'm not sure about the schematics.
- snakeye 6y agoOh, right, need some documentation there as well. In general you can try the project with ESP32 development board and upload the firmware using `pio run -t upload -t monitor` Then you need to pair the Bluetooth device. Afterwards you should be able to see connection requests in the serial monitor when you start authentication. The actual authentication commands are not implemented yet, so it will not go further. Sorry :(
- StavrosK 6y agoAh, I see, thanks. I will watch the project and hopefully will use it when it's finished, thanks!
- antoinealb 6y agoWhat I am doing, and I find it to work really well is to have a yubikey nano (https://www.yubico.com/product/yubikey-5-nano https://www.yubico.com/product/yubikey-5-nano) in one of the front USB ports of my PC case. Super easy to reach and takes no room at all.
- StavrosK 6y agoI don't want to pay $50 for another Yubikey when I have a box full of $4 ESP32s, though.
- sbr464 6y agoAwesome project. I have the USB-C version mounted under my desk with a USB-C extension cable. Works well. https://www.amazon.com/Faracent-Extension-Charging-Nintendo-Touchbar/dp/B071DMMW4J https://www.amazon.com/Faracent-Extension-Charging-Nintendo-... https://www.yubico.com/product/yubikey-5c-nano https://www.yubico.com/product/yubikey-5c-nano
- archi42 6y agoNot sure if applicable to your use-case, but I'm using a HyperFIDO Mini[1]. Much cheaper than the Yubikey, and the form factor is also nice for just keeping it in a (reachable by hand) USB port. Though I carry mine on the keychain (and have an older, bigger one at home as a backup). [1] https://hypersecu.com/tmp/products/hyperfido https://hypersecu.com/tmp/products/hyperfido
- snakeye 6y agoThis project is a spin-off from my wireless biometric authenticator. I was asked to make it open source many times. Other than that - I've got one on my keyring as well. But buying one is not as fun as making :)
- archi42 6y ago/me looks at his collection of electronic parts: Absolutely :) However, there is only so much time one can spent on this. Reminds me I should continue working on some FOSS after $dayjob is done for today...
- Freak_NL 6y agoDespite having a 'buy now' link to amazon.{de,fr,es,uk}, it refuses to ship to the Netherlands. That's disappointing (and sloppy).
- archi42 6y agoOh, that's really weird. I got it from .de delivered to DE. Maybe send the manufacturer a mail and ask them to fix it? Mine came DOA and I remember them to be pretty friendly.
- gruez 6y agoThat's surprisingly cheap, less than $10 for a token. Any downsides?
- solarkraft 6y ago
- badrabbit 6y agoWeld it into an anvil to prevent tampering while you are away!
- d33lio 6y agoHaha, I was thinking of a 50lb block of epoxy resin cast around the device, with metal rods protruding down to the touch sensors.
- mNovak 6y agoThe couple dozen keys storage limit definitely feels limiting if this ever supposed to be commonly used. Is anyone using the resident mode which OP mentions?
- StavrosK 6y agoI am, and yes, it's definitely limiting. I wouldn't buy a Yubikey because of that, I'm very excited about the new Solo keys that should be coming out soon, those will probably support thousands of keys.
- ecesena 6y agoChiming in to mention SoloKeys, it's open source, FIDO2 certified and supports 50 resident keys. @snakeye, please feel free to port over the CTAP implementation to your device (same for the other tokens I'm reading in the thread). We have already 3 products selling with our firmware. https://github.com/solokeys/solo https://github.com/solokeys/solo
- snakeye 6y agoThank you! I will definitely take a look at your CTAP implementation!
- StavrosK 6y agoI mentioned SoloKeys farther down the thread, I'm really excited about the new version. Is that coming out soon? I know it was supposed to come out in June, but haven't heard anything yet. I actually sent you guys an email a few minutes ago.
- ecesena 6y agoCurrently manufacturing the very first batch: we're waiting for the PCBs to be shipped, then we'll proceed with assembly, testing, etc. Conservatively I'd say we'll start shipping around Sep/Oct. But for sure there'll be some "limited edition" tokens in circulation before.
- StavrosK 6y agoThat's good news, thanks! Do you know how many resident keys you're going to end up storing? I'm really suffering with the Yubikey's 25, I'm going to write a post on SSH auth with FIDO2 and would like to be able to recommend SoloKeys.
- ecesena 6y agoWith the current Solo we have 256kB of flash so we sort of arbitrarily reserved space for 50 RKs, but you can prob tweak the firmware if you need. With the next gen of Solo we have 2MB of flash, so assume virtually unlimited RKs, at least given the number of sites that currently support them. (note: double checking w/ the team for correctness)
- mikecoles 6y agoWould the Krypton Authenticator be of any help to you? It works through an app on your phone. https://krypt.co/ https://krypt.co/
- StavrosK 6y agoI had used this for a while, the problem I had was that I change phones much more often than I change hardware keys, so I had to change every key on every site every year or so, which was too tedious.
- seppin 6y agoWhat is the case against using a bluetooth-linked 2fa from your phone the way Google Advanced Security does?
- brian_herman 6y agoBe careful with the bluetooth implementation. https://www.theverge.com/2019/5/15/18625028/google-titan-security-keys-bluetooth-vulnerability-replacement-free https://www.theverge.com/2019/5/15/18625028/google-titan-sec... https://nakedsecurity.sophos.com/2019/05/17/google-recalls-titan-bluetooth-keys-after-finding-security-flaw/ https://nakedsecurity.sophos.com/2019/05/17/google-recalls-t... edit: formatting
- snakeye 6y agoYes, I have seen this recently. Google is so unsatisfied with BLE in FIDO2 so they removed support for it from the Chrome browser.
- mtgx 6y agoYubico has said from the very beginning that they will stick to NFC because Bluetooth is not secure. Bluetooth is a 3000+ pages spec that's a mess and will likely always remain a mess. Maybe it's time for something better?
- snakeye 6y agoI'm using a bluetooth keyboard and I type my passwords in plain text. I don't think that public key sent over bluetooth is less secure. So it's a very tricky topic and I think it's more about corporate insterests that actual security.
- StavrosK 6y agoIs Bluetooth not encrypted? It would be disastrous if just anyone could read what your Bluetooth keyboard is sending.
- snakeye 6y agoIt is encrypted with MITM protection. That's why I do not believe in severe security issues in BLE. There can be problems with particular implementations, but in general it should not be less secure that typing password on a keyboard.
- nickik 6y agoFantastic. I have been thinking that the best possible thing would be an external device with a screen and a key pad input. This seems to be exactly that. You need the screen because the protocol includes the concept of an authenticator with a screen, and that allows you to verify the information even more compared to a yubikey or something like that.
- snakeye 6y agoThank you! :)
- jrexilius 6y agoI love this project. right approach for the problem. Will pitch in on the code.
- jrexilius 6y agoThat was my assessment as well a few years back, which drove the project I'm working on now. I embedded both the authentication (TOTP at the time) and content encryption functions directly into the keyboard and added an internal screen. I had been working through all the attack surfaces of trying to do it in the same kernel space as a compromised node and just decided that was the wrong way to go. Demo of the prototype I built is here: http://www.anomie.tech/deck/anigma-keyboard.m4v http://www.anomie.tech/deck/anigma-keyboard.m4v
- bendoerr 6y agoCan anyone explain or further expand on this statement > plain C and ESP IDF are too difficult for the broad audience My intuition is that most folks who hack on EPS32 and other microcontrollers have no problem with these things.
- snakeye 6y agoFrom my experience - most people say "Arduino is ok" but struggle working with plain C. As well keep in mind number of ready-made libraries for Arduino that can be reused here almost out of the box.
- TrueDuality 6y ago> But, wait, is it difficult to find a charger or power bank with Micro USB nowadays? It's definitely trending that way IME...
- alias_neo 6y agoI understood the point the article was trying to make here, but, actually, it's become almost a nightmare to find a Micro USB cable in my home, so I had to answer "yes". Every time one breaks or gets tatty I bin it and don't replace, because, really, the only thing I need it for is my PS4 controller and the baby monitor. I've burned through a decade or so worth of them thrown in boxes and drawers. It gets really hard these days to find one when I need to charge my PS4 controller and the baby monitor needs charging at the same time. While I'm on the go, I guarantee I don't have one. Phone, wife's phone, Switch, tablet, power bank, laptop, earbuds, all USB-C charging. It's taking me some time and careful purchasing choices to get to the point where I can carry a single power brick to fast charge all the devices I carry with one connector/cable, adding Micro USB back in would actually be an inconvenience.
- snakeye 6y agoNothing can stop us from making the same PCB but with USB Type C connector for charging. Actually I'm using it in my other device according to the exactly same thoughts.
- alias_neo 6y agoI've never tried hand soldering a USB-C SMT connector, expecting it to be somewhat harder than Micro USB, is it reasonably doable with hot air?
- snakeye 6y agoOh, in fact it's much simpler than MicroUSB. There is special type of USB Type C used for charging - https://en.ovcharov.me/uploads/2020/04/06/20200404_092055.jpg https://en.ovcharov.me/uploads/2020/04/06/20200404_092055.jp... It has only six huge pads and can be soldered either with hot air or normal soldering iron as a charm.
- dfox 6y agoIs it really necessary to use external ATECC508A with ESP32? I would not be surprised if software implementation on ESP32 is actually faster.
- snakeye 6y agoYou can not extract private key from ATECC508A while it can be an issue with custom key storage built on Arduino. The chip itself costs around one dollar so why not?
- ex3ndr 6y agoIsn't there is a good option is to use wireless charging instead of USB one?