3 ms·
There are a number of FOSS solutions. - https://github.com/google/OpenSK https://github.com/google/OpenSK <- DIY solution - https://solokeys.com/ https://solo
by e2le 4y ago
There are a number of FOSS solutions.
- https://github.com/google/OpenSK https://github.com/google/OpenSK <- DIY solution
- https://solokeys.com/ https://solokeys.com/
- https://www.nitrokey.com/ https://www.nitrokey.com/
The issue with any FOSS solution is that FIDO requires an attestation private key, which must be shared between a batch of at least 100,000 security keys. Using a DIY or cli app solution (application running on the host) will likely mean you'll be generating that private key yourself, this makes you identifiable across registrations.
Some sites (Cloudflare) may reject the use of attestation keys which are not found on the Fido Alliance Metadata Service. This precludes the use of any DIY solution.
https://fidoalliance.org/metadata/ https://fidoalliance.org/metadata/
https://support.cloudflare.com/hc/en-us/articles/4406889048077-FAQs-for-Cryptographic-Attestation-of-Personhood#h_16OGl1pu5javVk3m408rPU https://support.cloudflare.com/hc/en-us/articles/44068890480...
- Zamicol 4y agoThat's so dirty. Of course the centralized control is hidden in the details. Thanks for pointing that out.