23 ms·
Yubico is merging with ACQ Bure and intends to go public
- aborsy 3y agoAnyone has insights into how trustworthy is Yubico? Their firmware is opaque, not shared outside the company, so is their hardware (important for RNGs etc).
- bberrry 3y agoVery. They are a tiny Swedish company that pay for top talent, are quite active and hands-on in the netsec community. It's not a faceless corporation with a Chinese PO Box.
- gonesilent 3y agoUS government had a nice little swedish cryptography company there for a bit too...
- bschne 3y agoDo you mean Swiss (classic!) or was there another one? https://en.wikipedia.org/wiki/Crypto_AG https://en.wikipedia.org/wiki/Crypto_AG
- steve1977 3y agoThey were a tiny Swedish company…
- Namidairo 3y ago> It's not a faceless corporation with a Chinese PO Box. On this note, are Feitian still the OEM for the Google Titan keys?
- JoachimS 3y agoTiny is a bit misleading. The turnover is about 100 MUSD. The company has about 300 employees, with offices in all regions of the world and a lot of R&D in the USA.
- bberrry 3y agoI wasn't aware they had grown that much. Thanks for the correction
- JoachimS 3y agoIf you are looking for a tiny, Swedish company working in a similar area as Yubico, there is Tillits AB. Tillitis is a spin off from the Swedish VPN provider Mullvad. In contrast to Yubikeys, The Tillitis TKey as well as tools, device verification etc is 100% open source. https://tillitis.se/ https://tillitis.se/ https://github.com/tillitis https://github.com/tillitis https://mullvad.net/en https://mullvad.net/en (Full disclosure: I work for Tillitis.)
- FeistySkink 3y agoIs the TKey tamper-proof?
- JoachimS 3y agoNo, not yet. Physical attacks are out of scope for the TKey1, even if we have some mechanisms in play which try to extend the time and effort required to perform a successful evil maid-attack extracting the Unique Device Secret (UDS). See the threat model for the release: https://github.com/tillitis/tillitis-key1/blob/main/doc/threat_model/threat_model.md https://github.com/tillitis/tillitis-key1/blob/main/doc/thre... The current casing is fairly tamper evident (it will break), but we do not yet use real, tamper evident sealing. We are looking at tamper sealing for future versions. And ways to further protect against physical attacks.
- belter 3y agoWhen you do, please think about a special price for existing customers ;-)
- jtvjan 3y agoThe key costs 880 SEK. That's about 78 euros or 85 dollars. It's designed to be future proof, with applications being uploaded to the device by the host. The website feels a bit cramped with all the large text on desktop, like it was only tested on phones
- 3y ago
- aborsy 3y agoThanks for the info! The construction quality of Yubikeys has been good in my experience. I was just worried about the closed source proprietary firmware in a security product (including the random number generators, where issues were discovered in the past). But Yubikeys are used in various companies and apparently in some branches of governments too, thus must have been vetted by their security teams (though there could be different lines of firmware or products for different clients. People say there is not much benefit to purchasing FIPS-compliant Yubikeys. Neglecting the approved algorithms and features, is the firmware the same as that in non-FIPS security keys?)
- INTPenis 3y agoToday there are more trustworthy alternatives. Yubikey is great for a very limited set of uses. But it lacks programmability and openness. Something tillitis key has. Tkey has a steeper learning curve because they're programmable, but they're also 100% open source software and hardware.
- panny 3y ago>But it lacks programmability For a lot of us, that's a feature, not a bug.
- INTPenis 3y agoSure, I mean there will always be two main groups of clients on the market. Those who trust in openness and those who don't care, or even distrust it. So there will always be a place for Yubikey. But afaik there is nothing else out there right now like the tillitis key, programmable, 100% open, and already shipping.
- panny 3y agoIf you have a key that can't be reflashed, source code is irrelevant. It may as well be hardwired circuits. Even Richard Stallman agrees on this point. I don't want a field programmable key, because it expands the attack surface.If you like weakened security, that's fine.
- palata 3y agoI always wonder: isn't programmability a security risk? What if a malware puts a backdoor in my programmable key?
- nikanj 3y agoTime to crank the monetizing tap, add a mandatory monthly subscription to everything and deprecate well-working gear
- cinntaile 3y agoYou could buy a programmable open source security key instead, they recently opened their shop. https://tillitis.se/ https://tillitis.se/ Some of the people behind Mullvad VPN are associated with it.
- lhoff 3y agoThey are not just associated with it. It’s a spin-off and is owned by the same company. From there FAQ: > Tillitis is wholly owned by Amagicom AB and is a spin-off from the sister company Mullvad VPN
- adql 3y agoThat site is fucking garbage, and there doesn't even see to be a dock on what it supports. Like, programmable key is cool as an idea but I need smartcard support and a button on it to confirm transaction to replace YK usage...
- dathinab 3y ago> and there doesn't even see to be a dock on what it supports. there is, at the bottom of the get started page currently besides validating the key itself only ssh and git signing by ssh key is supported by them Also directly from the main page the first noticeable thing: > TKey’s design encourages developers to experiment with new security key applications and models in a way that makes adoption easier and less risky for end-users. I.e. it's for now mainly for developers not end users (for now). There is a "button" on it. (Which yes isn't mentioned anywhere, outside of some article you can navigate to by following multiple links). Most important (and they could be more clear about it) it doesn't have (writable) persistent memory. Which has both some grate benefits and but can also have some major inconvenience. And depending on how/for what you use smartcard support I'm not sure it might ever support it. Anyway the shop opened around 16 days ago so it's still very early days for TKeys (and their website, and documentation, etc.). I'm looking forward to what it will enable. But AFIK it's already a grate choice for certain kinds of companies for their employees.
- rmccue 3y ago(ACQ Bure is a SPAC.)
- VMG 3y ago> A special purpose acquisition company (SPAC; /spæk/), also known as a "blank check company", is a shell corporation listed on a stock exchange with the purpose of acquiring a private company, thus making it public without going through the traditional initial public offering process and the associated regulations thereof. https://en.wikipedia.org/wiki/Special-purpose_acquisition_company https://en.wikipedia.org/wiki/Special-purpose_acquisition_co...
- Sander_Marechal 3y agoWhy is that even legal?
- mongol 3y agoWhy should it not be legal? Exactly what is wrong with it and how would legislation that forbids it but allows other M&A activities look like? I don't see a problem.
- drexlspivey 3y agoIf “Hacker” News was assigned as a regulator nothing would be legal
- munchbunny 3y agoInteresting that Yubico is choosing to go public via SPAC. It’s lower scrutiny, it became more popular over the last few years, and then lost some popularity because of high profile duds. Why go with a SPAC in that environment if the business is healthy and profitable?
- red_admiral 3y agoBecause, as far as I know, the business is not hugely profitable and there's not much scope to change that. Yubico makes a product that is high quality, does exactly what it says on the tin, does not come with any integrated ads/AI or anything else like that, but in the grand scheme of things is fairly niche (I wonder how many people outside of the tech and perhaps gov sectors would even recognise the company name). There's simply no way they can line up the "here's how we get to 1B users and then mine all their personal data" business plan that some other tech companies can do.
- dumpster_fire 3y agoI have an irrational concern about using security products from a company post-merger or acquisition. It has never ended well for me as an anecdotal user. Going public is taking that worry even further. Make keys, sell keys. The end. What's there to raise funding for? Build yet another password vault?
- gonesilent 3y agobuilding a legal team to fight shareholder lawsuits!
- pavlov 3y agoThis is not really a merger because the other company is a “blank check” holding company (a.k.a. SPAC). It has no operations, it just holds a bunch of money put in by investors who want to find a private company that wants to go public.
- Raed667 3y agoThe fact this is not only legal, but common practice baffles me ...
- rekttrader 3y agoIt’s a more transparent and less predatory than venture capital.
- pavlov 3y agoIs it? VCs don’t raise money from “mom and pop and Reddit” retail investors, but SPACs have enabled insiders to sell stock at $10 that often ends up being worth less than $1 or even bankrupt just a year or two later. These often included a social media pump like the SPACs promoted by “SPAC king” Chamath Palihapitiya. However the companies that go public via SPAC are mostly VC-funded, so in that sense you’re right that they’re also profiting from the SPAC con by being able to dump their holdings in these companies that were not actually ready to go public.
- dboreham 3y agoTime for an open source u2f token.
- rootio 3y agoLike SoloKeys? The Solo 2 has a firmware written in Rust: https://solokeys.com https://solokeys.com
- faust201 3y agoReally like the SoloKeys... but once you go at the level of small or large MNC they do business with people like YubiCo etc only. Never with tiny shops. (Sad)
- xarope 3y agoAnybody have a solokey, or have some feedback? I wanted to buy some, but the comments about bent connectors put me off, as well as the supply issues for usb-c
- ptman 3y agosolokeys2 is physically better than solokeys1, but firmware is buggier
- zyberzero 3y agoI backed their crowdfunding campaign back in the day. Due to $REASON I didn't test all of them when I got them, but when I got around to it two out of four were broken (the broken ones had USB-C). Their support didn't help at all (why should they? but they could have offered me keys for a better price...) With that said, I had a Yubikey Neo die for me as well (NFC still worked, USB totally dead) - Yubikey offered me a new key for a discount.
- rootio 3y agoSolo 2 fixed the bent connectors issue. Solo 2 USB-C has supply issues, you'll probably have to wait a couple of months to get one.
- 3y ago
- snorremd 3y agoI really hope this does not affect their current mode of operation. The reason I bought my Yubikeys in the first place were the one off purchase cost and the promise that the keys would do their job without me having to interact with Yubico from that point onwards. This has worked great so far! Now with shareholders in the mix I fear they will try to find recurring income models to increase profits. I guess we'll just have to see.
- belter 3y agoAs somebody who just bought some keys last week for the same exact reasons, I share the same exact concerns. Why this need to always make more and more money? Do one thing, do it right, keep your customers happy, get your money, enjoy your life...
- flandish 3y agoThis “why” is the ever expanding nature of capitalism.
- lotsofpulp 3y agoDo you expect your retirement savings to earn a minimum of x% per year? What is that x%?
- belter 3y agoI expect a company to turn and stay profitable, by doing their core business, prioritizing product quality, customer service and sustainable development. Not to end up as an over leveraged financial construct riding on extracting more and more of their customers. Optimize the business quality not the shareholders returns.
- lotsofpulp 3y agoWould you (or do you) invest in that company over a different one whose share prices appreciate by a greater amount? Would you accept less compensation if your employer cannot keep up with competitors?
- toastal 3y agoOpen hardware security keys exist. Software should not lock themselves into proprietary hardware for security anymore than goobers locking themselves into Symantec's wrapper or only-our-app for basic TOTP which could be platform agnostic.
- dingusdew 3y ago[dead]
- 0xbadc0de5 3y agoAnd how have SPAC mergers historically performed? <quick search> Yikes! I didn't realize Yubico was is such bad shape financially that this was their best (only) option.
- super256 3y ago> Yikes! I didn't realize Yubico was is such bad shape financially that this was their best (only) option. Some early employees could want to cash out. Going public is a great way to do that.
- everdrive 3y agoHonestly, do any companies improve in the long term when going public? It seems like the business model is always to make short term profits and then slowly (or in some cases quickly) die about.
- echelon 3y agoLots of companies found greater success post-IPO. Apple, Google, Facebook, Microsoft (especially recently), Nintendo, Tesla, etc. The IPO is a statement to investors that the company believes it will grow bigger and seeks public market funds to accelerate growth. That doesn't always happen. Some companies and investors see the IPO as merely a liquidity event, which is the wrong perspective to take. SPACs were clearly being abused for this.
- deleted 3y ago[deleted]
- adql 3y agoNot talking about company being more successful but better to the actual customers. Google isn't exactly a good example here Also Microsoft went public almost 4 decades ago, apple went public over 4 decades ago, the landscape looked a bit different there.
- frunns 3y agoFacebook is my main argument why IPOs suck. Facebook used to be a decent platform, post-IPO it's awful. Might be unrelated to the IPO, might not. But yeah, financially it might be "better", as they're more heavily exploiting their users' attention.
- everdrive 3y agoAs the other commenter noted, I’m talking about value to the customer rather than value to the company. WRT your list, I would only claim Apple as a clear success in this regard. (I don’t particularly like Apple myself, but Apple does seem to be giving customers more of what they actually want.) Microsoft - Ruining Windows to extract more value from customers. Facebook - hardly anything even needs to be said here. Google - slowly getting worse and rotting away. Tesla - I’m a bit neutral here. Tesla has its problems, but it’s not clear that they used it be amazing and now are just trying to extract money from users.
- account-5 3y agoSeems like another reason not to use yubikeys, especially with the push for Fido. The cynical part of me assumes going public means they'll need to generate more income for investors. Fancy a subscription service to keep you yubikeys working?
- tonyarkles 3y agoSo maybe I’m too much of an optimist but I’be been thinking about Tailscale a lot recently because of how much of a game changer their product has been for us. I shudder to imagine what our VPN setup would look like at work if I hadn’t discovered Tailscale a month or two before the COVID craziness all started. Maybe Yubikey could do to PKI what Tailscale did for VPNs: make the whole process dramatically simpler and easy to use. Still sell Yubikeys, please, but set up a funnel to capture corporate recurring revenue by solving this problem better than the alternatives.
- JohnFen 3y agoI don't think there's anything Yubico can do that affects the operation of the keys they've already sold. Any adverse product effects will be with new keys they will sell.
- user3939382 3y agoThe problem with going public is that performance is now measured quarterly. This incentivizes mortgaging the long-term health of the company for short-term gains. Brand loyalty and trust become assets that can be profitably liquidated by diluting the quality of products and services. By the time customers catch on and the company falters, the investors/owners that profited financially, and managers that profited on their resumes, from the short-term gains may have moved on. The party that's really hurt is the customer base. I've seen this play out again and again.
- Scoundreller 3y ago> The problem with going public is that performance is now measured quarterly. Depends on ownership. When the insiders still own 80% (or control that much through super-voting shares), the minority shareholders’ interests (often but not always short-term) may still be ignored.
- wintogreen74 3y agoThe market now measures performance regardless of ownership. Just because they retain a huge percentage of shares, or controlling interest, doesn't mean they'll accept massive declines in market value.
- mattmaroon 3y agoIt means they can though. The tech world is full of examples of companies keeping their focus long-term due to dual class structure and/or founders retaining large stakes despite the vagaries of the market. But, nothing lasts forever. Eventually the founders sell, the shares get converted to common, etc.
- selectodude 3y agoFacebook is, even now, entirely beholden to Mark Zuckerberg's willingness to accept falls in share price. He cannot be removed.
- wnevets 3y ago
- philip1209 3y agoI'm curious how Apple Passkeys will affect the Yubico business. Competition for U2F products may increase drastically as consumers begin adopting it. This may be prescient timing to go public for Yubico.
- labcomputer 3y agoProbably not at all? Yubico is one of two brands that Apple recommends for securing your iCloud account.
- ec109685 3y agoThe keys in our phone and our computers are going to handle a majority of the use cases that currently rely on yubico. We use them at work, but they aren't fundamentally more secure than the what's built into the computer.
- labcomputer 3y agoRight, but you still “need” a pair of Yubikeys to secure the iCloud account that holds your Passkey credentials. So you’d use the Yubikeys less in day-to-day auth situations, but you still need to buy them.
- ec109685 3y agoThat or another iCloud device. If you have a couple, that can be your security backup (afaik). I do think the calculus changes for yubikey. Without built in security keys, every knowledge worker on earth should have a yubikey like thing, so their market is huge. With built in device security, then the keys might not be deployed at the same rate. It's a good point though. I also think companies (at least mine) like having full control over the yubikey experience whereas the way apple manages the secure enclave is more obtuse.
- kylehotchkiss 3y agoPasskeys already work with Secure Enclave and across multiple devices. Yubikeys require a purchase and potentially multiple keys. Passkeys will win the war for the everyday user, and Yubikeys will remain a niche IT item. Their focus on FIPS audiences is good though as that should provide a longer-term reliable source of sales. I hope Yubikey survives long term because I like their tech implementation (a key must be present AND physically touched to activate). I travel much more confidently with Yubikey locked accounts. I know where my Yubikeys are at home and I don't generally take them out with me. The war for better securing online accounts benefits us all though. haveibeenpwned hasn't gotten any smaller over the years :/
- armatav 3y agoFinally
- jmclnx 3y agoWell nice knowing you as a Company that cared for its user base. Soon you will be beholden to Wall Street. That means at the slightest controversy there will be calls to enable a back door to your product(s).
- JohnFen 3y agoCongratulations to the Yubico team! It was nice while it lasted.
- mattanimation 3y agoI literally just bought a Yubikey 5 yesterday... great.
- ChancyChance 3y agoI was a big fan of Yubikey (I have 3) until fewer and fewer services supported them, instead switching to authenticator apps. Now I have zero hard tokens, but still four authenticator apps: Google + 3 for banking services that use their own. The biggest killer was the fact that Yubikey NFC is so awful. I worked with tech support repeatedly, even bought two new keys, and it almost never worked right.
- Arnavion 3y agoServices support Yubikeys through U2F / WebAuthn, not anything Yubikey-specific, right? If you're using services that don't support that, I take it the apps you do use are using TOTP?
- nine_k 3y agoThis works with desktop / laptop where you can attach the key over USB. On mobile, if it works at all, it should be NFC.
- ChancyChance 3y agoAll three of my banks do not support Yubikey according to their tech support.
- Arnavion 3y agoI'm not asking you what they don't support. I'm asking you what they do support.
- ChancyChance 3y agoTheir own hard tokens and authenticator apps.
- tpmx 3y agoI think it makes a lot of sense for things like AWS developer/devops access. With AWS IAM Identity Center (successor to AWS Single Sign-On) - that's actually the official name, hopefully temporary - it seems well supported via WebAuthn. You can "even" have multiple keys assigned to your account...
- MaKey 3y agoPossible Open Source alternatives are Nitrokey (https://www.nitrokey.com/ https://www.nitrokey.com/) and Solokeys (https://solokeys.com/ https://solokeys.com/).
- Havoc 3y agoI swear if I need to drink a verification can to unlock my mail… Just kidding. Hopefully this has no security or usability impact.
- tptacek 3y agoACQ Bure is a SPAC, so really what Yubico is doing here is simply "going public"; a SPAC is just a vehicle for doing that, as is an underwritten IPO or a direct listing.
- JohnFen 3y agoA SPAC is not "just a vehicle" for doing that. It's an intentional dodge to let companies avoid scrutiny but still go public. The use of a SPAC to do this automatically casts a bit of shade over the company. But even ignoring that, going public itself doesn't bode well for the product regardless.
- paxys 3y agoI like Yubico but to me going public via a SPAC is a huge red flag.
- algesten 3y ago"Caroline af Ugglas, on behalf of ACQ board of directors commented: …" This is weirdly enough a Swedish singer who had Eurovision Song Contest ambitions. https://www.youtube.com/watch?v=HE1Vy5lKuzw https://www.youtube.com/watch?v=HE1Vy5lKuzw She's part of the Swedish upper class – the Swedish wikipedia page lists her as "baroness" (friherrinna), further accentuated by her name ("af" is the swedish variant of the german "von")
- JoachimS 3y agoNot the same person. The Caroline af Ugglas on the ACQ board is this person: https://www.acq.se/styrelsen/caroline-af-ugglas https://www.acq.se/styrelsen/caroline-af-ugglas This is the artist: https://en.wikipedia.org/wiki/Caroline_af_Ugglas https://en.wikipedia.org/wiki/Caroline_af_Ugglas
- 1letterunixname 3y agoAnd this, ladies and gents, is why you never take investment money unless your business absolutely needs a capital infusion to build whatever it is immediately. Equity is where the gold is, and each investor is an extra marriage partner who must be satisficed and can potentially upend everything. Build a stable business, not an instant payday.