Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
conorpp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
Designing Solo, a New U2F/FIDO2 Token
(conorpp.com)
3 points
by
conorpp
8y ago
|
0 comments
32.
▲
by
conorpp
8y ago
This is a hardware project I started when I was a senior in college. U2F Zero, a open source U2F token / two factor authentication device. https://www.amazon.com/gp/product/B01L9DUPK6 https://cono
33.
▲
by
conorpp
8y ago
ATECC608A is nice but can't provide total key isolation with the key derivation method most U2F keys use. E.g. it calculates the key using an HMAC, it gets sent back to MCU, the MCU writes it as a private key back to the ATECC608A to
34.
▲
by
conorpp
8y ago
We are using a EFM32 Silabs chipset and plan to use some sort of conformal coating to add water/weather resistance. We also plan to have a silicone case. I don't know about getting run over by a car, but they will certainly be r
35.
▲
by
conorpp
8y ago
This is a good point and generally a hard issue to solve completely. Right now, we plan to do the programming ourselves to at least verify that goes okay. Since we are bootstrapping, we are outsourcing the PCB-A, but hopefully since this i
36.
▲
by
conorpp
8y ago
FIDO2, possibly some other extensions. Also planning to have case, USB-C option, NFC option
37.
▲
by
conorpp
8y ago
Yes :(. I've been soldering with paste, stencil, and air gun and have had a good success rate, but it can be a bit more difficult. I'm thinking about making a short video showing how to solder one reliably for folks interesting
38.
▲
by
conorpp
8y ago
Thanks!! This next should will come with case and be more robust!
39.
▲
by
conorpp
8y ago
Assuming valid FIDO2/U2F implementation and same origin policy, this shouldn't be an issue. A browser will enforce that the APP-ID/domain name submitted to the token is the same as the origin requesting it. So in order to b
40.
▲
U2F Zero sales on Amazon year in review
(conorpp.com)
6 points
by
conorpp
9y ago
|
0 comments
41.
▲
by
conorpp
10y ago
A good idea is to store backup codes some place safe. You can use them as one time 2nd factors. Then you can then either disable 2FA, or more preferably, register a different 2FA option.
42.
▲
by
conorpp
10y ago
I'm naive and didn't realize Amazon wouldn't ship internationally by default. I just updated the listing to enable international shipping which should take effect in a couple days. Thanks!
43.
▲
by
conorpp
10y ago
Thank you!
44.
▲
by
conorpp
10y ago
Thanks! I didn't know about Security Dynamics. I think there's a lot of neat improvements you can make on 2FA products for different markets. But it's kind of at the point where if I wanted to continue working on a better 2
45.
▲
by
conorpp
10y ago
I agree. The problem is trying to do this at scale. I don't want to do it myself as it would be too time consuming and messy. Without having the funds for injection/pressure molding, I haven't been able to find a good solut
46.
▲
by
conorpp
10y ago
Haha good question. Yubico has a good explanation: https://www.yubico.com/products/yubikey-hardware/fido-u2f-se... It's the same as any other U2F token. You register it with a service that supports U2F (Goog
47.
▲
by
conorpp
10y ago
Yeah I'm not sure about the legals and just figured it would be fine. I did get a VID/PID from SiLabs which has already done USB certification for the chip. FIDO U2F also has a $10k certification process to allow you to use the F
48.
▲
by
conorpp
10y ago
Thank you! Assembly depends on the service you end up using. For PCBCart, I think I just ended up filling out their template BOM manually. Not much of a hassle since I only have 8 parts. I just had to match the component references on th
49.
▲
Designing and Producing 2FA tokens to Sell on Amazon
(conorpp.com)
255 points
by
conorpp
10y ago
|
109 comments
50.
▲
by
conorpp
10y ago
Yes you're right. It's hard to say that most mistakes are avoided from two audits. Especially in a browser; there's a lot of attack vectors.
51.
▲
by
conorpp
10y ago
Have you heard of or used signal? https://whispersystems.org/ Same idea -- strong crypto that's usable for anyone. It uses the OTR Ratchet protocol which uses perfect forward secrecy. The app also provides a way to v
52.
▲
by
conorpp
10y ago
Thanks for the comments! I never thought of trying to do a reversible USB connection. And it's actually quite easy! The button you point out looks like a better choice. It's about 10 cents cheaper than my current one. Currentl
53.
▲
by
conorpp
10y ago
The keys used for the picture are not used. But yes it is not a good practice to post pictures of door keys.
54.
▲
by
conorpp
10y ago
It's a good question. It's definitely not been through years of testing yet but in the past few months me and some friends have had no problems. All of the parts have a low center of mass with respect to the PCB and are unlikely
55.
▲
by
conorpp
10y ago
As the ATECC508A is just an I2C peripheral you still have a broad choice for microcontrollers (as you still need a U2F program and U2F). I choose to use a EFMUB1 from silicon labs.
56.
▲
by
conorpp
10y ago
Yes. There is [1] which is on Yubikey OTP specifically. And on a lot more that focus on general embedded platforms running common cryptographic algorithms. U2F uses elliptic curve cryptography (ECC) internally -- check out this source for
57.
▲
by
conorpp
10y ago
No it is purely a hardware peripheral that just has configuration options. http://www.atmel.com/Images/Atmel-8923S-CryptoAuth-ATECC508A...
58.
▲
Show HN: A secure, open source U2F token you can make with $4.5 worth of parts
(github.com)
267 points
by
conorpp
10y ago
|
92 comments
59.
▲
Pearson Educations exploitable method for checking homework answers
(conorpp.com)
1 points
by
conorpp
10y ago
|
0 comments
60.
▲
My experience with DirtyPCBS.com
(conorpp.com)
1 points
by
conorpp
11y ago
|
0 comments
More ›