!jNACPcjUkhjzSAaLLl:matrix.org

SoloKeys Development

160 Members
Development discussion of the SoloKeys project. See the community for more rooms: #solokeys-space:matrix.org49 Servers

Load older messages


SenderMessageTime
14 Jan 2024
@krasovsky:envs.netSavely Krasovsky In my opinion Kellerkind is a little bit categorical. SoloKeys team alive, but Solo 2 won't probably receive any updates soon or probably at all. Also it's not FIDO certified. I could not recommend them as FIDO2 keys for now. 20:14:41
@niko:conduit.rsnyanbinaryTKey seems more like a small computer20:32:23
@niko:conduit.rsnyanbinaryBut Solokey 2 is also a small computer (kinda)20:32:34
@niko:conduit.rsnyanbinarySince users were intended to be able to run apps on them too right?20:32:49
@niko:conduit.rsnyanbinaryBuild with Trussed20:32:52
@krasovsky:envs.netSavely KrasovskyAll security keys is kinda small computers. Solo and TKey just could run apps and allow to sideload it (Yubikeys also has kind of apps, but you cannot update them or install new).20:34:42
@niko:conduit.rsnyanbinaryAlso20:55:56
@niko:conduit.rsnyanbinaryit seems like the TKey is more powerful than the Solokey?20:56:07
@krasovsky:envs.netSavely Krasovsky * All security keys are kinda small computers. Solo and TKey just could run apps and allow to sideload it (Yubikeys also has kind of apps, but you cannot update them or install new).20:56:46
@niko:conduit.rsnyanbinarycan anyone confirm :321:11:17
@jannf:matrix.orgKellerkindTkey is a whole different approach, as there is no User data stored on it. It is implemented on a FPGA that has an open source tool chain. So it runs a soft core cpu rather than being dependant on a cpu from a manufacturer. 21:16:09
@jannf:matrix.orgKellerkindhttps://tillitis.se/products/threat-model/21:20:45
@krasovsky:envs.netSavely Krasovsky
In reply to @jannf:matrix.org
Tkey is a whole different approach, as there is no User data stored on it.
It is implemented on a FPGA that has an open source tool chain.
So it runs a soft core cpu rather than being dependant on a cpu from a manufacturer.
In that case FIDO app will require to store encrypted material at user machine?
21:24:43
@niko:conduit.rsnyanbinary
In reply to @jannf:matrix.org
Tkey is a whole different approach, as there is no User data stored on it.
It is implemented on a FPGA that has an open source tool chain.
So it runs a soft core cpu rather than being dependant on a cpu from a manufacturer.
Hmm how would this go up against the Solokey v2?
21:40:40
@krasovsky:envs.netSavely KrasovskyIt depends on what important for you. FPGA excludes any possibility of vendor hardware exploit from NSA or kinda.21:42:01
@jannf:matrix.orgKellerkind
In reply to @krasovsky:envs.net
In that case FIDO app will require to store encrypted material at user machine?
No but I think things are derived by a value that is stored at the lifetime programming of the small on time programmable memorie
21:42:09
@jannf:matrix.orgKellerkindThey also sell an "unlocked" version where you could program that area yourself 21:43:50
@niko:conduit.rsnyanbinary
In reply to @krasovsky:envs.net
It depends on what important for you. FPGA excludes any possibility of vendor hardware exploit from NSA or kinda.
Security and Open Source
21:43:48
@niko:conduit.rsnyanbinaryis important :321:43:51
@jannf:matrix.orgKellerkindFor me the current goto would still be nitrokey 3 as they use/develop trussed and implement a gpg Smartcard. 21:44:55
@krasovsky:envs.netSavely Krasovsky
In reply to @jannf:matrix.org
They also sell an "unlocked" version where you could program that area yourself
Could TKey approach even be certified by FIDO btw?
21:45:12
@krasovsky:envs.netSavely KrasovskyI see it more like a "fun" addon option like in Trezor or Flipper Zero.21:46:27
@niko:conduit.rsnyanbinaryin theory its a full HSM21:49:19
@niko:conduit.rsnyanbinaryjust pluggable 21:49:23
@niko:conduit.rsnyanbinaryAlso there serious weight behind these ppl21:49:34
@niko:conduit.rsnyanbinaryIts a spinoff of Mullvad VPN21:49:42
@niko:conduit.rsnyanbinarythe people who made the TKey21:49:48
@krasovsky:envs.netSavely KrasovskyYes, I read already.21:50:25
@niko:conduit.rsnyanbinaryAlso to note it uses a open RISC-V design21:54:25
@niko:conduit.rsnyanbinaryWhy hasnt Nitrokey gone the FGPA route btw?21:54:54

Show newer messages


Back to Room ListRoom Version: 5