Hardware security key options?

I’ve been thinking about getting a hardware security key and have heard of yubikey before; but I want to see what my options are and if they are worth it in your opinion.
My current setup is a local KeePassXC database (that I sync between my PC and phone and also acts as TOTP authenticator app), I know that KeePass supports hardware keys for unlocking the database.

I am personally still of the belief that passwords are the safest when done right; but 2FA/MFA can greatly increase security on top of that (again, if done right).
The key work work together with already existing passwords, not replace them.

As I use linux as my primary OS I do expect it to support it and anything that doesn’t I will have to pass on.

PS: what are the things I need to know about these hardware keys that’s not being talked about too much, I am very much delving into new territory and want to make sure I’m properly educated before I delve in.

@linux @technology@lemmy.ml @technology@lemmy.world @privacy #2FA #MFA #yubikey #InfoSec #CyberSecurity

20 points

There’s a Swedish startup named Tilitis making open source, verifiably secure hardware keys, but they’re not well supported at the moment.

https://tillitis.se/

Yubikey probably has the widest support for things like password managers and automatic sign in.

permalink
report
reply
4 points

Just +1 to Tillitis, they’re doing awesome stuff with FOSS hardware.

permalink
report
parent
reply
1 point

I use yubikey, hard to find sites that fully support yubikey services (the one touch feature)

permalink
report
parent
reply
9 points

Look into SoloKeys and NitroKeys and see if there’s products from those vendors that fit your needs.

permalink
report
reply

As to why thisisawayoflife recommends these products (over OP’s consideration of Yubico), probably because Solo and Nitro keys are open source hardware and firmware.

Nitro is a German company. Yubico is a Swedish company. I can’t find where SoloKeys is located. However, the OS nature of Solo and Nitro should make that a little less important.

permalink
report
parent
reply
2 points
*

In my research, I’ve found SoloKeys may be a US company. They are headquartered in New Jersey and one Co-founder is in New York City. However, according to their WhoIs data, the domain was registered in Iceland.

From SoloKey’s Solo 2A+ NFC Security Key product page “Made and programmed in Europe.” https://solokeys.com/products/solo-2a-nfc-security-key?variant=40297992093889

permalink
report
parent
reply
1 point
Deleted by creator
permalink
report
parent
reply
3 points

I also recommend Nitrokey. I have a Nitrokey Pro 2 and a Nitrokey 3 NFC and they both work well. Linux support is very good, and they also have good documentation on how to do most stuff you might want to do. +1 for being open-source as well.

permalink
report
parent
reply
1 point

Well I might be ignorant of first principles, but I couldn’t get a nitrokey I got for testing to work with anything.

Not that yubikey is easy.

permalink
report
parent
reply
1 point

Nitrokey isn’t fully open source though. The secure element is proprietary. But that’s not their fault, OSS secure elements aren’t a thing yet unfortunately, but some companies wanna bring a change in that

permalink
report
parent
reply
6 points
*

While Keepass has the ability to use a Yubikey (or similar) as 2FA (masterpassword is still required), this does not work on the mobile (Android) apps I tried. If you can make it work, please let me know!

Other than that: I got my Yubikey working ok on Linux Mint. But somehow the first login often does not work as expected (you have to touch the key). That is why I don’t use it anymore as 2FA for computer login.

permalink
report
reply
6 points
*

Yubikeys can work with KeePassDX you just need to install the key driver and have NFC enabled

Also I’m pretty sure you are always supposed to touch the key initially when you use it for things like unlocking your KeePass database and what not

permalink
report
parent
reply
2 points

keepass2android also work

permalink
report
parent
reply
1 point

I don’t have a key yet (which is why I’m asking) and I definitely want it in combination with passwords (they can take the key using force; but they can’t take thoughts out of my head just yet).

As for android apps not working with the yubikey: try giving KeePassDX a shot; I got it from F-Droid and it does give me a hardware key field with the option to autofill with “Yubikey challenge-response”.

permalink
report
parent
reply
1 point

Thanks, I will try again!

permalink
report
parent
reply
5 points

Nitrokey would probably be my choice as both the hardware and software are open source( in fact you could probably build your own if you wanted to). I don’t trust yubikey as the firmware that runs on them is closed source so you just don’t know of it’s actually secure.

permalink
report
reply
2 points

This. Yubikey is not libre hardware, not sure why they’re so popular. I’d avoid any closed-source hardware for security devices. Its a bad idea.

permalink
report
parent
reply
5 points

I’m using yubikeys. Works fine on Linux and Android.

permalink
report
reply

Linux

!linux@lemmy.ml

Create post

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Community stats

  • 7.5K

    Monthly active users

  • 6.6K

    Posts

  • 179K

    Comments