Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Today there are more trustworthy alternatives. Yubikey is great for a very limited set of uses. But it lacks programmability and openness.

Something tillitis key has. Tkey has a steeper learning curve because they're programmable, but they're also 100% open source software and hardware.



>But it lacks programmability

For a lot of us, that's a feature, not a bug.


Sure, I mean there will always be two main groups of clients on the market. Those who trust in openness and those who don't care, or even distrust it. So there will always be a place for Yubikey.

But afaik there is nothing else out there right now like the tillitis key, programmable, 100% open, and already shipping.


If you have a key that can't be reflashed, source code is irrelevant. It may as well be hardwired circuits. Even Richard Stallman agrees on this point. I don't want a field programmable key, because it expands the attack surface.If you like weakened security, that's fine.


I always wonder: isn't programmability a security risk? What if a malware puts a backdoor in my programmable key?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: