Experience and opinions about Token2 2FA hardware maker?

Hey, I came across token2.com (.eu; .swiss etc.) as a more budget friendly 2FA hardware maker HQd in Switzerland. They make FIDO certified keys, some with added functionality and they have some additional certifications as well. Industry customers use them too.

I would like to know if anyone knows anything about their products, I would be curious about their experience and opinion about ease of use, security, customer service etc.

Related Reddit thread: https://www.reddit.com/r/Bitwarden/comments/152e1ig/token2_a_cheap_alternatives_of_yubikey_good_enough/

1 Like

They don’t seems to have the hardware code open like the solokeys does, but they seems to have opened some of their companion tools there. Would like indeed, to have more insight from someone who knows more about that domain. Looks really interesting.

I asked them in email and this is what they said:

Q: Are the firmware on your keys open source, did it ever recieve a security audit, what was the name of the original firmware you used (I read somewhere that you used a 3rd party firmware)?

A: No, the firmware of our products is not open-source.
You will find Python scripts for compatible products after purchasing them in the customer account interface. You can change it and use it for internal use if needed.

I asked them again about the audits:

Q: Whether the firmwares had any security audits (despite not being open source), is that information available?

A: Our security keys are FIDO-certificated and meet the standards provided by FIDO Alliance.

To verify use the certification URL: FIDO® Certified - FIDO Alliance (Search for “TOKEN2…” in Company field)

See the PDFs below:
https://www.token2.com/img/FIDO2-T2F2ALU.pdf
https://www.token2.com/img/FIDO2-T2F2.pdf

The information about certifications is available below:
Token2 | Hardware MFA tokens for Azure MFA | Certifications & Compliance | TOKEN2 MFA Products and Services | programmable hardware token, FIDO2 key, U2F key, TOTP, Hardware MFA tokens for Azure MFA |

Take that as you will.

2 Likes

Thanks for asking. Expected answer for the first and totally out of topic from them for the second.

Too bad they don’t make a key in the format of a Yubico 5C Nano. They only have an USB A version.

Hello, I am associated with Token2. Let me provide clarification on the response from the helpdesk, which might not have been described very well.

FIDO2 keys undergo thorough audits by certification engineers from the FIDO Alliance. Generally, there is no requirement for additional security audits, especially for L1-certified keys.

In cases where products lack established certification routines, Token2 has engaged in third-party audits. For instance, Molto2 is an example: Token2 | One-Time Password (OTP) Tokens | OATH-compliant Authentication Tokens and Cards | OATH-TOTP SHA-1 SHA-256 | Blog | TOKEN2 MFA Products and Services | programmable hardware token, FIDO2 key, U2F key, TOTP, One-Time Password (OTP) Tokens | OATH-compliant Authentication Tokens and Cards | OATH-TOTP SHA-1 SHA-256 |

On a separate note, the link to Token2’s Github you posted previously is not the scripts the helpdesk mentions in the first response; there are some other Python source codes that are made available for customers to examine (and use).

1 Like