Mention Nitrokey 3A's FIDO2 certification

I was under the wrong impression that Nitrokey was removed already.

In fact it would be good to mention the FIDO2 certification for Nitrokey 3A Mini.

More important I request the following corrections.

Nitrokey has a security key capable of FIDO2 and WebAuthn called the Nitrokey FIDO2. For PGP support, you need to purchase one of their other keys such as the Nitrokey Start, Nitrokey Pro 2 or the Nitrokey Storage 2.

Nitrokey FIDO2 is not available anymore. Nitrokey Start and Nitrokey Pro 2 are obsolete. Latest Nitrokey 3 and Nitrokey Passkey both support FIDO2 and WebAuthn. Nitrokey 3 also supports PGP. The text could be changed as follows:

Nitrokey has a security keys capable of FIDO2 and WebAuthn, OTP, PGP, and encrypted stored. For PGP support, you need to purchase Nitrokey 3 or Nitrokey Storage 2.

The following warning was right for the now obsolete Nitrokey Pro 2 but is not correct for current Nitrokey 3 anymore:

While Nitrokeys do not release the HOTP/TOTP secrets to the device they are plugged into, the HOTP and TOTP storage is not encrypted and is vulnerable to physical attacks. If you are looking to store HOTP or TOTP secrets, we highly recommend that you use a YubiKey instead.

For Nitrokey 3, all credentials are encrypted with hardware key and optionally PIN-protected credentials are encrypted with PIN additionally. I suggest to remove the entire warning and not discuss implementation details for simplicity reasons.

The link to the comparison table has been moved to: Nitrokeys | Nitrokey

2 Likes