I think we should add security key criteria to require:
FIDO2 Level 1 or higher certification on the key itself (some websites/applications will only work with FIDO certified keys!)
Uses a secure element with a CC EAL6 or higher certification
Currently, only a single Nitrokey product has both: the Nitrokey 3A Mini.
We do note this on the page already, but we should be stronger about requiring this (because some websites/applications will only work with FIDO certified keys).
I think we could either change the recommendation to specifically the Nitrokey 3A Mini, or just remove Nitrokey entirely.
I’m most in favor of just removing Nitrokey if we add this minimum criteria to avoid confusion, to be honest. I think most people these days will go to their store and buy a Nitrokey 3C NFC (assuming that it is the same). We can warn against this, but in general it does not really inspire confidence that Nitrokey has not sought out certification for their other products in the first place.
If we are concerned about only recommending Yubico products, there are 3 products made by Trezor (starting at $59) and 4 products by Ledger (also starting at $59), which meet these criteria and are in the pricing ballpark of a YubiKey 5. I want to evaluate these separately, but I think they will be good candidates for future inclusion.
edit: I thought I checked this when writing, but apparently Trezor is not FIDO certified.
Google doesn’t disclose which secure element they are using, which is unfortunate in terms of the proposed EAL6 requirement.
Maybe this particular requirement is unnecessary, it mainly pertains to physical attacks which is not the primary use-case of security keys in the first place.
If missing features from other products are to be considered when recommending a single model, then I would also strongly hold it against Yubico for selling old stock with known vulnerable firmware.
I don’t think so. Level 1 certification has no hardware requirements. It literally just has to work.
I’ve found this $19.50 one which is Level 1 certified, and it’s name-brand:
At a glance, I can’t find any that are significantly cheaper than this on Amazon, if you know of any $10-$15 let me know. I also can’t find any that are the same price as this one and have NFC. This Identiv one looks like a good candidate to list, actually.
Did they though? Sounds like it was only FIPS models, which the commenter should not have purchased just because it was “the expensive FIPS variant.” If the government is demanding less secure hardware, that is hardly Yubico’s fault. The FIPS keys are already categorically worse in every way, they shouldn’t be a purchasing consideration for any of us.
At the government’s demand, Yubico is actually stillselling v5.4 keys today lol
I do hold it against Yubico for not issuing a recall/replacement, but Infineon’s vulnerability was hardly on the same level as Feitian’s problem that once resulted in a replacement program.
The YubiKey vulnerability only concerned physical duplication, which is not a key thing a security key needs to defend against anyways. That is to say, when used merely as a 2FA device this was a very low risk problem.
If they had a problem with the fundamental features, Yubico probably would issue a replacement program.
While Nitrokey 3 has a secure element and encrypts some secrets against the PIN, passkeys and FIDO2 credentials are not stored in that secure element and aren’t encrypted against the PIN either. Combined with no potting, this is not good.