# Require security key certifications & remove Nitrokey

**URL:** https://discuss.privacyguides.net/t/require-security-key-certifications-remove-nitrokey/39321
**Category:** Tool Suggestions
**Created:** 2026-07-24T00:57:23Z
**Posts:** 13

## Post 1 by @jonah — 2026-07-24T00:57:23Z

### Why should this tool be removed?

I think we should add security key criteria to require:

- FIDO2 Level 1 or higher certification on the key itself (some websites/applications will only work with FIDO certified keys!)
- Uses a secure element with a CC EAL6 or higher certification

Currently, only a single Nitrokey product has both: the Nitrokey 3A Mini.

We do note this on the page already, but we should be stronger about requiring this (because some websites/applications will only work with FIDO certified keys).

I think we could either change the recommendation to specifically the Nitrokey 3A Mini, or just remove Nitrokey entirely.

I’m most in favor of just removing Nitrokey if we add this minimum criteria to avoid confusion, to be honest. I think most people these days will go to their store and buy a Nitrokey 3C NFC (assuming that it is the same). We can warn against this, but in general it does not really inspire confidence that Nitrokey has not sought out certification for their other products in the first place.

* * *

If we are concerned about only recommending Yubico products, there are ~~3 products made by Trezor (starting at $59) and~~ 4 products by Ledger (also starting at $59), which meet these criteria and are in the pricing ballpark of a YubiKey 5. I want to evaluate these separately, but I think they will be good candidates for future inclusion.

edit: I thought I checked this when writing, but apparently Trezor is not FIDO certified.

---

## Post 2 by @fria — 2026-07-24T01:41:08Z

I’m in favor.

---

## Post 3 by @Quantum — 2026-07-24T02:49:15Z

I think removing them makes sense. Trying to parse it to a specific model is likely to sow confusion.

As for Yubikey alternatives; it seems Google’s Titan Security Key is FIDO 1 certified and may be worth a look.

> **[Google | FIDO Alliance](https://fidoalliance.org/company/google/)**

---

## Post 4 by @jonah — 2026-07-24T03:10:42Z

Google doesn’t disclose which secure element they are using, which is unfortunate in terms of the proposed EAL6 requirement.

Maybe this particular requirement is unnecessary, it mainly pertains to physical attacks which is not the primary use-case of security keys in the first place.

---

## Post 5 by @HugeDisk — 2026-07-24T05:41:46Z

> **[TOKEN2 Sàrl is a Swiss cybersecurity company specialized in the area of...](https://www.token2.eu/site/page/fido2-security-keys-faq#certification)**
>
> FIDO2 USB Key, U2F USB Key, Cheap Yubico alternative, FIDO2, fido alliance certified security keys Replace your mobile authenticator with secure hardware OTP token! Easily programmed via NFC. Designed to use with Google, Facebook, Dropbox, GitHub,...

Token2 keys may pass the criteria.

---

## Post 6 by @any1 — 2026-07-24T16:26:38Z

> [@jonah](#):
>
> We can warn against this, but in general it does not really inspire confidence that Nitrokey has not sought out certification for their other products in the first place.

If missing features from other products are to be considered when recommending a single model, then I would also strongly hold it against Yubico for selling [old stock with known vulnerable firmware.](https://discuss.privacyguides.net/t/yubikey-is-still-selling-old-stock-with-vulnerable-firmware/22361)

---

## Post 7 by @Lukas — 2026-07-24T16:43:50Z

This is a bigger issue than FIDO certification: [Nitrokey 3 key assembly - FIDO2 / Nitrokey 3 - Nitrokey Support](https://support.nitrokey.com/t/nitrokey-3-key-assembly/6285)

Potting is important.

---

## Post 8 by @lyricism — 2026-07-24T22:41:54Z

> [@jonah](#):
>
> because some websites/applications will only work with FIDO certified keys

Any examples? Only case I’m aware of “in the wild” is Entra ID tenants if so configured by the admin.

---

## Post 9 by @ph00lt0 — 2026-07-24T22:47:03Z

> **[FIDO Devices - Future of Cybersecurity](https://cpl.thalesgroup.com/access-management/authenticators/fido-devices)**
>
> FIDO devices offer the best solution to the global password challenge, using passwordless authentication with multi-factor (MFA) hardware.

Also Thales makes good keys these days. So i would say there are enough options available to set requirment for certified keys.

---

## Post 10 by @CarefulMouse — 2026-07-25T14:01:59Z

Could requiring certification influence the future market such that it increases prices to a point beyond the typical consumer?

I mention because I think there are some keys that are in the $20 price point and it may be counter to your goals if you see less user adoption.

I’m somewhat asking if these “certifications” are really just nice-to-have branding that the typical consumer will not benefit from beyond:

> some websites/applications will only work with FIDO certified keys!

---

## Post 11 by @jonah — 2026-07-25T16:32:58Z

I don’t think so. Level 1 certification has no hardware requirements. It literally just [has to work.](https://fidoalliance.org/certification/authenticator-certification-levels/)

I’ve found this $19.50 one which is Level 1 certified, and it’s name-brand:

> **[Amazon.com: Identiv uTrust FIDO2 NFC Security Key USB-C (FIDO2, U2F, WebAuthn) :...](https://www.amazon.com/Identiv-uTrust-FIDO2-Security-WebAuth/dp/B0C6YRJ7Y7)**
>
> Identiv’s uTrust FIDO2 NFC Security Key allows you to replace passwords with a secure, fast, scalable, FIDO Alliance certified cost-effective login solution. The cryptographic security model of the devices eliminates the risk of phishing, password...

_At a glance_, I can’t find any that are significantly cheaper than this on Amazon, if you know of any $10-$15 let me know. I also can’t find any that are the _same_ price as this one _and_ have NFC. This Identiv one looks like a good candidate to list, actually.

---

## Post 12 by @jonah — 2026-07-25T16:47:49Z

> [@any1](#):
>
> selling [old stock with known vulnerable firmware.](https://discuss.privacyguides.net/t/yubikey-is-still-selling-old-stock-with-vulnerable-firmware/22361)

Did they though? Sounds like it was only FIPS models, which the commenter should not have purchased just because it was “the expensive FIPS variant.” If the government is demanding less secure hardware, that is hardly Yubico’s fault. The FIPS keys are already categorically worse in every way, they shouldn’t be a purchasing consideration for any of us.

At the government’s demand, Yubico is actually **still** [selling v5.4 keys](https://www.yubico.com/us/product/yubikey-5-fips-series/yubikey-5c-nfc-fips-140-2/) today lol

* * *

I _do_ hold it against Yubico for not issuing a recall/replacement, but Infineon’s vulnerability was hardly on the same level as [Feitian’s problem](https://www.wired.com/story/google-titan-security-key-recall-ble/) that once resulted in a replacement program.

The YubiKey vulnerability only concerned physical duplication, which is not a key thing a security key needs to defend against anyways. That is to say, _when used merely as a 2FA device_ this was a very low risk problem.

If they had a problem with the fundamental features, Yubico probably [would](https://www.engadget.com/2019-06-13-yubico-recalls-government-grade-security-keys-due-to-bug.html) issue a replacement program.

---

## Post 13 by @Lukas — 2026-07-26T06:27:03Z

I think that Nitrokey removal is warranted, as per one of the reasons here: [Security Key Comparison - #19 by Lukas](https://discuss.privacyguides.net/t/security-key-comparison/39339/19)

> While Nitrokey 3 has a secure element and encrypts some secrets against the PIN, passkeys and FIDO2 credentials are not stored in that secure element and aren’t encrypted against the PIN either. Combined with no potting, this is not good.
